"Warning! Potential Spyware" Operation [RESOLVED], Need help to remove the above malware |
![]() ![]() |
"Warning! Potential Spyware" Operation [RESOLVED], Need help to remove the above malware |
Nov 2 2007, 05:48 AM
Post
#1
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi there,
I have been guided to post my problem here. I have recently downloaded Java updates and thereafter, I received this irritating pop-up message stating that there is potential spyware where I am required to click either yes or no to down the anti-spyware. I clicked "no" and it keeps popping out. Please help me to get rid of this pop-up. The decker log is as below. My control panel is now missing also. Not sure where it is hiding as I cannot find it. Please help. From, Stomp1 Main:- Deckard's System Scanner v20071014.68 Run on 2007-11-02 17:24:33 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 20: 2007-11-02 06:24:40 UTC - RP118 - Deckard's System Scanner Restore Point 19: 2007-11-01 07:19:12 UTC - RP117 - System Checkpoint 18: 2007-10-30 22:43:59 UTC - RP116 - Installed Time Zone Data Update Tool for Microsoft Office Outlook 17: 2007-10-25 13:01:51 UTC - RP115 - Installed iTunes 16: 2007-10-25 05:16:05 UTC - RP114 - Installed ICQ6 -- First Restore Point -- 1: 2007-10-03 09:19:07 UTC - RP99 - Installed ACDSee 8 Backed up registry hives. Performed disk cleanup. -- HijackThis Clone ------------------------------------------------------------ Emulating logfile of Trend Micro HijackThis v2.0.2 Scan saved at 2007-11-02 17:26:30 Platform: Windows XP Service Pack 2 (5.01.2600) MSIE: Internet Explorer (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\system32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\ati2evxx.exe C:\WINDOWS\explorer.exe C:\WINDOWS\system32\printer.exe C:\WINDOWS\system32\drivers\Icon.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\APPS\Powercinema\PCMService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe C:\Documents and Settings\Myra\Desktop\dss.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll F0 - system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe O1 - Hosts: 192.168.200.3 ad.doubleclick.net O1 - Hosts: 192.168.200.3 ad.fastclick.net O1 - Hosts: 192.168.200.3 ads.fastclick.net O1 - Hosts: 192.168.200.3 ar.atwola.com O1 - Hosts: 192.168.200.3 atdmt.com O1 - Hosts: 192.168.200.3 avp.ch O1 - Hosts: 192.168.200.3 avp.com O1 - Hosts: 192.168.200.3 avp.ru O1 - Hosts: 192.168.200.3 awaps.net O1 - Hosts: 192.168.200.3 banner.fastclick.net O1 - Hosts: 192.168.200.3 banners.fastclick.net O1 - Hosts: 192.168.200.3 ca.com O1 - Hosts: 192.168.200.3 click.atdmt.com O1 - Hosts: 192.168.200.3 clicks.atdmt.com O1 - Hosts: 192.168.200.3 customer.symantec.com O1 - Hosts: 192.168.200.3 dispatch.mcafee.com O1 - Hosts: 192.168.200.3 download.mcafee.com O1 - Hosts: 192.168.200.3 download.microsoft.com O1 - Hosts: 192.168.200.3 downloads-us1.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads-us2.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads-us3.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads.microsoft.com O1 - Hosts: 192.168.200.3 downloads1.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads2.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads3.kaspersky-labs.com O1 - Hosts: 192.168.200.3 downloads4.kaspersky-labs.com O1 - Hosts: 192.168.200.3 engine.awaps.net O1 - Hosts: 192.168.200.3 f-secure.com O1 - Hosts: 192.168.200.3 fastclick.net O1 - Hosts: 192.168.200.3 ftp.avp.ch O1 - Hosts: 192.168.200.3 ftp.downloads1.kaspersky-labs.com O1 - Hosts: 192.168.200.3 ftp.downloads2.kaspersky-labs.com O1 - Hosts: 192.168.200.3 ftp.downloads3.kaspersky-labs.com O1 - Hosts: 192.168.200.3 ftp.f-secure.com O1 - Hosts: 192.168.200.3 ftp.kasperskylab.ru O1 - Hosts: 192.168.200.3 ftp.sophos.com O1 - Hosts: 192.168.200.3 go.microsoft.com O1 - Hosts: 192.168.200.3 ids.kaspersky-labs.com O1 - Hosts: 192.168.200.3 kaspersky-labs.com O1 - Hosts: 192.168.200.3 kaspersky.com O1 - Hosts: 192.168.200.3 liveupdate.symantec.com O1 - Hosts: 192.168.200.3 liveupdate.symantecliveupdate.com O1 - Hosts: 192.168.200.3 mast.mcafee.com O1 - Hosts: 192.168.200.3 mcafee.com O1 - Hosts: 192.168.200.3 media.fastclick.net O1 - Hosts: 192.168.200.3 microsoft.com O1 - Hosts: 192.168.200.3 msdn.microsoft.com O1 - Hosts: 192.168.200.3 my-etrust.com O1 - Hosts: 192.168.200.3 nai.com O1 - Hosts: 192.168.200.3 networkassociates.com O1 - Hosts: 192.168.200.3 norton.com O1 - Hosts: 192.168.200.3 office.microsoft.com O1 - Hosts: 192.168.200.3 pandasoftware.com O1 - Hosts: 192.168.200.3 phx.corporate-ir.net O1 - Hosts: 192.168.200.3 rads.mcafee.com O1 - Hosts: 192.168.200.3 secure.nai.com O1 - Hosts: 192.168.200.3 securityresponse.symantec.com O1 - Hosts: 192.168.200.3 service1.symantec.com O1 - Hosts: 192.168.200.3 sophos.com O1 - Hosts: 192.168.200.3 spd.atdmt.com O1 - Hosts: 192.168.200.3 support.microsoft.com O1 - Hosts: 192.168.200.3 symantec.com O1 - Hosts: 192.168.200.3 trendmicro.com O1 - Hosts: 192.168.200.3 update.symantec.com O1 - Hosts: 192.168.200.3 updates.symantec.com O1 - Hosts: 192.168.200.3 updates1.kaspersky-labs.com O1 - Hosts: 192.168.200.3 updates2.kaspersky-labs.com O1 - Hosts: 192.168.200.3 updates3.kaspersky-labs.com O1 - Hosts: 192.168.200.3 updates4.kaspersky-labs.com O1 - Hosts: 192.168.200.3 updates5.kaspersky-labs.com O1 - Hosts: 192.168.200.3 us.mcafee.com O1 - Hosts: 192.168.200.3 vil.nai.com O1 - Hosts: 192.168.200.3 viruslist.com O1 - Hosts: 192.168.200.3 viruslist.ru O1 - Hosts: 192.168.200.3 virusscan.jotti.org O1 - Hosts: 192.168.200.3 virustotal.com O1 - Hosts: 192.168.200.3 windowsupdate.microsoft.com O1 - Hosts: 192.168.200.3 www.avp.ch O1 - Hosts: 192.168.200.3 www.avp.com O1 - Hosts: 192.168.200.3 www.avp.ru O1 - Hosts: 192.168.200.3 www.awaps.net O1 - Hosts: 192.168.200.3 www.ca.com O1 - Hosts: 192.168.200.3 www.f-secure.com O1 - Hosts: 192.168.200.3 www.fastclick.net O1 - Hosts: 192.168.200.3 www.grisoft.com O1 - Hosts: 192.168.200.3 www.kaspersky-labs.com O1 - Hosts: 192.168.200.3 www.kaspersky.com O1 - Hosts: 192.168.200.3 www.kaspersky.ru O1 - Hosts: 192.168.200.3 www.mcafee.com O1 - Hosts: 192.168.200.3 www.microsoft.com O1 - Hosts: 192.168.200.3 www.my-etrust.com O1 - Hosts: 192.168.200.3 www.nai.com O1 - Hosts: 192.168.200.3 www.networkassociates.com O1 - Hosts: 192.168.200.3 www.pandasoftware.com O1 - Hosts: 192.168.200.3 www.sophos.com O1 - Hosts: 192.168.200.3 www.symantec.com O1 - Hosts: 192.168.200.3 www.symantec.com O1 - Hosts: 192.168.200.3 www.trendmicro.com O1 - Hosts: 192.168.200.3 www.viruslist.com O1 - Hosts: 192.168.200.3 www.viruslist.ru O1 - Hosts: 192.168.200.3 www.virustotal.com O1 - Hosts: 192.168.200.3 www3.ca.com O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NAVShExt.dll O3 - Toolbar: Protection Bar - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Video ActiveX Access\imsmain.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: system.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: autorun.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1 O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr=1 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O18 - Protocol: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\MSITSS.DLL O18 - Protocol: mso-offdap - {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL O20 - AppInit_DLLs: sulimo.dat O22 - SharedTaskScheduler: adirondack - {547aaa89-7e6b-42b4-b112-a64955f86a2a} - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe O23 - Service: SmartLinkService (SLService) - Unknown owner - C:\WINDOWS\system32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\symwsc.exe O24 - Desktop Component 0: - file:///C:/DOCUME~1/Myra/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg -- End of file - 14353 bytes -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- All drivers whitelisted. -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 Apple Mobile Device - "c:\program files\common files\apple\mobile device support\bin\applemobiledeviceservice.exe" <Not Verified; Apple, Inc.; Apple Mobile Device Service> S3 NMIndexingService - "c:\program files\common files\ahead\lib\nmindexingservice.exe" (file missing) -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2007-11-02 16:37:59 418 --a------ C:\WINDOWS\Tasks\Symantec NetDetect.job 2007-10-31 09:44:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job 2007-10-19 21:00:00 536 --a------ C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job -- Files created between 2007-10-02 and 2007-11-02 ----------------------------- 2007-11-02 15:35:03 0 d-------- C:\Documents and Settings\Myra\Application Data\Uniblue 2007-11-02 15:34:54 0 d-------- C:\Program Files\Uniblue 2007-11-02 13:12:15 0 d-------- C:\db88a8d408147e526b38f155 2007-11-02 10:15:50 0 d-------- C:\80689c8efeee877b8e 2007-11-01 23:56:49 7680 --a------ C:\WINDOWS\system32\printer.exe 2007-11-01 23:56:48 7680 --a------ C:\WINDOWS\system32\winavxx.exe 2007-10-27 18:20:09 0 --a------ C:\WINDOWS\nsreg.dat 2007-10-26 00:02:25 0 d-------- C:\Documents and Settings\Benetton\Application Data\Apple Computer 2007-10-26 00:02:09 0 d-------- C:\Program Files\iPod 2007-10-26 00:01:53 0 d-------- C:\Program Files\iTunes 2007-10-26 00:01:03 0 d-------- C:\Program Files\QuickTime 2007-10-26 00:00:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-10-26 00:00:38 0 d-------- C:\Program Files\Apple Software Update 2007-10-26 00:00:28 0 d------c- C:\WINDOWS\system32\DRVSTORE 2007-10-26 00:00:17 0 d-------- C:\Program Files\Common Files\Apple 2007-10-26 00:00:12 0 d-------- C:\Documents and Settings\All Users\Application Data\Apple 2007-10-25 21:18:00 0 d-------- C:\Documents and Settings\Benetton\Application Data\ICQ Toolbar 2007-10-25 16:22:50 0 d-------- C:\Documents and Settings\Myra\Application Data\ICQ Toolbar 2007-10-25 16:15:54 0 d-------- C:\Program Files\ICQToolbar 2007-10-25 16:14:56 0 d-------- C:\Documents and Settings\Myra\Application Data\Mozilla 2007-10-20 23:33:21 0 d-------- C:\Documents and Settings\Benetton\Application Data\Mozilla 2007-10-17 20:10:24 0 d-------- C:\WINDOWS\system32\NtmsData 2007-10-11 22:08:04 0 d-------- C:\Documents and Settings\Myra\Application Data\ACD Systems 2007-10-11 22:05:09 0 d-------- C:\Program Files\ACD Systems 2007-10-04 20:47:12 0 d-------- C:\Documents and Settings\Benetton\Application Data\Help 2007-10-03 20:24:24 0 d-------- C:\Documents and Settings\Benetton\Application Data\ACD Systems 2007-10-03 20:19:12 0 d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems 2007-10-03 20:19:10 0 d-------- C:\Program Files\Common Files\ACD Systems 2007-10-03 20:16:40 0 d-------- C:\WINDOWS\Downloaded Installations -- Find3M Report --------------------------------------------------------------- 2007-11-02 16:36:57 0 d-------- C:\Program Files\Common Files 2007-11-02 09:28:48 0 d-------- C:\Program Files\Norton AntiVirus 2007-11-01 18:51:20 0 d-------- C:\Program Files\Movies 2007-10-31 16:37:42 0 d-------- C:\Documents and Settings\Myra\Application Data\eBookPro6 2007-10-31 09:43:46 0 d-------- C:\Program Files\MSECache 2007-10-25 16:16:05 0 d--h----- C:\Program Files\InstallShield Installation Information 2007-10-15 14:12:20 0 d-------- C:\Program Files\Symantec 2007-10-15 14:12:20 0 d-------- C:\Program Files\Common Files\Symantec Shared 2007-10-06 01:03:02 44184 --a------ C:\Documents and Settings\Myra\Application Data\GDIPFONTCACHEV1.DAT 2007-09-28 10:04:32 0 d-------- C:\Documents and Settings\Myra\Application Data\Yahoo! 2007-09-27 22:42:15 0 d-------- C:\Program Files\Yahoo! 2007-09-27 20:20:14 0 d-------- C:\Program Files\DivX 2007-09-21 21:36:19 0 d-------- C:\Documents and Settings\Myra\Application Data\Sonic 2007-09-21 21:36:07 0 d-------- C:\Documents and Settings\Myra\Application Data\Leadertech 2007-09-20 09:46:33 0 d-------- C:\Program Files\Invoke Solutions 2007-09-09 16:37:13 0 d-------- C:\Program Files\BitTorrent 2007-09-09 09:34:30 0 d-------- C:\Program Files\Common Files\Ahead -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}"= C:\Program Files\Video ActiveX Access\iesbpl.dll [ ] [-HKEY_CLASSES_ROOT\CLSID\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [08/04/2004 02:00 PM] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/04/2004 02:00 PM] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [08/04/2004 02:00 PM] "Icon"="C:\WINDOWS\system32\drivers\Icon.exe" [04/19/2004 03:23 PM] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [09/26/2003 11:01 AM] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [09/26/2003 11:01 AM] "SoundMan"="SOUNDMAN.EXE" [04/28/2004 05:19 PM C:\WINDOWS\SOUNDMAN.EXE] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [05/15/2004 09:10 PM] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [07/12/2007 05:00 AM] "PCMService"="c:\Apps\Powercinema\PCMService.exe" [10/08/2004 03:14 AM] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [08/18/2003 12:50 PM] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [05/26/2007 07:32 PM] "NWEReboot"="" [] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [11/08/2006 09:31 AM] "SNM"="C:\Program Files\SpyNoMore\SNM.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [06/29/2007 07:24 AM] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [01/12/2006 05:40 PM] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [09/26/2007 03:42 PM] "WinAVX"="C:\WINDOWS\system32\WinAvXX.exe" [11/01/2007 11:56 PM] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [10/14/2004 03:24 AM] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [04/21/2006 06:03 PM] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [08/04/2004 02:00 PM] "WinAVX"="C:\WINDOWS\system32\WinAvXX.exe" [11/01/2007 11:56 PM] "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [10/22/2007 10:12 AM] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=1 (0x1) "DisableTaskMgr"=1 (0x1) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoControlPanel"=1 (0x1) [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "rare"=C:\Program Files\Video ActiveX Access\imsmain.exe [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Shell"="Explorer.exe C:\WINDOWS\system32\printer.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=sulimo.dat [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{50fa6ea0-1357-11dc-8b90-0040d07c44a6}] Auto\command- infrom.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e196d640-1a04-11dc-8ba3-0040d07c44a6}] AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL wscript.exe .MS32DLL.dll.vbs [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{ea973180-090b-11dc-8b69-0040d07c44a6}] Auto\command- infrom.exe AutoRun\command- C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL infrom.exe -- Hosts ----------------------------------------------------------------------- 192.168.200.3 ad.doubleclick.net 192.168.200.3 ad.fastclick.net 192.168.200.3 ads.fastclick.net 192.168.200.3 ar.atwola.com 192.168.200.3 atdmt.com 192.168.200.3 avp.ch 192.168.200.3 avp.com 192.168.200.3 avp.ru 192.168.200.3 awaps.net 192.168.200.3 banner.fastclick.net 92 more entries in hosts file. -- End of Deckard's System Scanner: finished at 2007-11-02 18:07:41 ------------ Extra: Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 2.0 Architecture: X86; Language: English CPU 0: Intel® Pentium® M processor 2.00GHz Percentage of Memory in Use: 22% Physical Memory (total/avail): 2047.48 MiB / 1579.69 MiB Pagefile Memory (total/avail): 3944.07 MiB / 3614.72 MiB Virtual Memory (total/avail): 2047.88 MiB / 1929.92 MiB C: is Fixed (NTFS) - 66.74 GiB total, 10.91 GiB free. Q: is CDROM (No Media) \\.\PHYSICALDRIVE0 - SAMSUNG MP0804H - 74.56 GiB - 2 partitions \PARTITION0 - Unknown - 7.81 GiB \PARTITION1 (bootable) - Installable File System - 66.74 GiB - C: -- Security Center ------------------------------------------------------------- AUOptions is scheduled to auto-install. Windows Internal Firewall is enabled. FirstRunDisabled is set. AntiVirusDisableNotify is set. AV: Norton AntiVirus v2004 (Symantec Corporation) [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019" [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\\Program Files\\uTorrent\\utorrent.exe"="C:\\Program Files\\uTorrent\\utorrent.exe:*:Enabled:µTorrent" "C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupX.exe:*:Enabled:MSI starter" "C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupXu.exe"="C:\\Program Files\\Common Files\\Ahead\\Nero Web\\SetupXu.exe:*:Disabled:Nero ProductSetup" "C:\\Program Files\\Skype\\Phone\\Skype.exe"="C:\\Program Files\\Skype\\Phone\\Skype.exe:*:Disabled:Skype. Take a deep breath " "%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes" "%windir%\\system32\\winav.exe"="%windir%\\system32\\winav.exe:*:Enabled:@xpsp2res.dll,-22019" -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Myra\Application Data CLASSPATH=.;"C:\Program Files\Java\j2re1.4.2_05\lib\ext\QTJava.zip";C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=BENMYRA ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Myra LOGONSERVER=\\BENMYRA NUMBER_OF_PROCESSORS=1 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\ATI Technologies\ATI Control Panel;C:\Program Files\Common Files\Adobe\AGL;C:\Program Files\QuickTime\QTSystem\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 6 Model 13 Stepping 6, GenuineIntel PROCESSOR_LEVEL=6 PROCESSOR_REVISION=0d06 ProgramFiles=C:\Program Files PROMPT=$P$G QTJAVA=C:\Program Files\Java\jre1.6.0_02\lib\ext\QTJava.zip SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\Myra\LOCALS~1\Temp TMP=C:\DOCUME~1\Myra\LOCALS~1\Temp USERDOMAIN=BENMYRA USERNAME=Myra USERPROFILE=C:\Documents and Settings\Myra windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- Benetton (admin) Myra (admin) Administrator (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\Common Files\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\IsUninst.exe -fC:\WINDOWS\orun32.isu --> C:\WINDOWS\Modio\SLAMR2KO\Setup.exe /Remove --> C:\WINDOWS\system32\\MSIEXEC.EXE /x {9541FED0-327F-4df0-8B96-EF57EF622F19} --> C:\WINDOWS\system32\drivers\unMTCDIO.exe --> C:\WINDOWS\system32\Macromed\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Macromed\SHOCKW~1\Install.log --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> MsiExec.exe /X{0CA3D4B6-23FF-4ACC-8267-B6B0D66D0272} --> MsiExec.exe /X{1526D87C-A955-4FAB-BF18-697BA457E352} --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0BEDBD4E-2D34-47B5-9973-57E62B29307C}\setup.exe" --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2637C347-9DAD-11D6-9EA2-00055D0CA761}\Setup.EXE" -uninstall --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE --> rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean --> rundll32.exe "C:\Program Files\Synaptics\SynTP\SynISDLL.dll",standAloneUninstall --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf µTorrent --> "C:\Program Files\uTorrent\uninstall.exe" ACDSee 8 --> MsiExec.exe /I{AE80641A-0C8D-4670-A518-B4EC154B1027} Adobe Bridge 1.0 --> MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000103} Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5B39} Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-1033-0000-8E67-000000000001} Adobe Illustrator CS2 --> msiexec /I {B2F5D08C-7E79-4FCD-AAF4-57AD35FF0601} Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D} Adobe Reader 7.0.9 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70900000002} Adobe Stock Photos 1.0 --> MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A} Adobe SVG Viewer 3.0 --> C:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Winstall.exe -u -fC:\Program Files\Common Files\Adobe\SVG Viewer 3.0\Uninstall\Install.log Apple Mobile Device Support --> MsiExec.exe /I{3EBD3749-304E-4A4C-9575-C00E5F015217} Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4} CC_ccStart --> MsiExec.exe /I{D6414CC7-F215-467F-88B1-546ED863F35B} ccCommon --> MsiExec.exe /I{DC367608-64A7-4BF7-92F4-8BAA25BA02DB} Compatibility Pack for the 2007 Office system --> MsiExec.exe /X{90120000-0020-0409-0000-0000000FF1CE} DivX Content Uploader --> C:\Program Files\DivX\DivXContentUploaderUninstall.exe /CUPLOADER DivX Web Player --> C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN ffdshow (remove only) --> "C:\Program Files\ffdshow\uninstall.exe" Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe" ICQ Toolbar --> regsvr32 /u /s "C:\PROGRA~1\ICQTOO~1\toolbaru.dll" IExplorer Security Plug-in --> "C:\Program Files\Video ActiveX Access\iesunst.exe" Invoke Solutions Participant 5.5.0.1437 --> "C:\Program Files\Invoke Solutions\Participant\5.5\unins000.exe" iTunes --> MsiExec.exe /I{B045B608-4A47-4C77-9EAD-06C394503306} Java 2 Runtime Environment, SE v1.4.2_05 --> MsiExec.exe /I{7148F0A8-6813-11D6-A77B-00B0D0142050} Java™ 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Java™ SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE LiveUpdate 1.90 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U Messenger Service --> "C:\Program Files\Video ActiveX Access\imsunst.exe" Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe" Microsoft Office XP Professional with FrontPage --> MsiExec.exe /I{90280409-6000-11D3-8CFE-0050048383C9} Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe" Mozilla Firefox (2.0.0.8) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe MSRedist --> MsiExec.exe /I{FC37ABD0-2108-4beb-B010-1254E0662B5A} Nav Subscription year 2002 - 2003 for Win95 to XP --> C:\Documents and Settings\All Users\Application Data\Symantec\LiveSubscribe\Uninstal.exe Nero 7 Ultra Edition --> MsiExec.exe /I{5241FB1B-9CF5-448C-3BFD-1AE58B061033} neroxml --> MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} Norton AntiVirus 2004 --> MsiExec.exe /X{C6F5B6CF-609C-428E-876F-CA83176C021B} Norton AntiVirus 2004 (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\SymSetup\{C6F5B6CF-609C-428E-876F-CA83176C021B}.exe /X Norton AntiVirus Parent MSI --> MsiExec.exe /I{E5EE9939-259F-4DE2-8023-5C49E16A4F43} QuickTime --> MsiExec.exe /I{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC} Security Update for Step By Step Interactive Training (KB923723) --> "C:\WINDOWS\$NtUninstallKB923723$\spuninst\spuninst.exe" Sonic RecordNow! --> MsiExec.exe /I{9541FED0-327F-4DF0-8B96-EF57EF622F19} Symantec Script Blocking Installer --> MsiExec.exe /I{D327AFC9-7BAA-473A-8319-6EB7A0D40138} SymNet --> MsiExec.exe /I{E47EE8FB-ACC0-4608-859C-4E2851B18A6A} Time Zone Data Update Tool for Microsoft Office Outlook --> MsiExec.exe /X{95120000-0038-0409-0000-0000000FF1CE} Uniblue RegistryBooster 2 --> "C:\Program Files\Uniblue\RegistryBooster 2\unins000.exe" Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe" WinRAR archiver --> C:\Program Files\WinRAR\uninstall.exe Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type3824 / Error Event Submitted/Written: 11/02/2007 04:18:48 PM Event ID/Source: 1002 / Application Hang Event Description: Hanging application iexplore.exe, version 7.0.6000.16544, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Event Record #/Type3823 / Error Event Submitted/Written: 11/02/2007 03:33:09 PM Event ID/Source: 1002 / Application Hang Event Description: Hanging application MRT.exe, version 1.34.2288.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. Event Record #/Type3814 / Error Event Submitted/Written: 11/02/2007 00:42:05 PM Event ID/Source: 1000 / Application Error Event Description: Faulting application syntpenh.exe, version 7.8.1.0, faulting module syntpfcs.dll, version 7.8.1.0, fault address 0x00001750. Processing media-specific event for [syntpenh.exe!ws!] Event Record #/Type3812 / Warning Event Submitted/Written: 11/02/2007 00:41:30 PM Event ID/Source: 1524 / Userenv Event Description: Windows cannot unload your classes registry file - it is still in use by other applications or services. The file will be unloaded when it is no longer in use. Event Record #/Type3811 / Error Event Submitted/Written: 11/02/2007 00:32:20 PM Event ID/Source: 1002 / Application Hang Event Description: Hanging application MRT.exe, version 1.31.2276.0, hang module hungapp, version 0.0.0.0, hang address 0x00000000. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type14752 / Error Event Submitted/Written: 11/02/2007 05:26:43 PM Event ID/Source: 7016 / Service Control Manager Event Description: The SmartLinkService service has reported an invalid current state 0. Event Record #/Type14717 / Error Event Submitted/Written: 11/02/2007 04:29:39 PM Event ID/Source: 7000 / Service Control Manager Event Description: The MTCDIO service failed to start due to the following error: %%2 Event Record #/Type14693 / Error Event Submitted/Written: 11/02/2007 04:23:17 PM Event ID/Source: 7000 / Service Control Manager Event Description: The MTCDIO service failed to start due to the following error: %%2 Event Record #/Type14647 / Error Event Submitted/Written: 11/02/2007 00:56:00 PM Event ID/Source: 7000 / Service Control Manager Event Description: The MTCDIO service failed to start due to the following error: %%2 Event Record #/Type14579 / Error Event Submitted/Written: 11/02/2007 08:28:23 AM Event ID/Source: 7000 / Service Control Manager Event Description: The MTCDIO service failed to start due to the following error: %%2 -- End of Deckard's System Scanner: finished at 2007-11-02 18:07:41 ------------ |
|
|
Nov 2 2007, 09:41 AM
Post
#2
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
Hello Stomp1
Welcome to G2Go. You have quite a few files that we need to take care of . Let's start by doing this: * Click here to download HJTsetup.exe
After that Download ComboFix from Here or Here to your Desktop.
In case you have used Combofix before, please delete the version you have and redownload it again, because Combofix is being updated everyday. In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix, please disable your scanner and redownload Combofix again. Because some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them. |
|
|
Nov 2 2007, 10:45 PM
Post
#3
|
|
|
New Member ![]() Posts: 8 OS: XP |
Dear Kahdah,
Thank you for replying so promptly. I really appreciate this. The log files on HiJackThis and ComboFix are attached below as instructed:- HiJackThis log:- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:33:30 AM, on 11/3/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\system32\drivers\Icon.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Apps\Powercinema\PCMService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\iTunes\iTunesHelper.exe C:\WINDOWS\system32\WinAvXX.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo! R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\printer.exe O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Protection Bar - {29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00} - C:\Program Files\Video ActiveX Access\iesbpl.dll (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Icon] C:\WINDOWS\system32\drivers\Icon.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [WinAVX] C:\WINDOWS\system32\WinAvXX.exe O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S O4 - HKLM\..\Policies\Explorer\Run: [rare] C:\Program Files\Video ActiveX Access\imsmain.exe O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: system.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: autorun.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - AppInit_DLLs: sulimo.dat O22 - SharedTaskScheduler: adirondack - {547aaa89-7e6b-42b4-b112-a64955f86a2a} - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O24 - Desktop Component 0: (no name) - file:///C:/DOCUME~1/Myra/LOCALS~1/Temp/msohtml1/01/clip_image002.jpg -- End of file - 8508 bytes Here is the ComboFix Log file:- ComboFix 07-11-01.1 - Myra 2007-11-03 11:56:14.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1596 [GMT 11:00] Running from: C:\Documents and Settings\Myra\Desktop\ComboFix.exe * Created a new restore point . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\All Users\Start Menu\Programs\Startup\autorun.exe C:\Documents and Settings\Benetton\Start Menu\Programs\Startup\system.exe C:\Documents and Settings\Myra\Start Menu\Programs\Startup\system.exe C:\Program Files\video activex access C:\Program Files\video activex access\ot.ico C:\Program Files\video activex access\Thumbs.db C:\Program Files\video activex access\ts.ico C:\Program Files\VirusProtectPro 3.5 C:\Program Files\VirusProtectPro 3.5\ignored.lst C:\Program Files\VirusProtectPro 3.5\vpp.ini C:\WINDOWS\system32\drivers\Icon.exe C:\WINDOWS\system32\printer.exe C:\WINDOWS\system32\WinAvXX.exe . ((((((((((((((((((((((((( Files Created from 2007-10-03 to 2007-11-03 ))))))))))))))))))))))))))))))) . 2007-11-03 11:42 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-03 11:33 <DIR> d-------- C:\Program Files\Trend Micro 2007-11-02 17:24 <DIR> d-------- C:\Deckard 2007-11-02 15:35 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\Uniblue 2007-11-02 13:12 <DIR> d-------- C:\db88a8d408147e526b38f155 2007-11-02 13:11 8,706,680 --a------ C:\Program Files\Windows-KB890830-V1.34.exe 2007-11-02 00:54 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-10-27 18:20 0 --a------ C:\WINDOWS\nsreg.dat 2007-10-26 00:02 <DIR> d-------- C:\Program Files\iPod 2007-10-26 00:02 <DIR> d-------- C:\Documents and Settings\Benetton\Application Data\Apple Computer 2007-10-26 00:01 <DIR> d-------- C:\Program Files\QuickTime 2007-10-26 00:01 <DIR> d-------- C:\Program Files\iTunes 2007-10-26 00:00 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2007-10-26 00:00 <DIR> d-------- C:\Program Files\Common Files\Apple 2007-10-26 00:00 <DIR> d-------- C:\Program Files\Apple Software Update 2007-10-26 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-10-26 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2007-10-25 21:18 <DIR> d-------- C:\Documents and Settings\Benetton\Application Data\ICQ Toolbar 2007-10-25 16:22 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\ICQ Toolbar 2007-10-25 16:15 <DIR> d-------- C:\Program Files\ICQToolbar 2007-10-17 20:10 <DIR> d-------- C:\WINDOWS\system32\NtmsData 2007-10-11 22:08 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\ACD Systems 2007-10-11 22:05 <DIR> d-------- C:\Program Files\ACD Systems 2007-10-10 15:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll 2007-10-03 20:24 <DIR> d-------- C:\Documents and Settings\Benetton\Application Data\ACD Systems 2007-10-03 20:19 <DIR> d-------- C:\Program Files\Common Files\ACD Systems 2007-10-03 20:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ACD Systems 2007-10-03 20:16 <DIR> d-------- C:\WINDOWS\Downloaded Installations . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-01 22:28 --------- d-----w C:\Program Files\Norton AntiVirus 2007-11-01 07:51 --------- d-----w C:\Program Files\Movies 2007-10-31 05:37 --------- d-----w C:\Documents and Settings\Myra\Application Data\eBookPro6 2007-10-30 22:43 --------- d-----w C:\Program Files\MSECache 2007-10-25 05:16 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-10-15 03:12 --------- d-----w C:\Program Files\Symantec 2007-10-15 03:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-10-05 14:03 44,184 ----a-w C:\Documents and Settings\Myra\Application Data\GDIPFONTCACHEV1.DAT 2007-09-27 23:04 --------- d-----w C:\Documents and Settings\Myra\Application Data\Yahoo! 2007-09-27 11:46 --------- d-----w C:\Documents and Settings\Benetton\Application Data\Yahoo! 2007-09-27 11:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2007-09-27 11:42 --------- d-----w C:\Program Files\Yahoo! 2007-09-27 09:20 --------- d-----w C:\Program Files\DivX 2007-09-22 13:24 --------- d-----w C:\Documents and Settings\Benetton\Application Data\uTorrent 2007-09-21 10:36 --------- d-----w C:\Documents and Settings\Myra\Application Data\Sonic 2007-09-21 10:36 --------- d-----w C:\Documents and Settings\Myra\Application Data\Leadertech 2007-09-19 22:46 --------- d-----w C:\Program Files\Invoke Solutions 2007-09-14 08:44 40,296 ----a-w C:\Documents and Settings\Benetton\Application Data\GDIPFONTCACHEV1.DAT 2007-09-09 05:37 --------- d-----w C:\Program Files\BitTorrent 2007-09-08 22:34 --------- d-----w C:\Program Files\Common Files\Ahead 2007-09-08 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead 2007-09-08 13:26 --------- d-----w C:\Documents and Settings\Benetton\Application Data\Ahead 2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-08-20 10:04 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll 2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll 2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll 2007-08-20 10:04 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll 2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-20 10:04 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll 2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll 2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll 2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll 2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 14:00] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-09-26 11:01] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-09-26 11:01] "SoundMan"="SOUNDMAN.EXE" [2004-04-28 17:19 C:\WINDOWS\SOUNDMAN.EXE] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 21:10] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 05:00] "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2004-10-08 03:14] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-18 12:50] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-05-26 19:32] "NWEReboot"="" [] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-08 09:31] "SNM"="C:\Program Files\SpyNoMore\SNM.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 07:24] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 15:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 03:24] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-04-21 18:03] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00] "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [] R2 MTC0005_MTCDIO;Wireless HotKey Driver;C:\WINDOWS\system32\drivers\MTCDIO.sys R3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys R3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys R3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys S2 MTCDIO;MTCDIO;C:\WINDOWS\system32\DRIVERS\MTCDIO.sys . Contents of the 'Scheduled Tasks' folder "2007-10-30 22:44:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" "2007-11-02 09:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job" - C:\PROGRA~1\NORTON~1\Navw32.exe "2007-11-03 01:19:47 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-03 12:27:51 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-03 12:39:19 - machine was rebooted . --- E O F --- |
|
|
Nov 3 2007, 06:14 AM
Post
#4
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
You are welcome
1. Please open Notepad
CODE Registry:: [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser] "{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}"=- [-HKEY_CLASSES_ROOT\CLSID\{29C5A3B6-9A8D-4FA0-B5AD-3E20F4AA5C00}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinAVX"=- [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "WinAVX"=- [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=dword:00000000 "DisableTaskMgr"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoControlPanel"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "rare"=- [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Shell"="Explorer.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"="" 3. Save the above as CFScript.txt 4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again. ![]() 5. After reboot, (in case it asks to reboot),after reboot then please save the log to post in your next reply. =============================================================== Please download AVG Anti-Spyware from HERE and save that file to your desktop. This is a 30 day trial of the program
Please post back with these logs: Combofix log AVG anstispyware log New Hijackthis log. This post has been edited by kahdah: Nov 3 2007, 06:15 AM |
|
|
Nov 4 2007, 05:54 AM
Post
#5
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
Here are the Combo log, AVG Anti-Spyware log and new HiJackThis log files. BTW, any word of advice for me (like what software I should have to protect my system from unwanted future spy, or when transferring files on the internet, etc) to protect my system from these malware in future? Combo log: ComboFix 07-11-01.1 - Benetton 2007-11-04 16:55:01.2 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1621 [GMT 11:00] Running from: C:\Documents and Settings\Benetton\Desktop\ComboFix.exe Command switches used :: C:\Documents and Settings\Benetton\Desktop\CFScript.txt * Created a new restore point . ((((((((((((((((((((((((( Files Created from 2007-10-04 to 2007-11-04 ))))))))))))))))))))))))))))))) . 2007-11-04 15:50 <DIR> d-------- C:\DRV 2007-11-04 15:50 <DIR> d-------- C:\DevLog 2007-11-03 23:29 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\uTorrent 2007-11-03 11:42 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-11-03 11:33 <DIR> d-------- C:\Program Files\Trend Micro 2007-11-02 17:24 <DIR> d-------- C:\Deckard 2007-11-02 15:35 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\Uniblue 2007-11-02 13:12 <DIR> d-------- C:\db88a8d408147e526b38f155 2007-11-02 13:11 8,706,680 --a------ C:\Program Files\Windows-KB890830-V1.34.exe 2007-11-02 00:54 626,688 --a------ C:\WINDOWS\system32\msvcr80.dll 2007-10-27 18:20 0 --a------ C:\WINDOWS\nsreg.dat 2007-10-26 00:02 <DIR> d-------- C:\Program Files\iPod 2007-10-26 00:02 <DIR> d-------- C:\Documents and Settings\Benetton\Application Data\Apple Computer 2007-10-26 00:01 <DIR> d-------- C:\Program Files\QuickTime 2007-10-26 00:01 <DIR> d-------- C:\Program Files\iTunes 2007-10-26 00:00 <DIR> d----c--- C:\WINDOWS\system32\DRVSTORE 2007-10-26 00:00 <DIR> d-------- C:\Program Files\Common Files\Apple 2007-10-26 00:00 <DIR> d-------- C:\Program Files\Apple Software Update 2007-10-26 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple Computer 2007-10-26 00:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple 2007-10-25 21:18 <DIR> d-------- C:\Documents and Settings\Benetton\Application Data\ICQ Toolbar 2007-10-25 16:22 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\ICQ Toolbar 2007-10-25 16:15 <DIR> d-------- C:\Program Files\ICQToolbar 2007-10-17 20:10 <DIR> d-------- C:\WINDOWS\system32\NtmsData 2007-10-11 22:08 <DIR> d-------- C:\Documents and Settings\Myra\Application Data\ACD Systems 2007-10-11 22:05 <DIR> d-------- C:\Program Files\ACD Systems 2007-10-10 15:09 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-11-04 05:15 --------- d-----w C:\Documents and Settings\Benetton\Application Data\uTorrent 2007-11-04 04:18 --------- d-----w C:\Program Files\BitTorrent 2007-11-03 12:29 --------- d-----w C:\Program Files\uTorrent 2007-11-03 09:04 --------- d-----w C:\Program Files\Norton AntiVirus 2007-11-01 07:51 --------- d-----w C:\Program Files\Movies 2007-10-31 05:37 --------- d-----w C:\Documents and Settings\Myra\Application Data\eBookPro6 2007-10-30 22:43 --------- d-----w C:\Program Files\MSECache 2007-10-25 05:16 --------- d--h--w C:\Program Files\InstallShield Installation Information 2007-10-15 03:12 --------- d-----w C:\Program Files\Symantec 2007-10-15 03:12 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2007-10-11 11:05 --------- d-----w C:\Program Files\Common Files\ACD Systems 2007-10-05 14:03 44,184 ----a-w C:\Documents and Settings\Myra\Application Data\GDIPFONTCACHEV1.DAT 2007-10-03 09:24 --------- d-----w C:\Documents and Settings\Benetton\Application Data\ACD Systems 2007-10-03 09:19 --------- d-----w C:\Documents and Settings\All Users\Application Data\ACD Systems 2007-09-27 23:04 --------- d-----w C:\Documents and Settings\Myra\Application Data\Yahoo! 2007-09-27 11:46 --------- d-----w C:\Documents and Settings\Benetton\Application Data\Yahoo! 2007-09-27 11:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\Yahoo! Companion 2007-09-27 11:42 --------- d-----w C:\Program Files\Yahoo! 2007-09-27 09:20 --------- d-----w C:\Program Files\DivX 2007-09-21 10:36 --------- d-----w C:\Documents and Settings\Myra\Application Data\Sonic 2007-09-21 10:36 --------- d-----w C:\Documents and Settings\Myra\Application Data\Leadertech 2007-09-19 22:46 --------- d-----w C:\Program Files\Invoke Solutions 2007-09-14 08:44 40,296 ----a-w C:\Documents and Settings\Benetton\Application Data\GDIPFONTCACHEV1.DAT 2007-09-08 22:34 --------- d-----w C:\Program Files\Common Files\Ahead 2007-09-08 17:32 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead 2007-09-08 13:26 --------- d-----w C:\Documents and Settings\Benetton\Application Data\Ahead 2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:15 683,520 ----a-w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-08-20 10:04 824,832 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-20 10:04 671,232 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-20 10:04 63,488 ------w C:\WINDOWS\system32\dllcache\icardie.dll 2007-08-20 10:04 6,058,496 ------w C:\WINDOWS\system32\dllcache\ieframe.dll 2007-08-20 10:04 52,224 ------w C:\WINDOWS\system32\dllcache\msfeedsbs.dll 2007-08-20 10:04 477,696 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-20 10:04 459,264 ------w C:\WINDOWS\system32\dllcache\msfeeds.dll 2007-08-20 10:04 44,544 ----a-w C:\WINDOWS\system32\dllcache\iernonce.dll 2007-08-20 10:04 384,512 ------w C:\WINDOWS\system32\dllcache\iedkcs32.dll 2007-08-20 10:04 383,488 ------w C:\WINDOWS\system32\dllcache\ieapfltr.dll 2007-08-20 10:04 3,584,512 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-20 10:04 27,648 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-20 10:04 267,776 ------w C:\WINDOWS\system32\dllcache\iertutil.dll 2007-08-20 10:04 232,960 ------w C:\WINDOWS\system32\dllcache\webcheck.dll 2007-08-20 10:04 230,400 ----a-w C:\WINDOWS\system32\dllcache\ieaksie.dll 2007-08-20 10:04 214,528 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-20 10:04 193,024 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-20 10:04 153,088 ----a-w C:\WINDOWS\system32\dllcache\ieakeng.dll 2007-08-20 10:04 132,608 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-20 10:04 124,928 ------w C:\WINDOWS\system32\dllcache\advpack.dll 2007-08-20 10:04 105,984 ------w C:\WINDOWS\system32\dllcache\url.dll 2007-08-20 10:04 102,400 ------w C:\WINDOWS\system32\dllcache\occache.dll 2007-08-20 10:04 1,152,000 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-17 10:21 625,152 ------w C:\WINDOWS\system32\dllcache\iexplore.exe 2007-08-17 10:20 63,488 ------w C:\WINDOWS\system32\dllcache\ie4uinit.exe 2007-08-17 10:20 13,824 ------w C:\WINDOWS\system32\dllcache\ieudinit.exe 2007-08-17 07:34 161,792 ----a-w C:\WINDOWS\system32\dllcache\ieakui.dll . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-04 14:00] "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00] "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-04 14:00] "SynTPLpr"="C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" [2003-09-26 11:01] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2003-09-26 11:01] "SoundMan"="SOUNDMAN.EXE" [2004-04-28 17:19 C:\WINDOWS\SOUNDMAN.EXE] "ATIPTA"="C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-05-15 21:10] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" [2007-07-12 05:00] "PCMService"="c:\Apps\Powercinema\PCMService.exe" [2004-10-08 03:14] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2003-08-18 12:50] "Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-05-26 19:32] "NWEReboot"="" [] "TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-11-08 09:31] "SNM"="C:\Program Files\SpyNoMore\SNM.exe" [] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2007-06-29 07:24] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 17:40] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 15:42] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-14 03:24] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" [2006-04-21 18:03] "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 14:00] "updateMgr"="C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" [2006-03-30 17:45] C:\Documents and Settings\All Users\Start Menu\Programs\Startup\ Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 23:05:26] Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 04:01:04] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "DisableRegistryTools"=0 (0x0) "DisableTaskMgr"=0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableTaskMgr"=0 (0x0) R2 MTC0005_MTCDIO;Wireless HotKey Driver;C:\WINDOWS\system32\drivers\MTCDIO.sys R3 EMSCR;EMSCR;C:\WINDOWS\system32\DRIVERS\EMS7SK.sys R3 ESDCR;ESDCR;C:\WINDOWS\system32\DRIVERS\ESD7SK.sys R3 ESMCR;ESMCR;C:\WINDOWS\system32\DRIVERS\ESM7SK.sys S2 MTCDIO;MTCDIO;C:\WINDOWS\system32\DRIVERS\MTCDIO.sys [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{011e5bb0-0b79-11dc-8b74-0040d07c44a6}] \Shell\AutoRun\command - D:\Setup.exe -auto . Contents of the 'Scheduled Tasks' folder "2007-10-30 22:44:01 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job" "2007-11-02 09:00:00 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer.job" - C:\PROGRA~1\NORTON~1\Navw32.exe "2007-11-04 05:22:01 C:\WINDOWS\Tasks\Symantec NetDetect.job" - C:\Program Files\Symantec\LiveUpdate\NDETECT.EXE . ************************************************************************** catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-11-04 17:15:39 Windows 5.1.2600 Service Pack 2 NTFS scanning hidden processes ... scanning hidden autostart entries ... scanning hidden files ... scan completed successfully hidden files: 0 ************************************************************************** . Completion time: 2007-11-04 17:29:39 C:\ComboFix2.txt ... 2007-11-03 12:39 . --- E O F --- AVG Anti-Spyware log: --------------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 7:34:31 PM 11/4/2007 + Scan result: C:\Documents and Settings\Benetton\Desktop\My File\Software\All New Vista Automated Activation Crack Relly works.rar/All New Vista Automated Activation Crack Relly works\GET CASH MONEY IN 30 MINUTES - DISCOVER HOW NOW\Install.exe -> Adware.Casino : Cleaned with backup (quarantined). :mozilla.142:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.143:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.240:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.247:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.251:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.310:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.385:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.543:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.544:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.545:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.546:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.547:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.548:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.549:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.550:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.551:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.552:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.553:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@msnservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.24:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.26:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.47:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.48:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@3.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.16:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.17:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.18:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.7:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.8:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.9:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.179:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.470:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.471:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.472:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.43:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.484:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.434:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.23:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.24:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.25:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.485:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.133:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.415:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.49:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.38:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.39:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.40:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.49:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.50:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.51:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.52:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.83:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.89:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.265:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.358:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.410:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.522:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.523:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.524:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.525:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.526:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.527:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.537:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.292:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.293:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@searchportal.information[1].txt -> TrackingCookie.Information : Cleaned. :mozilla.257:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.157:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.312:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned. :mozilla.146:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.384:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.175:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.176:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.177:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.178:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.422:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.425:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.426:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.427:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.428:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.429:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.430:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.431:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.435:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.436:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.437:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.438:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.367:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.368:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.339:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.340:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.341:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.342:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.343:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@revenue[2].txt -> TrackingCookie.Revenue : Cleaned. :mozilla.185:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.186:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.188:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.189:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.190:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.191:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@revsci[2].txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@revsci[2].txt -> TrackingCookie.Revsci : Cleaned. :mozilla.318:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.319:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.320:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.321:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.322:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.542:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.258:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.259:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.260:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.261:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.20:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.21:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.22:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.26:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.119:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Myra\Cookies\myra@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.86:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.122:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.130:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.28:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.29:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.30:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.31:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.32:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.33:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.34:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.35:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.35:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.36:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.36:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.37:C:\Documents and Settings\Benetton\Application Data\Mozilla\Firefox\Profiles\5r3yxuc7.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.37:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.38:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.39:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.40:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.41:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.42:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.43:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.44:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.45:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.46:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.127:C:\Documents and Settings\Myra\Application Data\Mozilla\Firefox\Profiles\s03jjzhr.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\Benetton\Cookies\benetton@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. ::Report end New HiJackThis log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 7:42:23 PM, on 11/4/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe C:\Apps\Powercinema\PCMService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe C:\Program Files\iPod\bin\iPodService.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe" O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 7959 bytes |
|
|
Nov 4 2007, 06:55 AM
Post
#6
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
Yes keeping an up to date antivirus and running Full system scans Bi-weekly will help prevent future infections.
Also an up to date antispyware program run Bi weekly will also prevent future infctions. I see that you have uTorrent installed. Having P2p programs such as these raise the possibility of getting infected again. See here for information on P2P's. I will leave it up to you if you want to remove it. To remove it just simply uninstall it then delete this folder>C:\Program Files\UTorrent =========================================================== After that please update your Java: Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version of Java components and upgrade the application. Beware it is NOT supported for use in 9x or ME and probably will not install in those systems Ugrading Java:
Please download ATF Cleaner by Atribune. This program is for XP and Windows 2000 only
Under Main choose: Select All Click the Empty Selected button.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click the Empty Selected button. NOTE: If you would like to keep your saved passwords, please click No at the prompt. For Technical Support, double-click the e-mail address located at the bottom of each menu ============================================ Please then do an online scan with Kaspersky WebScanner (This scanner is for use with internet explorer only) Click on Kaspersky Online Scanner You will be promted to install an ActiveX component from Kaspersky, Click Yes.
Scan Mail Bases
PLease post back with these logs: Kaspersky log New Hijackthis log |
|
|
Nov 5 2007, 09:40 AM
Post
#7
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
I encountered some problems when I did the scanning via Kespersky. The scan was halted in Adobe Stock Photo for a few hours. I cancelled the first scan and did it the second time and the same happened. It halted at 25% showing reading at Adobe Stock Photo (Adobe Bridge). Attached is the snapshot for your reference. Please advice the course of action for this. Should I uninstall Adobe Stock Photo/Bridge? Thanks, Stomp1
Attached File(s)
|
|
|
Nov 5 2007, 06:10 PM
Post
#8
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
You can uninstall it if you don't mind.(Just temporarily)
It may be the only way to properly scan your computer. Make sure to get your license key so you can reinstall it. You can redownload it from the Adobe site. Try it again after that please. |
|
|
Nov 5 2007, 11:10 PM
Post
#9
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
I managed to pass 25% scanned at Kespersky but when it reached 99%, it halted at C:\WINDOWS\system32\oobe\msobshel.htm for hours. It just won't complete the 1% left. Since this is file is part of windows, I am unable to delete it. Any idea what would be the next available option for me? Thanks, Stomp1 |
|
|
Nov 6 2007, 03:53 AM
Post
#10
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
If it got that far then that is fine do you have the log?
|
|
|
Nov 6 2007, 10:39 PM
Post
#11
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
That is exactly the problem. The log report won't pop up unless Kespersky complete a 100% scan? Unless, there is another way to get this report, maybe it is stored somewhere on the 99% scan, do let me know. Thanks. Regards, Myra |
|
|
Nov 7 2007, 03:53 AM
Post
#12
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
When it get's to tyhat point click on stop.
Then it should popup giving you an option to save it. |
|
|
Nov 7 2007, 09:59 PM
Post
#13
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
Thank you for your patience. It is strange that now I am able to complete the 100% scan at Kaspersky. Attached here is the kaspersky log and new hijackthis log as requested. Kespersky Log: ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Thursday, November 08, 2007 11:54:17 AM Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.98.0 Kaspersky Anti-Virus database last update: 8/11/2007 Kaspersky Anti-Virus database records: 453728 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: extended Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ Q:\ Scan Statistics: Total number of scanned objects: 79395 Number of viruses found: 5 Number of infected objects: 10 Number of suspicious objects: 0 Duration of the scan process: 01:16:41 Infected Object Name / Virus Name / Last Action C:\9267a8617378d9a8b2daff\$shtdwn$.req Object is locked skipped C:\9267a8617378d9a8b2daff\mrt.exe Object is locked skipped C:\9267a8617378d9a8b2daff\mrtstub.exe Object is locked skipped C:\db88a8d408147e526b38f155\mrt.exe Object is locked skipped C:\db88a8d408147e526b38f155\mrtstub.exe Object is locked skipped C:\Documents and Settings\All Users\Application Data\Microsoft\Dr Watson\user.dmp Object is locked skipped C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped C:\Documents and Settings\Benetton\Cookies\index.dat Object is locked skipped C:\Documents and Settings\Benetton\Desktop\My File\Software\AVG.v7.5.490.Anti-Virus Professional Edition.Incl.Keygen-FULL\avg_7.5.x_keygen.exe Infected: Trojan-Dropper.Win32.Agent.clt skipped C:\Documents and Settings\Benetton\Desktop\My File\Software\Slysoft AnyDVD 6.1.7.4 Final __KEY\SetupAnyDVD6174.exe Infected: Trojan.Win32.Chifrax.a skipped C:\Documents and Settings\Benetton\Desktop\My File\Software\Windows.Vista.Activation.Crack\Windows.Vista.Activation.Crack.zip/Windows.Vista.Activation.Crack/install.exe Infected: not-virus:Hoax.Win32.Agent.p skipped C:\Documents and Settings\Benetton\Desktop\My File\Software\Windows.Vista.Activation.Crack\Windows.Vista.Activation.Crack.zip 7-Zip: infected - 1 skipped C:\Documents and Settings\Benetton\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\History\History.IE5\MSHist012007110820071109\index.dat Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Temp\Perflib_Perfdata_ee8.dat Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Temp\~DF4F78.tmp Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Temp\~DF4F83.tmp Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Documents and Settings\Benetton\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\Benetton\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Benetton\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\Myra\NTUSER.DAT Object is locked skipped C:\Documents and Settings\Myra\ntuser.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Cookies\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\History\History.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped C:\PC Solution File\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\PC Solution File\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped C:\PC Solution File\SmitfraudFix.exe RarSFX: infected - 2 skipped C:\Program Files\BitTorrent\gossip.girl.s01e07.hdtv.xvid-xor.[VTV].avi Object is locked skipped C:\Program Files\BitTorrent\Hostel-Part.2[2007][Unrated.Edition]DvDrip.AC3[Eng]-aXXo\Hostel-Part.2[2007][Unrated.Edition]DvDrip.AC3[Eng]-aXXo.avi Object is locked skipped C:\Program Files\Norton AntiVirus\AVApp.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVError.log Object is locked skipped C:\Program Files\Norton AntiVirus\AVVirus.log Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{30DD81CB-0D10-4DDE-A5BA-94D67265A2AB}\RP129\change.log Object is locked skipped C:\System Volume Information\_restore{30DD81CB-0D10-4DDE-A5BA-94D67265A2AB}\RP99\A0022642.EXE/data0000.cab/rBot.exe Infected: Backdoor.Win32.Ciadoor.gn skipped C:\System Volume Information\_restore{30DD81CB-0D10-4DDE-A5BA-94D67265A2AB}\RP99\A0022642.EXE/data0000.cab Infected: Backdoor.Win32.Ciadoor.gn skipped C:\System Volume Information\_restore{30DD81CB-0D10-4DDE-A5BA-94D67265A2AB}\RP99\A0022642.EXE Rsrc-Package: infected - 2 skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\Sti_Trace.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\wiadebug.log Object is locked skipped C:\WINDOWS\wiaservc.log Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed. New HiJackThis Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:55:54 AM, on 11/8/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Apps\Powercinema\PCMService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\uTorrent\utorrent.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-21-3827159811-3825654406-3671572164-1006\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (User 'Myra') O4 - HKUS\S-1-5-21-3827159811-3825654406-3671572164-1006\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S (User 'Myra') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 8203 bytes |
|
|
Nov 7 2007, 10:16 PM
Post
#14
|
|
![]() GeekU Teacher Posts: 13,397 From: Florida OS: Windows xp,Vista business |
You are welcome
============= Please re-open Hijackthis and place a check mark next to these entries listed below: O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) Now click on Fix checked and then close Hijackthis. =================================== Using Windows Explorer (to get there right-click your Start button and go to "Explore") Delete these folders/files listed below: C:\Documents and Settings\Benetton\Desktop\My File\Software\AVG.v7.5.490.Anti-Virus Professional Edition.Incl.Keygen-FULL C:\Documents and Settings\Benetton\Desktop\My File\Software\Windows.Vista.Activation.Crack C:\Documents and Settings\Benetton\Desktop\My File\Software\Slysoft AnyDVD 6.1.7.4 Final __KEY C:\PC Solution File\SmitfraudFix.exe Now close Windows Explorer. (If you cannot delete these files try booting into safe mode to delete them) After that you can delete any other tools that I had you use then empty your recycle bin. ========================================================= Then I will need you to reset your System Restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. (Windows XP) 1. Turn off System Restore.
Right-click *My Computer Click *Properties Click the *System Restore tab Check *Turn off System Restore Click *Apply, and then click *OK. 3. Turn ON System Restore.
Right-click *My Computer Click *Properties *UN-Check *Turn off System Restore* Check *Turn on System Restore Click *Apply, and then click *OK. http://support.microsoft.com/default.aspx?...kb;en-us;310405 ============================================ After that Your log is clean. The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again. Spybot Search & Destroy-Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections. Ad-Aware-Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well. Spyware Blaster - Great prevention tool to keep nasties from installing on your system. Spywareguard-Works as a Spyware "Shield" to protect your computer from getting malware in the first place. IE-SPYAD- puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there. Castle Cops To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein. If you have any further problems please feel free to contact G2Go. This post has been edited by kahdah: Nov 7 2007, 10:17 PM |
|
|
Nov 9 2007, 10:42 AM
Post
#15
|
|
|
New Member ![]() Posts: 8 OS: XP |
Hi Kahdah,
Thank you so much for all your help and also for the additional tips on keeping my system clean. Just out of curiosity, if say I didn't go through what I have done for the past few days when my machine was infected by malware and I did a system reformat instead, will the malware be gone or it will still be in my computer after reformating. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:35:27 AM, on 11/10/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16544) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\SAVScan.exe C:\WINDOWS\system32\slserv.exe C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Apps\Powercinema\PCMService.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\QuickTime\QTTask.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.sun.com/update/1.6.0/jin...ows-i586-jc.cab O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing) O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe -- End of file - 7775 bytes |
|
|
![]() ![]() |
Similar Topics
| Topic Title | Replies / Views | Topic Information | |||||
|---|---|---|---|---|---|---|---|
![]() |
18 / 5,563 | 11th October 2007 - 06:43 AM num.1 started - last by Stamper19 |
|||||
![]() |
5 / 1,016 | 22nd October 2007 - 12:50 PM TheMany41 started - last by Essexboy |
|||||
![]() |
16 / 1,037 | 12th April 2008 - 10:33 PM coolcricket started - last by kahdah |
|||||
![]() |
2 / 531 | 4th January 2008 - 01:36 PM dxbdude started - last by don77 |
|||||
|
Time is now: 8th November 2009 - 01:58 AM |
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks mentioned on this page are the property of their respective owners.
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy | Advertising