Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

MY MALWARE/SPYWARE LOG ! [RESOLVED]


  • This topic is locked This topic is locked

#1
DJ_Hellenic

DJ_Hellenic

    Member

  • Member
  • PipPip
  • 14 posts
Well when i restart my computer... i cannot start any applications...it just has the hourglass then it goes normal, no matter how many times I try. The about 10 minutes later, every program I tried to open just opens all at once. Later on when I'm on my computer, the windows pops up and says Windows Explorer encountered an error and it must close etc. etc. and I press dont send.

Then items in my system tray are missing, but are still running the background, but not in system tray...and finally, many programs dont close. I close a program, then notice it is still running in Task manager, FOR EXAMPLE listening to music on windows media player, exit out, and music is still playing. No clue why??

Anyway I did a HiJackThis Log and here it is.

Logfile of HijackThis v1.99.1
Scan saved at 10:35:39 PM, on 22/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\zHotkey.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\BigFix\BigFix.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Halis Family\My Documents\Progs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: ATLDistrib Object - {2353FCBC-012D-487B-8BF3-865C0929FBEB} - C:\WINDOWS\system32\awtss.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptoda...pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125874388531
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.m...ted/mvt/mvt.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.nullsoft....ayx_vp6_aac.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe


I ALSO DID A SCAN WITH EWIDO SECURITY SUITE, AND HERE IS THE LOG FILE FOR THAT.


---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 9:20:19 PM, 22/01/2006
+ Report-Checksum: 45F01CC9

+ Scan result:

:mozilla.11:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.273:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.274:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.275:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.276:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.457:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.458:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.462:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.494:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.496:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.520:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.977:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.978:C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis family@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis family@statcounter[2].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis [email protected][2].txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@statcounter[1].txt -> Spyware.Cookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Halis Family\Local Settings\Temp\Temporary Internet Files\Content.IE5\STQN45UZ\mm[1].js -> Spyware.Chitika : Cleaned with backup


::Report End

aNY HELP is greatly appreciated. Thanks.

Edited by DJ_Hellenic, 23 January 2006 - 10:31 PM.

  • 0

Advertisements


#2
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Hello DJ Hellenic, and welcome to GeeksToGo! My name is Matt and I will be assisting you with your malware issues.

Thank you for being patient with us and we apologize for the delay, but our helpers are very busy around here. I am currently working on your log and will post a fix for you shortly.
  • 0

#3
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Regards,
Matt
  • 0

#4
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hey Matt, thanks for the help so far.

Ok, here is my Vundo Scan Report :tazz:

VundoFix V4.0

Listing files found while scanning....

C:\WINDOWS\system32\awtss.dll
C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.bak1

C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.ini
Attempting to delete C:\WINDOWS\system32\sstwa.ini
C:\WINDOWS\system32\sstwa.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sstwa.bak1
C:\WINDOWS\system32\sstwa.bak1 Has been deleted!

Performing Repairs to the registry.
Done!



And here is my new HiJackThis! log.

Logfile of HijackThis v1.99.1
Scan saved at 2:56:54 PM, on 26/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Halis Family\My Documents\Progs\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptoda...pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125874388531
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.m...ted/mvt/mvt.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.nullsoft....ayx_vp6_aac.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
  • 0

#5
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Good job.

Please run a scan with HijackThis and place a check next to the following items:O4 - HKLM\..\Run: [ShowWnd] ShowWnd.exe
O20 - Winlogon Notify: awtss - C:\WINDOWS\system32\awtss.dll (file missing)

Now, using the Search program available in the Start menu, please search for the following file and tell me its location on your computer: ShowWnd.exe

If you have any trouble finding it, let me know.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report along with the location of the file I asked for and a fresh HijackThis log.
Regards,
Matt
  • 0

#6
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Hey Matt, when I run the HiJackThis scan again and checkmark those items, do I just leave them checkmarked? Or do I press Fix Selected to get rid of them. I'm just a bit unclear about that.

I will run the Panda scan first thing when I get back to my home.
Thank you.
  • 0

#7
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Oh I'm sorry! Yes, you need to leave them checked and then click Fix Checked.
  • 0

#8
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Ok, Here is the location of ShowWnd.exe
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ShowWnd.zip

Here is my Panda ActiveScan report.

Incident Status Location

Spyware:spyware/dluca Not disinfected Windows Registry
Spyware:Cookie/3 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@3[1].txt
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@888[3].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@adultfriendfinder[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@ask[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@banner[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@belnk[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@bravenet[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cassava[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@ccbill[2].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cdfreaks[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cgi-bin[2].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@clickbank[1].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Errorguard Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@errorguard[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@fortunecity[2].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@gangbangsquad[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@gostats[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@go[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@kinghost[1].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@kount[2].txt
Spyware:Cookie/Netster Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Mp3search Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@mp3search[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@offeroptimizer[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@realmedia[1].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@rightmedia[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@rn11[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@servlet[3].txt
Spyware:Cookie/SpywareStormer Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@spywarestormer[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/TeensForCash Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@teensforcash[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@tickle[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@toplist[2].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@webpower[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@yadro[1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.go.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[server.iad.liveperson.net/hc/38894410]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[server.iad.liveperson.net/hc/38894410]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.xiti.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/Qsrch Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.qsrch.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.ask.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.ath.belnk.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.gostats.com/]
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.master.mx-targeting.com/mx/servlet/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.rightmedia.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.terra.com.br/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.tickle.com/]
Spyware:Cookie/SaveNow Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.tracking.thunderdownloads.com/]
Spyware:Cookie/Versiontracker Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[.versiontracker.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[38894410]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[38894410]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Halis Family\Application Data\Mozilla\Firefox\Profiles\j6kxmmw2.default\cookies.txt[]
Spyware:Cookie/3 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@3[1].txt
Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@888[3].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@adultfriendfinder[2].txt
Spyware:Cookie/Ask Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@ask[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@banner[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@belnk[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@bravenet[2].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cassava[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@ccbill[2].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cdfreaks[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@cgi-bin[2].txt
Spyware:Cookie/Clickbank Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@clickbank[1].txt
Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@did-it[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Errorguard Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@errorguard[1].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@fortunecity[2].txt
Spyware:Cookie/GangbangSquad Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@gangbangsquad[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@gostats[1].txt
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@go[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@kinghost[1].txt
Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@kount[2].txt
Spyware:Cookie/Netster Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Mp3search Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@mp3search[1].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@offeroptimizer[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@realmedia[1].txt
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@rightmedia[2].txt
Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@rn11[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/Twain-Tech Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@servlet[3].txt
Spyware:Cookie/SpywareStormer Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@spywarestormer[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][2].txt
Spyware:Cookie/TeensForCash Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@teensforcash[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@tickle[2].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@toplist[2].txt
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@webpower[1].txt
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Affiliate fuel Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Buydomains Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis [email protected][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@xiti[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Halis Family\Cookies\halis family@yadro[1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@bravenet[1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@ccbill[2].txt
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis [email protected][1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@gostats[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Halis Family\Local Settings\Temp\Cookies\halis family@realmedia[1].txt
Spyware:Spyware/BetterInet Not disinfected C:\WINDOWS\inf\adrmcer.inf


And finally, my new HiJackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 12:43:15 AM, on 28/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\
  • 0

#9
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Seems it didnt allow my whole HiJackThis log in my last post LOL.
Well here it is.

Logfile of HijackThis v1.99.1
Scan saved at 12:43:15 AM, on 28/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\BitComet\BitComet.exe
C:\Documents and Settings\Halis Family\My Documents\Progs\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptoda...pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125874388531
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.m...ted/mvt/mvt.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.nullsoft....ayx_vp6_aac.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

Thanks alot for your help so far Matt. Your work is very appreciated. You guys are the best :tazz:
  • 0

#10
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    C:\WINDOWS\inf\adrmcer.inf
  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Run Ad-Aware with the latest update.
  • Download the latest version of Ad-Aware (Ad-Aware SE Build 1.06r1) from here.
  • If you have a previous version of Ad-Aware installed, during the installation of the new version you will be prompted to uninstall or keep the older version - be sure to uninstall the previous version.
  • After installing Ad-aware, you will be prompted to update the program and run a full scan. De-select all boxes so that it does not run.
  • Manually run "Ad-Aware SE Personal" and from the main screen Click on "Check for Updates Now".
  • Once the definitions have been updated:
  • Reconfigure Ad-Aware for Full Scan as per the following instructions:
    • Launch the program, and click on the Gear at the top of the start screen.
    • Under General Settings the following boxes should all be checked off: (Checked will be indicated by a green circle with a check mark in it, Un-Checked is a red circle with an X in it. If it is greyed out, those features are only available in the retail version.)
      • "Automatically save logfile"
      • Automatically quarantine objects prior to removal"
      • Safe Mode (always request confirmation)
      • Prompt to update outdated confirmation) - Change to 7 days.
    • Click the "Scanning" button (On the left side).
    • Under Drives & Folders, select "Scan within Archives"
    • Click "Click here to select Drives + folders" and select your installed hard drives.
    • Under Memory & Registry, select all options.
    • Click the "Advanced" button (On the left hand side).
    • Under "Shell Integration", select "Move deleted files to Recycle Bin".
    • Under "Log-file detail", select all options.
    • Click on the "Defaults" button on the left.
    • Type in the full url of what you want as your default homepage and searchpage e.g. http://www.google.com.
    • Click the "Tweak" button (Again, on the left hand side).
    • Expand "Scanning Engine" by clicking on the "+" (Plus) symbol and select the following:
      • "Unload recognized processes during scanning."
      • "Obtain command line of scanned processes"
      • "Scan registry for all users instead of current user only"
    • Under "Cleaning Engine", select the following:
      • "Automatically try to unregister objects prior to deletion."
      • "During removal, unload explorer and IE if necessary"
      • "Let Windows remove files in use at next reboot."
      • "Delete quarrantined objects after restoring"
    • Click on "Safety Settings" and select "Write-protect system files after repair (Hosts file, etc)"
    • Click on "Proceed" to save these Preferences.
    • Click on the "Scan Now" button on the left.
    • Under "Select Scan Mode, be sure to select "Use Custom Scanning Options".
  • Close all programs except ad-aware.
  • Click on "Next" in the bottom right corner to start the scan.
  • Run the Ad-Aware scan and allow it to remove everything it finds and then REBOOT - Even if not prompted to.
  • After you log back in, Ad-Aware may run to finalize the scan and remove any locked files that it may of found. Allow it to finish.
Plug-Ins for Ad-Aware (VX2 Cleaner)


*Close Ad-Aware, if it is currently open.

* Download the VX2 Cleaner 2.0 Plug-in Here.

* After installing, restart Ad-Aware before running the VX2 Cleaner.

*Using VX2 Cleaner 2.0

*NOTE: If you have earlier attempted to run Ad-Aware to remove VX2, you may need to run the VX2 Cleaner several times to remove possible VX2 remains.

*If you have already attempted to remove VX2 with Ad-Aware, do the following:

* Before running the VX2 Cleaner, make sure other anti-virus or anti-spyware applications are closed.

* Run the VX2 Cleaner. If you computer is infected with VX2, a dialog box with text such as "New VX2 variant found" or "VX2 variant 1 found" will appear.

* Press "Clean" and a dialog box with text "The first phase completed. Please reboot and perform a Smart Scan" will appear. After saving your work, reboot your system manually.

* Repeat this until the VX2 Cleaner reports "System clean". Press "Close" to exit.

* Run Ad-Aware one more time and scan your computer to make sure VX2 has been found and removed.
  • Manually download Latest definition file: Here
  • Please Note Version SE Build 1.06 is now available! This download is for use with Ad-Aware SE versions only.
  • Manual Installation: Unzip the archive, replace the existing file and restart Ad-Aware\Ad-Watch.
  • You can also use the webupdate component implemented in Ad-Aware to install this update.
Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Now please run the Panda ActiveScan again and post the results along with a fresh HJT log.

Regards,
Matt
  • 0

#11
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Alright Matt here it is,

I ran the instructions on Killbox, and received NO prompt containing the message PendingFileRenameOperations prompt.

Ad-Aware found 35 infected things, and all were removed. (latest version, definitions)

VX2 Cleaner 2.0 found nothing. I disabled antivirus and firewall. It just said System Clean.

I ran ATF Cleaner as you said, cleaned Main (sometimes use IE), and Firefox.

Here are the PandaScan and HJT logs. :)

PANDA SCAN - JAN.31

Incident Status Location

Spyware:spyware/dluca Not disinfected Windows Registry
Spyware:Spyware/BetterInet Not disinfected C:\!KillBox\adrmcer.inf



And finally my fresh HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 12:35:38 AM, on 31/01/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\zHotkey.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Digital Media Reader\shwiconem.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Halis Family\My Documents\Progs\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.ca/0SEENCA/SAOS01
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.ca
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CHotkey] zHotkey.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SunKistEM] C:\Program Files\Digital Media Reader\shwiconem.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.t...all/xscan60.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcaf...83/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.co...ad/MsnPUpld.cab
O16 - DPF: {5F0C30E4-1E72-4DCC-85E5-57810F1CA97B} (McUpdatePortalFactory Class) - http://www.amiuptoda...pdatePortal.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1125874388531
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {78AEEDE8-7345-4FB5-A8FE-4BFF16EF25FC} (McAfee Virtual Technician Control Class) - http://us-download.m...ted/mvt/mvt.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.c.../cpcScanner.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcaf...,20/mcgdmgr.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697519} (NsvPlayX Control) - http://www.nullsoft....ayx_vp6_aac.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe

EDIT: Just to note, after I posted all this i rebooted my computer once again. Yet the same problem. The only thing that oppens is Windows Explorer. When I try to open other applications it shows the hourglass then dissapears. Then roughly 5-10 minutes later the apps. i tried to open all open at once. :) :) :tazz:

Edited by DJ_Hellenic, 31 January 2006 - 12:05 AM.

  • 0

#12
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
DJ Hellenic,

All of your scans are coming back clean and I don't see any malware in your log. To get further assistance with your issue, please post in our Windows XP, 2000, 2003, NT forum. Be sure to include a link to this topic so that the experts there know you have been cleared in the malware forum. They will be better suited to assist you with this problem.

If you have no more malware-related questions, shall I post some tips for you to aid you in staying malware-free in the future?

Regards,
Matt
  • 0

#13
DJ_Hellenic

DJ_Hellenic

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks for the info Matt, I've asked for help in the XP Forum.

BTW, I think I'm pretty good with my spyware right now. I have SpywareBlaster, Microsoft anti-spyware, mcafee security, spybot etc. all installed and updated.

Thanks a lot for you're time, and for the help. It doesn't go unappreciated.
  • 0

#14
Matt.F

Matt.F

    Visiting Staff

  • Visiting Consultant
  • 512 posts
Not a problem. Glad to help. :tazz:
  • 0

#15
therock247uk

therock247uk

    Expert

  • Expert
  • 14,672 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP