Welcome Guest ( Log In | Register )

Discover the best free computer help!
Learn more about Geeks to Go by taking the tour. Spyware, virus, trojan, fake security or privacy alerts? Read the malware cleaning guide.
      
 
Closed TopicStart new topic
monhop.exe malware - how to remove [RESOLVED], trojan poses as wma codec upgrade - multiple malware activities result
patdow
post Dec 1 2007, 02:56 PM
Post #1


New Member
*
Posts: 6
OS: Windows XP



Need help bigtime - none of the major antivirus scans find anything amiss (althought hijackthis and smitfraudfix do).

BTW - I am new subscriber- so excuse any misunderstanding of how to post

My problems are identical to a thread solved by Kahdah described as worm.win32.netsky. Thread I am Referencing re:worm.win32.netsky

The problem started when I was at a news site and clicked on a WMV link for a story. Windows Media player (or so I assume) requested to load an updated codec. When it did, the command interface came up and before I saw what was going on some program was run. 3 hours later, total chaos breaks loose on my system. I am obviously sending stuff out my internet connection, my system is running incredibly slowly, process name buttons at the base of the windows display just start to blink orange for no reason, there is a fake McAfee warning flashing in the system tray, pop-up messages claiming I have worm.win32.netsky are prompting me to run virus scanning off of security company sites I have never heard of, etc. Scans using PREVX, McAfee, Kaspersky(Online) all find nothing (after hours!!!). Two things I notice: MGHTML.EXE and EXPLORER are taking 99% CPU (system idle is at 0%) and there are an interesting new set of things created in the %Windows% directory - in particular a program called monhop.exe. By the way I killed the MGHTML process and that at least gave me back the system performance.

Pasted in below are the Hijackthis scanlog and just after is the SMitfraudfix scan log....

I followed all the instructions from the thread I reference above. However when I went to repair using Smitfraudfix (in safe mode), the process bombed because it identified "process.exe" as being invalid. When I looked in the Smitfraudfix directory (stored at desktop) the Process.exe file was 0 bytes. Re-installing Smitfraudfix did not change this. What do I do now?????

Help appreciated... Patdow


======================
HIJACKTHIS:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:59:31 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\AWORKS\solotray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: MSVPS System - {9352055D-879B-4876-92E3-6DF8D5210B54} - C:\WINDOWS\werbetorq.dll
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: The hdtip - {17D69B84-065B-4F88-AFE8-3BA9B4907501} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx2\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [AdwareRemover2007] C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe
O4 - Startup: Mixer Taskbar Icon.lnk = C:\Program Files\AWORKS\solotray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\participant\pull.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000014-9593-4264-8B29-930B3E4EDCCD} (HPVirtualRooms14 Class) - https://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall14.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {11865A2A-649F-4FA1-8B99-B97DF8070B7C} (IWSystemchecks Control) - http://call.interwise.com/europartners/Eng...ystemchecks.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://ukpwca.ops.placeware.com/etc/place/...quicksilver.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {7A162288-DE78-473C-A6BA-23FF17F768E9} (AxWebInstaller Control) - http://call.interwise.com/europartners/app...ebInstaller.cab
O16 - DPF: {9B57C630-AA6E-440D-8D44-D34542E5531A} (SendMail Class) - http://www203.placeware.com/etc/static/UKC...MailObjects.cab
O16 - DPF: {BB8B9052-8D27-45D4-B79F-84946D41EBF7} (Office Live Meeting Presentation-Upload Control) - https://fwd502.livemeeting.com/etc/place/BA...loadControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetingsssl.webex.com/client/v_my...bex/ieatgpc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: pmkret - {7AFF5EA8-F901-4C49-B8DD-407774AAC1F8} - C:\WINDOWS\pmkret.dll
O21 - SSODL: gormet - {9D2E9582-8A92-437F-93EA-0C3613030C9C} - C:\WINDOWS\gormet.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PREVXAgent - Prevx - C:\Program Files\Prevx2\PXAgent.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 12265 bytes
========================
SMITFRAUDFIX LOG (RAPPORT)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:59:31 PM, on 12/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
C:\Program Files\WinZip\WZQKPICK.EXE
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\AWORKS\solotray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {77701e16-9bfe-4b63-a5b4-7bd156758a37} - (no file)
O2 - BHO: MSVPS System - {9352055D-879B-4876-92E3-6DF8D5210B54} - C:\WINDOWS\werbetorq.dll
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: The hdtip - {17D69B84-065B-4F88-AFE8-3BA9B4907501} - C:\WINDOWS\hdtip.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx2\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Windows update loader] C:\Windows\xpupdate.exe
O4 - HKCU\..\Run: [AdwareRemover2007] C:\Program Files\AdwareRemover2007\AdwareRemover2007.exe
O4 - Startup: Mixer Taskbar Icon.lnk = C:\Program Files\AWORKS\solotray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\participant\pull.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000014-9593-4264-8B29-930B3E4EDCCD} (HPVirtualRooms14 Class) - https://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall14.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {11865A2A-649F-4FA1-8B99-B97DF8070B7C} (IWSystemchecks Control) - http://call.interwise.com/europartners/Eng...ystemchecks.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://ukpwca.ops.placeware.com/etc/place/...quicksilver.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {7A162288-DE78-473C-A6BA-23FF17F768E9} (AxWebInstaller Control) - http://call.interwise.com/europartners/app...ebInstaller.cab
O16 - DPF: {9B57C630-AA6E-440D-8D44-D34542E5531A} (SendMail Class) - http://www203.placeware.com/etc/static/UKC...MailObjects.cab
O16 - DPF: {BB8B9052-8D27-45D4-B79F-84946D41EBF7} (Office Live Meeting Presentation-Upload Control) - https://fwd502.livemeeting.com/etc/place/BA...loadControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetingsssl.webex.com/client/v_my...bex/ieatgpc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: pmkret - {7AFF5EA8-F901-4C49-B8DD-407774AAC1F8} - C:\WINDOWS\pmkret.dll
O21 - SSODL: gormet - {9D2E9582-8A92-437F-93EA-0C3613030C9C} - C:\WINDOWS\gormet.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PREVXAgent - Prevx - C:\Program Files\Prevx2\PXAgent.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 12265 bytes





QUOTE(kahdah @ Nov 30 2007, 07:19 PM) *
I see that you have uTorrent installed.
Having P2p programs such as these raise the possibility of getting infected again.
See here for information on P2P's.
I will leave it up to you if you want to remove it.
To remove it just simply uninstall it then delete this folder>C:\Program Files\UTorrent

Pirated sofware is a sure way to get infected.
===============================================================
Please download the OTMoveIt by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt.exe to run it.
  • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\Documents and Settings\Kym\Desktop\SmitfraudFix
    C:\Documents and Settings\Kym\Desktop\SmitfraudFix.exe
    C:\Documents and Settings\Kym\Shared\01 Track 1.wma
    C:\Documents and Settings\Kym\Shared\02 Track 2.wma
    C:\Documents and Settings\Kym\Shared\03 Track 3.wma
    C:\Documents and Settings\Kym\Shared\06 Track 6.wma
    C:\Documents and Settings\Kym\Shared\death metal remix.wm
    C:\Program Files\ESET\infected\XUYBQIAA.NQF
    C:\Software_Pirated\Smart Keystroke Recorder\Hooks.dll
    C:\WINDOWS\system32\68okbngr.ini
    Q:\Torrents\What Toolbox - Windows\MIRC.v6.3.Incl.KeyMaker.and.AuthPatch-DVT\dv8b1mi1.zip


  • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
  • Click the red Moveit! button.
    Click "Exit" to close OTMoveIt.

    **When ready to Reply on the forum, please Paste the content of the latest log which is located at the root of the drive where the OTMoveIt folder is:
    C:\_OTMoveIt\MovedFiles\********_******.log
    (where "********_******" is the "date_time")
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
=======================================
Also a new Hijackthis log.

Go to the top of the page
 
+Quote Post
kahdah
post Dec 1 2007, 03:15 PM
Post #2


GeekU Teacher
Group Icon
Posts: 8,741
From: Somewhere
OS: Windows xp home



Hello patdow

Welcome to G2Go. smile.gif
==========================
Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click SmitfraudFix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.


Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm
Go to the top of the page
 
+Quote Post
patdow
post Dec 1 2007, 05:46 PM
Post #3


New Member
*
Posts: 6
OS: Windows XP



I will try that again, this time moving the exe to root.

In the meantime, I ran Prevx2 - and it found the following files and registry entries that it "jailed" (see screen capture attachment).

Despite that, all the same activities continued. It did however, intercept a process attempting to change the home page right after I had changed it back to my setting manually. That process is now "blocked" from making that change. However, the subsequent scan Prevx ran didn't find anything even thought pop-ups and other weirdness continued.

Go to the top of the page
 
+Quote Post
kahdah
post Dec 1 2007, 05:49 PM
Post #4


GeekU Teacher
Group Icon
Posts: 8,741
From: Somewhere
OS: Windows xp home



Ok I will need to see the Smitfraudfix log to start the cleaning process and a new Hijackthis as well please.
Thank you. smile.gif
Go to the top of the page
 
+Quote Post
patdow
post Dec 2 2007, 09:37 AM
Post #5


New Member
*
Posts: 6
OS: Windows XP



Prevx2 and McAfee have both started to find a few things and the pop-up and browser hijacking of homepage seem to have stopped.

Here is the lastest HiJackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:32:09 AM, on 12/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Prevx2\PXConsole.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\interwise\participant\pull.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AWORKS\solotray.exe
C:\Program Files\Prevx2\PXAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: MSVPS System - {9352055D-879B-4876-92E3-6DF8D5210B54} - C:\WINDOWS\werbetorq.dll (file missing)
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: The hdtip - {17D69B84-065B-4F88-AFE8-3BA9B4907501} - C:\WINDOWS\hdtip.dll (file missing)
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Lexmark X6100 Series] "C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\System32\igfxpers.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx2\PXConsole.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [GoBoingo] C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Mixer Taskbar Icon.lnk = C:\Program Files\AWORKS\solotray.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: HotSync Manager.lnk = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Mobile User VPN.lnk = C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
O4 - Global Startup: Push Client.LNK = C:\Program Files\interwise\participant\pull.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00000014-9593-4264-8B29-930B3E4EDCCD} (HPVirtualRooms14 Class) - https://www.rooms.hp.com/vRoom_Cab/WebHPVCInstall14.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/u...can_unicode.cab
O16 - DPF: {11865A2A-649F-4FA1-8B99-B97DF8070B7C} (IWSystemchecks Control) - http://call.interwise.com/europartners/Eng...ystemchecks.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru...cat-no-eula.cab
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - http://ukpwca.ops.placeware.com/etc/place/...quicksilver.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m...01/mcinsctl.cab
O16 - DPF: {7A162288-DE78-473C-A6BA-23FF17F768E9} (AxWebInstaller Control) - http://call.interwise.com/europartners/app...ebInstaller.cab
O16 - DPF: {9B57C630-AA6E-440D-8D44-D34542E5531A} (SendMail Class) - http://www203.placeware.com/etc/static/UKC...MailObjects.cab
O16 - DPF: {BB8B9052-8D27-45D4-B79F-84946D41EBF7} (Office Live Meeting Presentation-Upload Control) - https://fwd502.livemeeting.com/etc/place/BA...loadControl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m...,26/mcgdmgr.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://mymeetingsssl.webex.com/client/v_my...bex/ieatgpc.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bhead.co.uk,nomadix.com,hsd1.ma.comcast.net.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 193.129.117.44
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: SafeNet Monitor Service (IPSECMON) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
O23 - Service: SafeNet IKE Service (IreIKE) - SafeNet - C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PREVXAgent - Prevx - C:\Program Files\Prevx2\PXAgent.exe
O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - C:\Program Files\VMware\VMware Player\vmware-authd.exe
O23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\system32\vmnetdhcp.exe
O23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
O23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\system32\vmnat.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 11656 bytes


Here is the latest SmitFraudFix log:

SmitFraudFix v2.256

Scan done at 10:35:44.55, Sun 12/02/2007
Run from C:\Documents and Settings\P Dowling\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WatchGuard\Mobile User VPN\IreIKE.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmgr.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Lexmark X6100 Series\lxbfbmon.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Apoint\Apntex.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\System32\igfxpers.exe
C:\WINDOWS\System32\igfxsrvc.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Prevx2\PXConsole.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Boingo\GoBoingo\GoBoingo.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WatchGuard\Mobile User VPN\IPSecMon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\WatchGuard\Mobile User VPN\SafeCfg.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\interwise\participant\pull.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\AWORKS\solotray.exe
C:\Program Files\Prevx2\PXAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\VMware\VMware Player\vmware-authd.exe
C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exe
C:\WINDOWS\system32\vmnat.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\vmnetdhcp.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\P Dowling


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\P Dowling\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PDOWLI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Dell Wireless WLAN 1450 Dual Band WLAN Mini-PCI Card - Packet Scheduler Miniport
DNS Server Search Order: 205.188.146.145

HKLM\SYSTEM\CCS\Services\Tcpip\..\{54464BEE-2C11-446A-94CB-441D112FACF0}: DhcpNameServer=205.188.146.145
HKLM\SYSTEM\CS1\Services\Tcpip\..\{54464BEE-2C11-446A-94CB-441D112FACF0}: DhcpNameServer=205.188.146.145
HKLM\SYSTEM\CS2\Services\Tcpip\..\{0F61AB78-4D3A-49E5-A088-E4B6830DDEA8}: DhcpNameServer=163.244.112.254 163.244.100.254
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=205.188.146.145
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: NameServer=193.129.117.44
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=205.188.146.145
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: NameServer=193.129.117.44


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



Thank you for help....
Go to the top of the page
 
+Quote Post
kahdah
post Dec 2 2007, 10:12 AM
Post #6


GeekU Teacher
Group Icon
Posts: 8,741
From: Somewhere
OS: Windows xp home



Please re-open Hijackthis and click on "Do a system scan only"
Then place a check mark next to these entries below:

O2 - BHO: MSVPS System - {9352055D-879B-4876-92E3-6DF8D5210B54} - C:\WINDOWS\werbetorq.dll (file missing)
O2 - BHO: File Print FedEx Kinko's - {9566395F-43D2-4c64-B525-B501FFA276E2} - mscoree.dll (file missing)
O3 - Toolbar: File Print FedEx Kinko's - {9566395f-43d2-4c64-b525-b501ffa276e2} - mscoree.dll (file missing)


Now click on Fix Checked and then close Hijackthis.
====================================
Please download SUPERAntiSpyware Home Edition (free version).
–Install it and double-click the icon on your desktop to run it.
  • It will ask if you want to update the program definitions, click Yes.
  • Under Configuration and Preferences, click the Preferences button.
  • Click the Scanning Control tab.
  • Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Scan for Alternate Data streams
  • Terminate memory threats before quarantining.
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.

*Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.

Then run Superantispyware.
  • Double click on the icon to start Superantispyware.
  • On the main screen, under Scan for Harmful Software click Scan your computer.
  • On the left check C:\Fixed Drive.
  • On the right, under Complete Scan, choose Perform Complete Scan.
  • Click Next to start the scan. Please be patient while it scans your computer.
  • After the scan is complete a summary box will appear. Click OK.
  • Make sure everything in the white box has a check next to it, then click Next.
  • It will quarantine what it found and if it asks if you want to reboot, click Yes.
1. To retrieve the removal information for me please do the following:
2. After reboot, double-click the SUPERAntispyware icon on your desktop.
3. Click Preferences. Click the Statistics/Logs tab.
4. Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.
5. It will open in your default text editor (such as Notepad/Wordpad).
6. Please highlight everything in the notepad, then right-click and choose copy.
7. Click close and close again to exit the program.
Save the log information. If needed (still infected) paste this info along with your HijackThis log.
Go to the top of the page
 
+Quote Post
patdow
post Dec 5 2007, 09:51 PM
Post #7


New Member
*
Posts: 6
OS: Windows XP



Travelling - so delay in dealing with this.... Here are the logs from Superantispyware and hijack this. Am I out of the woods?
====================================================================
SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 12/04/2007 at 02:34 AM

Application Version : 3.9.1008

Core Rules Database Version : 3354
Trace Rules Database Version: 1353

Scan type : Complete Scan
Total Scan Time : 02:14:18

Memory items scanned : 168
Memory threats detected : 0
Registry items scanned : 6434
Registry threats detected : 0
File items scanned : 71150
File threats detected : 484

Adware.Tracking Cookie
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@sitestats.tiscali.co[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@stats.channel4[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@fastclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@e-2dj6wjnywhcjwlo.stats.esomniture[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads2.drivelinemedia[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@burstnet[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@cgi-bin[5].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@43836137[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@revenue[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@nextag[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@belnk[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@login.tracking101[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@paycounter[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.businessweek[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@perf.overture[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@casalemedia[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@www.burstbeacon[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adinterax[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@phg.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@tracking.citibank[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@weborama[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@toplist[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-salesforce.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adknowledge[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-ctv.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@webstat[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adserver.news.com[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-verizoncommunications.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@fcstats.bcentral[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@ads.pointroll[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@dist.belnk[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@doubleclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@tradedoubler[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-techtarget.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@server.iad.liveperson[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@icc.intellisrv[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@mediaonenetwork[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@2o7[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@server3.web-stat[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@edge.ru4[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.cnn[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@cgi-bin[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@qnsr[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.channel4[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ad1.dmcmedia.co[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@clickability[2].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@advertising[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@indextools[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@stat.dealtime[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@a[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adrevolver[3].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@questionmarket[2].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@ad.yieldmanager[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@e-2dj6wjmywpcjkfp.stats.esomniture[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@hurricanedigitalmedia[2].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@ehg-pennwell.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@s.clickability[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.monster[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@fl01.ct2.comclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@sdc.rbistats[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.e-planning[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adprofile[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@atdmt[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@mediaplex[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@adopt.specificclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@z1.adserver[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@wpni.112.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@serving-sys[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@as-us.falkag[2].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@statse.webtrendslive[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@pro-market[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@bs.serving-sys[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-mgnlimited.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@citi.bridgetrack[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@banner[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adserver[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@image.masterstats[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@atwola[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@windowsmedia[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@pbteen[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-bestbuy.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adv.webmd[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@entrepreneur[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@partner2profit[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-christushealth.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.realcastmedia[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-tfl.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@tripod[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@powellsbooks.122.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@statcounter[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads1.itadnetwork.co[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@himss.advertserve[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@katu.adbureau[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@spylog[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@cgi-bin[8].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@galleries.deluxecum.xxxkey[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@webstat[3].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@sento.122.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@microsofteup.112.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@trafficmp[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@www.entrepreneur[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@bluestreak[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@fortunecity[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@rapidresponse.directtrack[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@html[3].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.cc214142[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-ignitemedia.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@sel.as-eu.falkag[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@media.discosfuentes[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@roiservice[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@sales.liveperson[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adopt.euroclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@maxserving[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@ehg-dig.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@rotator.adjuggler[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@www.smartadserver[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@overture[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@i.screensavers[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adserving.autotrader[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-kasperskylab.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ad.admarketplace[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-ipm.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@apmebf[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@valueclick[3].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adtech[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.as4x.tmcs[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@hc2.humanclick[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@counter.hitslink[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@xiti[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@cnn.122.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.as4x.tmcs.ticketmaster[1].txt
C:\Documents and Settings\P Dowling\Cookies\p_dowling@tacoda[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-iwantoneofthose.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@admarketplace[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ads.mediaturf[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-zoom.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-bestwestern.hitbox[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@msnportal.112.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@clicktracks.aristotle[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@superstats[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ad101com.adbureau[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@adrevolver[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-documentum.hitbox[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@cf-db01.clickfacts[2].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@gettyimages.122.2o7[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@clickbank[1].txt
C:\Documents and Settings\P Dowling\Cookies\p dowling@ehg-microso