Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

trojan downloader


  • Please log in to reply

#1
spiritboy3

spiritboy3

    Member

  • Member
  • PipPipPip
  • 136 posts
hm its been a few day i register in this site. my friend introduced to me to get some help.WEll its very laming to be called laggers when i got this trojan . i got avg antivirus before and scanned for quite a great time but then it didnt delete all of the virus and one day it seems it couldnt detect anymore. I use spybot and did delete all the ad ware stuff but i still have the trojan stuff to get deleted, i heard avast was a good antivirus to delete the trojans but i just wanna get a few suggeestion by u ! THx for hu use their ability to help :whistling:


Logfile of HijackThis v1.99.1
Scan saved at 3:20:47 PM, on 10/2/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\pathname.exe
C:\WINDOWS\System32\rxr.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe

Edited by spiritboy3, 02 October 2006 - 02:22 PM.

  • 0

Advertisements


#2
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3,

Hi, and welcome to Geeks to Go. I'm going to help you clean up your PC.

You definitely have some malware on your computer, so let's get started with some scans.


First download AVG Anti-Spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the results of the AVG Anti-Spyware report scan.
Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • If it wants to install an ActiveX component allow it
  • Select either Home User or Company
  • Click the big Scan Now button
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
In your reply, please include the AVG Anti-spyware log, the Activescan log, and a new hijackthis log.

Thanks,

sari
  • 0

#3
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Logfile of HijackThis v1.99.1
Scan saved at 8:00:06 PM, on 10/5/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\WINDOWS\System32\pathname.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe

AVG log

AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 6:42:45 PM 10/5/2006

+ Scan result:



C:\WINDOWS\Wnqfqefl.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000010} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINDOWS\ieunst.exe -> Adware.IEPlug : Cleaned with backup (quarantined).
HKU\S-1-5-21-1708537768-688789844-1060284298-1003\Software\dsktb -> Adware.IEPlugin : Cleaned with backup (quarantined).
HKU\S-1-5-21-1708537768-688789844-1060284298-1003\Software\dsktb\DesktopToolbar -> Adware.IEPlugin : Cleaned with backup (quarantined).
C:\WINDOWS\system32\e8jm0i11e8.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\susinv.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit3.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit3.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit31.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit31.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit4.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mit4.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mitA.tmp.cab/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\mitA.tmp/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\WINDOWS\mirar.exe -> Adware.NetNucleus : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\system32\rk.bin -> Adware.RK : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cv3wanv28.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\w9seq.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\u39.tmp -> Adware.Surfside : Cleaned with backup (quarantined).
C:\WINDOWS\getnexus.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\My Documents\Aimbots+bypass.rar/Aimbots\Genisous\genisous.exe -> Backdoor.Dragonbot.1 : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\My Documents\Aimbots+bypass.rar/Aimbots\Perro Aimbot.exe -> Backdoor.Dragonbot.1 : Cleaned with backup (quarantined).
C:\Documents and Settings\darren\Local Settings\Temp\gokm.exe -> Downloader.Agent.afi : Cleaned with backup (quarantined).
:mozilla.194:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.145:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.146:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.147:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.148:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.149:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.150:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.151:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.152:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.153:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.154:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.155:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.157:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.158:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.159:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.160:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.161:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.162:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.163:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.164:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.165:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.166:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.167:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.168:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.169:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.170:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.171:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.172:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.173:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.174:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.175:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.176:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.338:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.449:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.516:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.198:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.199:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.212:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.793:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.794:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.795:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.211:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.781:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.782:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.783:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.784:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.785:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][4].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.14:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.15:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.702:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.703:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.704:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.705:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.706:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.707:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.708:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.222:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.223:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.36:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.268:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.269:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.739:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.135:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.136:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.137:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.138:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.143:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.144:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.261:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.262:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.263:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.264:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Casinotropez : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Casinotropez : Cleaned.
:mozilla.265:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.270:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.29:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.30:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Comclick : Cleaned.
:mozilla.96:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.832:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.116:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected]oubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.735:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.296:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.297:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.298:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.299:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.300:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.301:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.302:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.303:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Estat : Cleaned.
:mozilla.208:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.230:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.231:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.114:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.115:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.330:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.132:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Gamershell : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Gamershell : Cleaned.
:mozilla.736:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.737:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.376:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.796:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.797:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.798:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.799:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.800:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.804:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.805:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.806:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.807:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.808:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.809:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.810:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.811:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.812:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.813:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.814:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.815:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.816:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.817:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.818:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.819:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.820:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.821:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.118:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.119:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.522:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Paypopup : Cleaned.
:mozilla.216:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.217:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.218:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.219:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.531:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.532:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.533:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.534:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.535:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.559:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.312:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Searchingbooth : Cleaned.
:mozilla.255:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.580:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.581:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.582:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.583:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.766:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.767:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.190:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.191:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.192:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.210:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.7:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.8:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.9:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\70o7ejyy.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.360:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.361:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.830:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned.
:mozilla.612:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.613:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.614:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.615:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.616:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.617:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.618:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.619:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.139:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.140:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.646:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.647:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.648:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.649:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.133:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.134:C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\darren\Cookies\[email protected][1].txt -> TrackingCookie.Tribalf
  • 0

#4
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Incident Status Location

Virus:W32/Gaobot.OFV.worm Disinfected Operating system
Adware:adware program Not disinfected c:\windows\system32\data.~
Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr
Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\darren\Local Settings\Temporary Internet Files\Ssk.log
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard41.dat
Adware:adware/ieplugin Not disinfected c:\windows\kwv2.dat
Adware:adware/webhancer Not disinfected c:\windows\whCC-GIANT.exe
Adware:adware/maxifiles Not disinfected c:\program files\common files\Download
Adware:adware/vaultsearch Not disinfected c:\program files\common files\VCClient
Adware:adware/fchelp Not disinfected Windows Registry
Adware:adware/wupd Not disinfected Windows Registry
Adware:adware/searchexe Not disinfected Windows Registry
Adware:adware/cws.aboutblank Not disinfected Windows Registry
Adware:adware/mirar Not disinfected Windows Registry
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.target.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\darren\Cookies\da[email protected][2].txt
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][3].txt
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][4].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][6].txt
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Diglnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/AspinallsOnlineCasino Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Tucows Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Adware:Adware/BookedSpace Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\bs5-ventee.exe
Spyware:Cookie/888 Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\Cookies\[email protected][2].txt
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\GLF2CGLF2C.EXE
Adware:Adware/Sqwire Not disinfected C:\Documents and Settings\darren\Local Settings\Temp\GLFAGLFA.EXE
Virus:W32/Gaobot.OFV.worm Disinfected C:\Documents and Settings\darren\m&k.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\Common Files\VCClient\VCMain.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\eeedo.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\elos.exe
this is the panda one its kinda messy
  • 0

#5
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3,

Well, those scans cleaned up a lot of stuff that wasn't even visible in your log, but we still have a ways to go.

Antivirus
I see you're not running any antivirus program. Before we go any further, you must download and install an AV.

I recommend one of the following:

AVG Free
Avast

Clean up trusted domains:
Right click Here and select Save As to download WinHelp2002's DelDomains.inf. Please save the file somewhere you can find it like on the desktop. To run the inf file, right click on it and select Install.

Clean up Hijackthis:

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)

Now close all windows other than HiJackThis, then click Fix Checked. Reboot into safe mode.

Show Hidden files/folders:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Please delete these folders using Windows Explorer(if present):

C:\Program Files\Tjpb\
c:\program files\common files\Download
c:\program files\common files\VCClient

Please delete these files using Windows Explorer(if present):

C:\WINDOWS\System32\qfsol.exe
2523292B26282E3.exe <--- you'll have to use the search function to find this
C:\WINDOWS\System32\pathname.exe
rxr.exe <--- you'll have to use the search function to find this
c:\windows\system32\data.~
c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
c:\windows\system32\f3PSSavr.scr
c:\windows\keyboard41.dat
c:\windows\kwv2.dat
c:\windows\whCC-GIANT.exe
C:\WINDOWS\eeedo.exe
C:\WINDOWS\elos.exe



Hide Hidden files/folders:
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Do not Show hidden files and folders.
* Check the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

After that, Reboot.

Clean out temporary files and folders:


Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Run an indepth scan:


Please print these directions before continuing since we will be rebooting the computer into Safe Mode and these instructions will not be available.

Download WinPFind.exe to your desktop and double-click on it to extract the files. This will create a folder named WinPFind on your desktop.

Start in Safe Mode Using the F8 method:
  • Restart the computer.
  • As soon as the BIOS is loaded begin tapping the F8 key until the boot menu appears.
  • Use the arrow keys to select the Safe Mode menu item.
  • Press the Enter key.
Double-click on the WinPFind foider on your desktop to open it and then double-click on the WinPFind.exe file to start the program.

Now click the Start Scan button to begin the scan.

When the scan is complete reboot normally and post the WinPFind.txt file (located in the WinPFind folder) back here along with a new HijackThis log and I will review the information when it comes in.

Thanks,

sari
  • 0

#6
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
UPX!
FSG!
PEC2
PECompact2
Umonitor
qoologic
aspack
PTech
urllogic
ad-beh
ad-behNior.com
sYVLLSAKY
_rtneg3
SAHAgent
buddy.exe
ZepMon
aurora.exe
;2x(V]@BMD
Tlji7Mk
urllogic
KavSvc
69.59.186.63
209.66.67.134
66.63.167.97
66.63.167.77
abetterinternet.com
8B!7F\(T
testpopup
web-nex
yourkey
winsync
rec2_run
WinShutDown
ad-w-a-r-e.com
WSUD
Call (RPC) Help
lightspeedsarch
NIWU.UWIN
UpackByDwing
UPX!
FSG!
PEC2
PECompact2
Umonitor
qoologic
aspack
PTech
urllogic
ad-beh
ad-behNior.com
sYVLLSAKY
_rtneg3
SAHAgent
buddy.exe
ZepMon
aurora.exe
;2x(V]@BMD
Tlji7Mk
urllogic
KavSvc
69.59.186.63
209.66.67.134
66.63.167.97
66.63.167.77
abetterinternet.com
8B!7F\(T
testpopup
web-nex
yourkey
winsync
rec2_run
WinShutDown
ad-w-a-r-e.com
WSUD
Call (RPC) Help
lightspeedsarch
NIWU.UWIN
UpackByDwing


i just got this after the 2 hours scan of it i waited like 3 hours cant i not do the winpfind thing if i had to tell me the exact time

Logfile of HijackThis v1.99.1
Scan saved at 10:04:46 PM, on 10/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
  • 0

#7
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3,

I was just going to have you run the winpfind to make sure there wasn't anything hidden, but if your pc seems to be running well when we're done, I think we'll be ok without it.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)

Now close all windows other than HiJackThis, then click Fix Checked.

Post another log for review.

thanks,

sari
  • 0

#8
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
hey sari ok i gonna post that hi jac later but em excuse me after i finish that windpfind my webcam just got like stupid i cant see it clear its very unclear like when it face me it cant really see my eyes and stuff just pink empty face ok i post hi jack log just another min or more
  • 0

#9
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Logfile of HijackThis v1.99.1
Scan saved at 9:08:20 PM, on 10/10/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\V-Gear BEE\VBService.exe
C:\WINDOWS\System32\pathname.exe
C:\WINDOWS\System32\rxr.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: BEE Service.lnk = C:\Program Files\V-Gear BEE\VBService.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netm...NMStarter23.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netm...ce/kdfense8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://star.hangame....anSetup1008.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
  • 0

#10
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3,

I'm very confused by this log. You had downloaded and installed AVG, as I had instructed, and you should have been almost clean. Now I look at this log, and AVG is no longer there, and all the same infections are back. Did you uninstall AVG? If so, you need to go back and install it again - I can't help you unless you have an anti-virus program installed.

sari
  • 0

Advertisements


#11
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Logfile of HijackThis v1.99.1
Scan saved at 4:48:46 PM, on 10/12/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\WINDOWS\System32\pathname.exe
C:\WINDOWS\System32\rxr.exe
C:\WINDOWS\System32\hdoxioo.exe
C:\Program Files\V-Gear BEE\VBService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\Run: [Managment Service] hdoxioo.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKLM\..\RunServices: [Managment Service] hdoxioo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: BEE Service.lnk = C:\Program Files\V-Gear BEE\VBService.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netm...NMStarter23.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netm...ce/kdfense8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://star.hangame....anSetup1008.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe
  • 0

#12
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3,

Ok, please make sure you keep your AVG installed now, as you've managed to pick up more infections.

Show Hidden Files
* Click Start.
* Open My Computer.
* Select the Tools menu and click Folder Options.
* Select the View Tab.
* Under the Hidden files and folders heading select Show hidden files and folders.
* Uncheck the Hide protected operating system files (recommended) option.
* Click Yes to confirm.
* Click OK.

Please go here to upload a suspicious file for analysis.
  • Enter your username from this forum
  • Copy and paste the link to this thread
  • Browse for this filename: C:\WINDOWS\System32\qfsol.exe
  • Repeat this step in the next box for this filename: C:\WINDOWS\System32\rxr.exe
  • Repeat this step in the next box for this filename: C:\WINDOWS\System32\hdoxioo.exe
  • Repeat this step in the next box for this filename: C:\Program Files\Tjpb\Xysw.exe
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\qfsol.exe
O4 - HKLM\..\Run: [413F454742444A4D4] 2523292B26282E3.exe
O4 - HKLM\..\Run: [Vdwwyyfz] C:\Program Files\Tjpb\Xysw.exe
O4 - HKLM\..\Run: [pathname] C:\WINDOWS\System32\pathname.exe
O4 - HKLM\..\Run: [RPC Service] rxr.exe
O4 - HKLM\..\Run: [Managment Service] hdoxioo.exe
O18 - Filter: text/html - {994D478A-45D0-4DB4-AE77-288B1E346E99} - (no file)

Now close all windows other than HiJackThis, then click Fix Checked.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

Please delete these folders using Windows Explorer(if present):

C:\Program Files\Tjpb

Please delete these files using Windows Explorer(if present):

C:\WINDOWS\System32\pathname.exe
C:\WINDOWS\System32\rxr.exe
C:\WINDOWS\System32\hdoxioo.exe
2523292B26282E3.exe <-- this may be in c:\windows\system32, but you may have to search for it.

After that, Reboot.

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • If it wants to install an ActiveX component allow it
  • Select either Home User or Company
  • Click the big Scan Now button
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
Please post a new hijackthis log and the results of the Activescan report.

Thanks,

sari
  • 0

#13
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
OK the c: window 32 things i cant find them in search and cant del them i hope u can gimme more detail on that if i really still have that file WELl ty anyways


Logfile of HijackThis v1.99.1
Scan saved at 12:24:47 PM, on 10/15/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\V-Gear BEE\VBService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe /STARTUP
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKLM\..\RunServices: [Managment Service] hdoxioo.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: BEE Service.lnk = C:\Program Files\V-Gear BEE\VBService.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netm...NMStarter23.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netm...ce/kdfense8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://star.hangame....anSetup1008.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe


Incident Status Location

Virus:W32/Gaobot.OFV.worm Disinfected Operating system
Virus:W32/Gaobot.OJF.worm Disinfected Operating system
Adware:adware program Not disinfected c:\windows\system32\data.~
Potentially unwanted tool:application/mywebsearch Not disinfected c:\windows\system32\f3PSSavr.scr
Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
Spyware:spyware/surfsidekick Not disinfected C:\Documents and Settings\darren\Local Settings\Temporary Internet Files\Ssk.log
Adware:adware/dollarrevenue Not disinfected c:\windows\keyboard41.dat
Adware:adware/ieplugin Not disinfected c:\windows\kwv2.dat
Spyware:spyware/new.net Not disinfected c:\windows\NDNuninstall7_22.exe
Adware:adware/webhancer Not disinfected c:\windows\whCC-GIANT.exe
Adware:adware/maxifiles Not disinfected c:\program files\common files\Download
Adware:adware/vaultsearch Not disinfected c:\program files\common files\VCClient
Adware:adware/fchelp Not disinfected Windows Registry
Adware:adware/deskwizz Not disinfected Windows Registry
Adware:adware/wupd Not disinfected Windows Registry
Adware:adware/searchexe Not disinfected Windows Registry
Adware:adware/cws.aboutblank Not disinfected Windows Registry
Adware:adware/mirar Not disinfected Windows Registry
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.com.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.ads.addynamix.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[adserver.filefront.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\darren\Application Data\Mozilla\Firefox\Profiles\hzb6ldjp.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][3].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][3].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\darren\Cookies\[email protected][2].txt
Virus:W32/Gaobot.OJF.worm Disinfected C:\Documents and Settings\darren\Local Settings\Temp\yxzj.exe
Virus:W32/Gaobot.OJF.worm Disinfected C:\Documents and Settings\darren\Local Settings\Temporary Internet Files\Content.IE5\2DSZEL25\Bif[1].exe
Virus:W32/Gaobot.OFV.worm Disinfected C:\Documents and Settings\darren\m&k.exe
Spyware:Spyware/SurfSideKick Not disinfected C:\Program Files\Common Files\VCClient\VCMain.exe
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\eeedo.exe
Spyware:Spyware/Media-motor Not disinfected C:\WINDOWS\elos.exe
Adware:Adware/IEPlugin Not disinfected C:\WINDOWS\extract.exe
Adware:Adware/Mirar Not disinfected C:\WINDOWS\mirar.exe
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\e8jm0i11e8.dll
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\susinv.dll
Virus:W32/Gaobot.OJF.worm Disinfected C:\WINDOWS\system32\taskmgr.exe.tmp
Adware:Adware/BookedSpace Not disinfected C:\WINDOWS\Wnqfqefl.dll

it looks better after the active scan before when i uninstalled AVG it lags like [bleep] ty for it
  • 0

#14
sari

sari

    GeekU Admin

  • Administrator
  • 21,803 posts
  • MVP
spiritboy3

Please download the Killbox by Option^Explicit.

Note: In the event you already have Killbox, this is a new version that I need you to download.
  • Save it to your desktop.
  • Please double-click Killbox.exe to run it.
  • Select:
    • Delete on Reboot
    • then Click on the All Files button.
  • Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

    c:\windows\system32\data.~
    c:\windows\system32\f3PSSavr.scr
    c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
    C:\Documents and Settings\darren\Local Settings\Temporary Internet Files\Ssk.log
    c:\windows\keyboard41.dat
    c:\windows\kwv2.dat
    c:\windows\NDNuninstall7_22.exe
    c:\windows\whCC-GIANT.exe
    c:\program files\common files\Download
    c:\program files\common files\VCClient
    C:\WINDOWS\eeedo.exe
    C:\WINDOWS\elos.exe
    C:\WINDOWS\extract.exe
    C:\WINDOWS\mirar.exe
    C:\WINDOWS\system32\e8jm0i11e8.dll
    C:\WINDOWS\system32\susinv.dll
    C:\WINDOWS\system32\taskmgr.exe.tmp
    C:\WINDOWS\Wnqfqefl.dll
    c:\windows\system32\rxr.exe
    c:\windows\system32\hdoxioo.exe


  • Return to Killbox, go to the File menu, and choose Paste from Clipboard.
  • Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).
If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O4 - HKLM\..\RunServices: [RPC Service] rxr.exe
O4 - HKLM\..\RunServices: [Managment Service] hdoxioo.exe
O16 - DPF: {CFCB7308-782F-11D4-BE27-000102598CE4} (NPX Control) - http://nprotect.rose...Netizen/npx.cab
O16 - DPF: {D6FCA8ED-4715-43DE-9BD2-2789778A5B09} - http://nprotect.rose...Crypt/npkcx.cab

Now close all windows other than HiJackThis, then click Fix Checked.

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Reboot and post a new hijackthis log for me.

Thanks,

sari

Edited by sari, 19 October 2006 - 03:26 PM.

  • 0

#15
spiritboy3

spiritboy3

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 136 posts
Logfile of HijackThis v1.99.1
Scan saved at 1:35:02 PM, on 10/22/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\V-Gear BEE\VBService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\darren\My Documents\New Folder (2)\HijackThis.exe

F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~2\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Startup: BEE Service.lnk = C:\Program Files\V-Gear BEE\VBService.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Search - http://bar.mywebsear...?p=ZNxmk121COUS
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O16 - DPF: {00001023-A15C-11D4-97A4-0050BF0FBE67} (NetmarbleStarter23 Class) - http://download.netm...NMStarter23.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?LinkID=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.c...nst20040510.cab
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplane...DC_2.1.2.76.cab
O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games....GamesPlugin.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spiritboy3.sp...ad/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitd...can8/oscan8.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1148253403894
O16 - DPF: {88D969C0-F192-11D4-A65F-0040963251E5} (XML DOM Document 4.0) - http://www.survival....etup/msxml4.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {A4508A45-F1C4-40F3-99B4-0CA08AC77E3B} (Kdfense8 Control) - http://download.netm...ce/kdfense8.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab47946.cab
O16 - DPF: {C044CD87-DFB0-4130-A5E4-49361106FBC8} (HanSetupCtrl1008 Class) - http://star.hangame....anSetup1008.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload....GPlugin9USA.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) - http://www.gamengame...utComponent.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {F7899FAE-51C9-4EF5-B98C-A64997635235} (GSPRunGame Class) - http://playinfinity..../WindyGSPAx.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: ANIWZCSd Service (ANIWZCSdService) - Alpha Networks Inc. - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~2\avgemc.exe

i dun think the nt svice is ood but here u go i hope it a little cleaner
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP