Panda scan
Incident Status Location
Spyware:spyware/media-motor Not disinfected c:\windows\unstall.exe
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.atdmt.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.advertising.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.winfixer.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.xmts.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.2o7.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.burstnet.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.adviva.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.apmebf.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.overture.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.adtech.de/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.realmedia.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.targetnet.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.bravenet.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.fastclick.net/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.bfast.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.questionmarket.com/]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.atwola.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[sel.as-eu.falkag.net/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.statcounter.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.maxserving.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.xiti.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.hitbox.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.did-it.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.seeq.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[www48.seeq.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.toplist.cz/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.belnk.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.tickle.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.gostats.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.offeroptimizer.com/]
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\jigwzb7f.Default User\cookies.txt[.tucows.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\k4ejyyld.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\k4ejyyld.default\cookies.txt[rightmedia.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Becka\Application Data\Mozilla\Firefox\Profiles\k4ejyyld.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Becka\Cookies\becka@2o7[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Becka\Cookies\becka@adrevolver[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Becka\Cookies\becka@adrevolver[3].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][1].txt
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Becka\Cookies\becka@adtech[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Becka\Cookies\becka@advertising[1].txt
Spyware:Cookie/Adviva Not disinfected C:\Documents and Settings\Becka\Cookies\becka@adviva[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Becka\Cookies\becka@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Becka\Cookies\becka@atwola[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Becka\Cookies\becka@bluestreak[1].txt
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Becka\Cookies\becka@doubleclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Becka\Cookies\becka@mediaplex[1].txt
Spyware:Cookie/Microsofte Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Becka\Cookies\becka@questionmarket[1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Becka\Cookies\becka@serving-sys[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Becka\Cookies\becka@statcounter[1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Becka\Cookies\
[email protected][2].txt
Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Becka\Cookies\becka@xmts[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Becka\Cookies\becka@zedo[1].txt
Potentially unwanted tool:Application/ErrorSafe Not disinfected C:\Documents and Settings\Dom\Application Data\Mozilla\Firefox\Profiles\6g80s3yw.default\Cache\ACD008F5d01
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Dom\Application Data\Mozilla\Firefox\Profiles\6g80s3yw.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Dom\Application Data\Mozilla\Firefox\Profiles\6g80s3yw.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Dom\Application Data\Mozilla\Firefox\Profiles\6g80s3yw.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Dom\Cookies\dom@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Dom\Cookies\dom@atdmt[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Dom\Cookies\dom@doubleclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Dom\Cookies\dom@mediaplex[1].txt
Hijack this-Logfile of HijackThis v1.99.1
Scan saved at 08:06:14, on 27/04/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\CConnect\CConnect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Becka\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.wwe.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=54729R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....cid={SUB_CLCID}O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - Global Startup: CorrectConnect.lnk = C:\Program Files\CConnect\CConnect.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe