Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Badly Infected Computer! (quiet HJT log?)


  • Please log in to reply

#1
zxSolidSnakexz

zxSolidSnakexz

    Member

  • Member
  • PipPip
  • 40 posts
Hi, I am at my Great Aunts house and immediately noticed that she was badly infected with spyware. Many hijacked IE popups were randomly appearing even when we were not surfing. This was obviosly a clientside attack.

I ran the usual AdAware, Spybot, CWShredder, Panda Active Scan, and I Installed Firefox to reach GTG, but we were still badly infected.

They bought Freedom firewall a while back, is this on the blacklist?

Anyway I have two HJT logs, one before I ran Spybot and one after.

Here is the first one

(They are both attached if that is easier to read ^_-)

Logfile of HijackThis v1.99.1
Scan saved at 3:36:29 PM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.vyshyhqub...wT41QfV8gP.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.rhxojsxgv...pXgcNbCsiA.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {705F6324-DF07-DD47-CAA9-36977B009B61} - C:\DOCUME~1\user\APPLIC~1\Popthunk\listreadme.exe (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Loudwaitpartmemo] C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\OnlineSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [JunkWin] C:\DOCUME~1\user\APPLIC~1\GREYME~1\dent audio proxy.exe
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.co...up1.0.0.8-2.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinn...ll/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v44/sol/sol.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://activation.s...nadaActiveX.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

Attached Files

  • Attached File  log1.txt   7.87KB   173 downloads
  • Attached File  log2.txt   7.97KB   108 downloads

Edited by zxSolidSnakexz, 12 August 2006 - 02:13 PM.

  • 0

Advertisements


#2
zxSolidSnakexz

zxSolidSnakexz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Here is the one after Spybot

Logfile of HijackThis v1.99.1
Scan saved at 3:57:08 PM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE
C:\Program Files\MSN\MSNCoreFiles\msn.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.vyshyhqub...wT41QfV8gP.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Pop-Up Blocker BHO - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Form Filler BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dll
O2 - BHO: (no name) - {705F6324-DF07-DD47-CAA9-36977B009B61} - C:\DOCUME~1\user\APPLIC~1\Popthunk\listreadme.exe (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Freedom] C:\Program Files\Zero Knowledge\Freedom\Freedom.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [Loudwaitpartmemo] C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\OnlineSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [JunkWin] C:\DOCUME~1\user\APPLIC~1\GREYME~1\dent audio proxy.exe
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {6C6FE41A-0DA6-42A1-9AD8-792026B2B2A7} (FreeCell Control) - http://www.worldwinn...ll/freecell.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinn...ed/wwlaunch.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {97438FE9-D361-4279-BA82-98CC0877A717} (Cubis Control) - http://www.worldwinn...cubis/cubis.cab
O16 - DPF: {9903F4ED-B673-456A-A15F-ED90C7DE9EF5} (Sol Control) - http://www.worldwinn...v44/sol/sol.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) - https://activation.s...nadaActiveX.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zon...ss.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

#3
zxSolidSnakexz

zxSolidSnakexz

    Member

  • Topic Starter
  • Member
  • PipPip
  • 40 posts
Here is the log from Activescan

(also attached)

I noticed most of them are in temp directories so I will be running Cleanup and CCleaner now

Incident Status Location

Adware:Adware/Lop Not disinfected c:\docume~1\user\applic~1\greyme~1\dentau~1.exe
Adware:adware/gator Not disinfected c:\windows\GatorPdpLoudInstaller.log
Adware:adware/savenow Not disinfected c:\program files\Save
Spyware:spyware/bridge Not disinfected Windows Registry
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\64 wait.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\Bikeobj.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\chic readme.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\delete lite.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\Download gram.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\find obj.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\Heart Plan.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\liescake.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\MultiCreative.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\OnlineSend.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\Ooze Up.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\PART DENT.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\PLANBLAH.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\README STYLE.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\Dog Start Loud Wait\Trans 32.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\bjzeavnd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\boobbuildbin16.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\dent audio proxy.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\epdrmopp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\fgdgxatp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\fldewvjk.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\goyzznqc.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\iodqysmi.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\mokabsuo.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\mstdoohw.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\olhsfhie.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\pdhkogkd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\rtjsjuwv.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\sfrtqihd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\sxapuxqc.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\tznrrofw.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\uhcqyaah.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\vdsolngd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\xlgzawqq.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\yskzkflm.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\ytafiaqu.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Application Data\Grey Media\yxboicrd.exe
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\7x3qeerk.default\cookies.txt[.com.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\7x3qeerk.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Advnt Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.www.advnt01.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.i.screensavers.com/]
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.c3.gostats.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.statse.webtrendslive.com/S117816]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.statse.webtrendslive.com/dcs4o6w3n4twkf0ur09tjdxb3_3r4s]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.statse.webtrendslive.com/dcs2omr9fpifwznrgv67zf9ub_7p8i]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.searchportal.information.com/]
Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.fe.lea.lycos.es/]
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.tickle.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.winfixer.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.go.com/]
Spyware:Cookie/Lop Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.lop.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.stats1.reliablestats.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.c.enhance.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.888.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.server.iad.liveperson.net/hc/70062990]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.server.iad.liveperson.net/hc/70062990]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.ath.belnk.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\user\Application Data\Mozilla\Firefox\Profiles\mry6ctdi.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\user\Cookies\user@atwola[1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\user\Cookies\user@cassava[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\user\Cookies\[email protected][2].txt
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\1b8661.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\1fd4e0.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\288681.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\5d63e.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7150b663.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b0208ca.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b020903.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b0312a2.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b035fc8.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b03aea6.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b118a75.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7b19f93b.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7e29f874.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\7f2417ca.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\a1c91.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\apgfojgr.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\bgjskmqe.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\cflnxbob.exe
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@888[1].txt
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@888[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@adultfriendfinder[2].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\user\Local Settings\Temp\Cookies\user@cassava[1].txt
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\crjtxetj.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\edbqhlfp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\fdmqggcr.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\gbwhpfya.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\ghwksvba.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\Inside Program.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\iycvcfjl.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\jmrxdwkd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\ldwhewfv.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\nhtfmucd.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\njtsjkbr.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\nlqsvrms.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\nsxlfvsq.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\okoapujp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\pbocwhhx.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\pjzllzti.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\qjfgqony.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\rjldcfjj.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\rzhntuos.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\vygbspyc.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\wlygeuyt.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\wttfcdux.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\wvxumhdb.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\zdvguxvp.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\zfmhpdme.exe
Adware:Adware/Lop Not disinfected C:\Documents and Settings\user\Local Settings\Temp\zwnhjvjs.exe

Attached Files


Edited by zxSolidSnakexz, 12 August 2006 - 02:20 PM.

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP