Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Spyware "Critical System Error"!"


  • Please log in to reply

#1
DK24

DK24

    New Member

  • Member
  • Pip
  • 4 posts
System is infected. I have already completed the steps outlined here. Attached are the printouts:

Activescan:
Incident Status Location

Adware:Adware/VirusBurst Not disinfected C:\WINNT\system32\tazth.dll
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt[.winfixer.com/]



Report Scan:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:32:06 PM 10/16/2006

+ Scan result:



C:\Documents and Settings\Administrator\Desktop\Setup.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\\{479fd0cf-5be9-4c63-8cda-b6d371c67bd5} -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Explorer Security Plugin 2006 -> Adware.Generic : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Internet Security Add-On -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\iesplugin.dll -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\iesuninst.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\isaddon.dll -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\isamini.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\isamonitor.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\isauninst.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\ot.ico -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\pmmon.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\pmsngr.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\pmuninst.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\ts.ico -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
C:\Program Files\HQVideoCodec\uninst.exe -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\CLSID\{d869742a-e5d2-4624-96c7-aae26170665e} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d869742a-e5d2-4624-96c7-aae26170665e} -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\HQVideoCodec -> Adware.HQVideoCodec : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Public Messenger ver 2.03 -> Adware.IntCodec : Cleaned with backup (quarantined).
HKU\S-1-5-21-1644491937-1284227242-725345543-500\Software\Internet Security -> Adware.IntCodec : Cleaned with backup (quarantined).
C:\WINNT\$NtUpdateRollupPackUninstall$\netapi32.dll -> Not-A-Virus.Exploit.Win32.CAN.20030533 : Cleaned with backup (quarantined).
C:\WINNT\ServicePackFiles\i386\netapi32.dll -> Not-A-Virus.Exploit.Win32.CAN.20030533 : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.522:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.523:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.524:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.525:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.526:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.527:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.528:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.529:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.530:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.531:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.532:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.533:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.534:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.363:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.366:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.279:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.280:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.281:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.282:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.179:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.180:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.181:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.182:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.183:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.184:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.185:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.186:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.187:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.188:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.189:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.190:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.191:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.192:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.193:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.194:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.195:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.196:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.13:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.472:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.444:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.394:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.396:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.463:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.464:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.465:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.275:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.276:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.277:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.278:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.162:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.163:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.467:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.468:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.427:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.11:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.239:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.254:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.255:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.256:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.258:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.260:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.261:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.262:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.264:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.265:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.266:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.267:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.268:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.339:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.340:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.341:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.342:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.343:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.347:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.410:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.411:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.435:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.443:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.453:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.454:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.461:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.462:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.477:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.478:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.480:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.504:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.535:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.536:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.164:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.165:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.166:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.167:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.168:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.169:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.126:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.127:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.128:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.129:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.130:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.131:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.244:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.338:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.100:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.101:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.102:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.103:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.308:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.309:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.333:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.334:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.368:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.382:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.383:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.384:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.429:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.430:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.474:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.505:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.51:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.52:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.53:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.54:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.55:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.56:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.57:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.58:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.59:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.60:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.86:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.87:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.89:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.90:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.91:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.92:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.93:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.94:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.95:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.96:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.97:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.98:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.99:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.469:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.470:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.540:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.17:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.18:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.226:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.227:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.243:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.509:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.10:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.12:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.8:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.9:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.14:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.15:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.417:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.418:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.419:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.420:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.421:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.336:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.222:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.223:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.224:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.225:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.197:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.198:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.199:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.200:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.484:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.485:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.486:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.487:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.488:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.489:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.490:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.491:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.511:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.512:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.299:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.203:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.204:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.205:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.206:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.207:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.208:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.209:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.210:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.113:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.114:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.115:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.116:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.253:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.501:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.361:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.362:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.364:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.365:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.110:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.111:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.112:C:\Documents and Settings\kelly\Application Data\Mozilla\Firefox\Profiles\zbh0yoyk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Hijack This:
Logfile of HijackThis v1.99.1
Scan saved at 3:28:31 PM, on 10/17/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimtoday.aol....ay/aimtoday.adp
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...oad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1139082725187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1139082708921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://tdsqlserver2/tdbin/Spider.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O21 - SSODL: gaonic - {f31aee4a-1530-4fef-8537-79c6973bff9a} - C:\WINNT\system32\tazth.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


Thanks for the help.
  • 0

Advertisements


#2
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
1) Download SmitfraudFix.zip by S!Ri from here and save it to your Desktop.
You will then need to extract the files.
To do this: Right click on the zipped folder and from the menu that appears, click on Extract All...
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "1" and then <ENTER> to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Add a fresh HJT log as well.
  • 0

#3
DK24

DK24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Here's the log from smitfraud:
SmitFraudFix v2.110

Scan done at 17:41:39.29, Tue 10/17/2006
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINNT\system32

C:\WINNT\system32\tazth.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\VirusBurster\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{f31aee4a-1530-4fef-8537-79c6973bff9a}"="gaonic"

[HKEY_CLASSES_ROOT\CLSID\{f31aee4a-1530-4fef-8537-79c6973bff9a}\InProcServer32]
@="C:\WINNT\system32\tazth.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{f31aee4a-1530-4fef-8537-79c6973bff9a}\InProcServer32]
@="C:\WINNT\system32\tazth.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


Here's the first log from HJT:
Ad-Aware SE Personal
Adobe Acrobat 7.0.1 and Reader 7.0.1 Update
Adobe Download Manager 2.0 (Remove Only)
Adobe Photoshop Album 2.0 Starter Edition
Adobe Reader 7.0
AOL Uninstaller (Choose which Products to Remove)
ATI Display Driver
AVG Anti-Spyware 7.5
AVG Free Edition
Canon Camera Support Core Library
Canon Camera TWAIN Driver 6.6
Canon Camera Window DC_DV 5 for ZoomBrowser EX
Canon Camera Window DC_DV 6 for ZoomBrowser EX
Canon Camera Window DSLR 5 for ZoomBrowser EX
Canon Camera Window MC 6 for ZoomBrowser EX
Canon MovieEdit Task for ZoomBrowser EX
Canon PhotoRecord
Canon RAW Image Task for ZoomBrowser EX
Canon Utilities PhotoStitch 3.1
Canon ZoomBrowser EX (E)
DLA
Free Spider
GC-Prevue 14.1.2
HijackThis 1.99.1
Hotfix for MDAC 2.53 (KB911562)
hp deskjet 6127 series
hp dvd writer
HP Extended Capabilities 4.7
HP Image Zone 4.7
HP PSC & OfficeJet 4.7
HP RecordNow
HP Simple Backup 4.75 (OEM)
HP Software Update
Intel® PRO Ethernet Adapter and Software
iTunes
J2SE Runtime Environment 5.0 Update 1
J2SE Runtime Environment 5.0 Update 6
LabSystem PRO Version 2.1
LiveUpdate 2.0 (Symantec Corporation)
Macromedia Shockwave Player
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office 2000 SR-1 Professional
Microsoft Office Outlook 2003
Microsoft Visual SourceSafe 6.0
Microsoft Windows Journal Viewer
Microsoft XML Parser and SDK
Mozilla Firefox (1.5.0.7)
MyDVD
Panda ActiveScan
PowerDVD
QuickTime
Safety Alerter 2006
Security Update for Windows Media Player (KB911564)
Symantec AntiVirus
Update Rollup 1 for Windows 2000 SP4
Verizon FiOS Activation
Viewpoint Media Player
Windows 2000 Hotfix - KB842773
Windows 2000 Hotfix - KB890046
Windows 2000 Hotfix - KB893756
Windows 2000 Hotfix - KB896358
Windows 2000 Hotfix - KB896422
Windows 2000 Hotfix - KB896423
Windows 2000 Hotfix - KB896424
Windows 2000 Hotfix - KB897715
Windows 2000 Hotfix - KB899587
Windows 2000 Hotfix - KB899589
Windows 2000 Hotfix - KB900725
Windows 2000 Hotfix - KB901017
Windows 2000 Hotfix - KB901214
Windows 2000 Hotfix - KB902400
Windows 2000 Hotfix - KB904706
Windows 2000 Hotfix - KB905414
Windows 2000 Hotfix - KB905495
Windows 2000 Hotfix - KB905749
Windows 2000 Hotfix - KB905915
Windows 2000 Hotfix - KB908519
Windows 2000 Hotfix - KB908523
Windows 2000 Hotfix - KB908531
Windows 2000 Hotfix - KB911280
Windows 2000 Hotfix - KB911567
Windows 2000 Hotfix - KB912812
Windows 2000 Hotfix - KB912919
Windows 2000 Hotfix - KB913580
Windows 2000 Hotfix - KB914388
Windows 2000 Hotfix - KB914389
Windows 2000 Hotfix - KB916281
Windows 2000 Hotfix - KB917008
Windows 2000 Hotfix - KB917159
Windows 2000 Hotfix - KB917422
Windows 2000 Hotfix - KB917537
Windows 2000 Hotfix - KB917736
Windows 2000 Hotfix - KB917953
Windows 2000 Hotfix - KB918899
Windows 2000 Hotfix - KB920670
Windows 2000 Hotfix - KB920683
Windows 2000 Hotfix - KB920685
Windows 2000 Hotfix - KB920958
Windows 2000 Hotfix - KB921398
Windows 2000 Hotfix - KB921883
Windows 2000 Hotfix - KB922582
Windows 2000 Hotfix - KB922616
Windows 2000 Hotfix - KB923191
Windows 2000 Hotfix - KB923414
Windows 2000 Hotfix - KB924191
Windows 2000 Hotfix - KB925486
Windows 2000 Service Pack 4
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Media Player Hotfix [See Q828026 for more information]
WinRunner
WinZip

And here's the fresh log from HJT:
Logfile of HijackThis v1.99.1
Scan saved at 5:46:48 PM, on 10/17/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\WINNT\system32\cmd.exe
C:\WINNT\NOTEPAD.EXE
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://aimtoday.aol....ay/aimtoday.adp
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...oad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1139082725187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1139082708921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://tdsqlserver2/tdbin/Spider.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O21 - SSODL: gaonic - {f31aee4a-1530-4fef-8537-79c6973bff9a} - C:\WINNT\system32\tazth.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe


Thanks again!
  • 0

#4
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click ewido-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Delete your old version and download a fresh copy of SmitfraudFix.zip by S!Ri from here and save it to your Desktop.
The fix is frequently updated and it is advisable to ensure that you have the latest version.
You will then need to extract the files.
To do this: Right click on the zipped folder and from the menu that appears, click on Extract All...
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


Close the folder, you will need it later.

3) You will need to know how to boot into Safe Mode.
Instructions can be found here.

4) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

5) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.

2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted - if this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

7) Empty the Recycle Bin.

8) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

9) Reboot into Normal Mode.

10) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
This fix is based on a canned speech supplied by Kimberly.
  • 0

#5
DK24

DK24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
I have followed most of the directions given, but I am unable to do the following:
6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

I do not have a Desktop tab on my display option off CP. I am running Windows 2000 if that helps. I can see that this option exists on XP. Thanks!
  • 0

#6
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
If you don't have it, you can't do it. The above is a standard XP post, so don't worry about this step, just complete the rest and post accordingly.
  • 0

#7
DK24

DK24

    New Member

  • Topic Starter
  • Member
  • Pip
  • 4 posts
Here's the file from HJT:

Logfile of HijackThis v1.99.1
Scan saved at 6:02:19 PM, on 10/18/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINNT\system32\regsvc.exe
C:\Program Files\Symantec AntiVirus\SavRoam.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: @msdxmLC.dll,[email protected],&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [DVDBitSet] "C:\Program Files\HP CD-DVD\Umbrella\DVDBitSet.exe" /NOUI
O4 - HKLM\..\Run: [HPCDTray] "C:\Program Files\HP CD-DVD\Umbrella\hpcdtray.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1149712663\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.1\resources\en-US\local\search.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfi...oad/tgctlcm.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1139082725187
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1139082708921
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {CDBD9968-7BF1-11D4-9D36-0001029DEBEB} (Loader Class) - http://tdsqlserver2/tdbin/Spider.ocx
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = NA.AD.CRBARD.COM,CRBARD.COM
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O20 - Winlogon Notify: nwprovau - C:\WINNT\SYSTEM32\nwprovau.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINNT\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINNT\System32\HPZipm12.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

Here's the AVG A-S scan:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 5:53:43 PM 10/18/2006

+ Scan result:



:mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.51:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.20:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.23:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.24:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.25:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.43:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.59:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.60:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.66:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.26:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.27:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.28:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.70:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.34:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.35:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.36:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.42:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.64:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.65:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\l1vudawd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end

Here's Rapport.txt:
SmitFraudFix v2.110

Scan done at 19:54:21.12, Tue 10/17/2006
Run from C:\Documents and Settings\Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows 2000 [Version 5.00.2195] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


I haven't plugged into the internet yet. but the icon on the toolbar indicating that I have a "critical system error" is gone. Thanks!
  • 0

#8
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
The log looks OK, malware-wise.




You need to decide on which anti-virus program you prefer, AVG or Symantec, and then uninstall the other - two or more AVs running in real time can conflict resulting in less, not more, protection.

I don't see a firewall installed on the PC, but I may have missed it. There are a few free firewalls available.
Zone Alarm: Available here.
Kerio: Available here.
Outpost: Available here.

It is important to note that you should only have one firewall installed at a time, but you can download both to your Desktop and install each in turn to see which one you prefer.

Understanding and Using Firewalls: http://www.bleepingc...tutorial60.html

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You are running an old version of Sun Java which needs updating:
  • Go here and click on the Download button to the right of Java Runtime Environment (JRE) 5.0 Update 9.
  • Accept the license agreement by clicking the radio button.
  • Under Windows Platform - J2SE™ Runtime Enviroment 5.0 Update 9, click the Windows Offline Installation, Multi-language link.
  • Go to Add/Remove Programs and remove any entries that refer to Java 2 Runtime Enviroment and then reboot your PC.
  • Navigate to and delete the following folder, if it exists: C:\Program Files\Java.
  • Finally double click the installation file that you downloaded earlier.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

As long as the above goes OK, I want you to run your PC as normal for a few days. When you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.

I'm not sure if you have System Restore on your PC - if not skip that bit.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP