Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Spyware, Trojans, Malware, and other misc.


  • Please log in to reply

#1
Hero Link

Hero Link

    Member

  • Member
  • PipPip
  • 25 posts
Alright, this is the second time I've tried posting this because stuff is shutting down FireFox. I now have 2 blinking icons in my system tray. One being a blue circle with a yellow X changing to a yellow ? and back, and the other being the Windows help icon chaniong to a red circle strikethrough and back. Here is my Hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 6:25:35 PM, on 10/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\mspaint.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ishost.exe
C:\WINDOWS\system32\ismini.exe
C:\Program Files\Common Files\{78720464-07C9-1033-0718-020403020001}\Update.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Jess\APPLIC~1\MCROSO~1\csrss.exe
C:\Program Files\Common Files\?racle\?ttrib.exe
C:\WINDOWS\octeltpop.exe
C:\WINDOWS\ac3_0002.exe
C:\WINDOWS\system32\RUNDLL32.EXE
c:\windows\system32\dwdsregt.exe
C:\WINDOWS\MirarSetup_876057.exe
C:\WINDOWS\sys010207381482.exe
C:\WINDOWS\Duce6.exe
C:\WINDOWS\sys022073814820.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\issearch.exe
C:\WINDOWS\system32\isnotify.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\Jess\LOCALS~1\Temp\b104.exe
C:\WINDOWS\Sm9zaHVh\command.exe
C:\Program Files\Network Monitor\netmon.exe
C:\Documents and Settings\Jess\Desktop\hijackthis\HijackThis.exe
C:\Program Files\SpyQuake2.com\Spy-Quake2.exe
C:\Program Files\SpyQuake2.com\Spy-Quake2.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.java.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer BLOWS [bleep]!!!!!!!!!!!!
R3 - URLSearchHook: (no name) - {D66A434F-80FE-8577-8FAA-A2289223609B} - C:\WINDOWS\system32\jeck.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: Protection Bar - {1a29a79a-b9c8-44a9-bedf-7fadde3cf33f} - C:\Program Files\VideoKeyCodec\iesplugin.dll (file missing)
O3 - Toolbar: ToolBar888 - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{38720464-07C9-1033-0718-020403020001}\MyToolBar.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB57.dll
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [CTDrive] rundll32.exe C:\WINDOWS\system32\drvcuh.dll,startup
O4 - HKLM\..\Run: [hqnxqoe.dll] C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\hqnxqoe.dll,rxjfkqe
O4 - HKLM\..\Run: [1pop06apelt3] C:\WINDOWS\octeltpop.exe
O4 - HKLM\..\Run: [oyr7dc06] RUNDLL32.EXE w18f2ab4.dll,n 0067dc000000000218f2ab4
O4 - HKLM\..\Run: [{20-04-46-64-ZN}] c:\windows\system32\dwdsregt.exe ELT001
O4 - HKLM\..\Run: [sys022073814820] C:\WINDOWS\sys022073814820.exe
O4 - HKLM\..\Run: [ToolbarInstall] C:\WINDOWS\MirarSetup_876057.exe
O4 - HKLM\..\Run: [sys010207381482] C:\WINDOWS\sys010207381482.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\Duce6.exe
O4 - HKLM\..\Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Oser] "C:\DOCUME~1\Jess\APPLIC~1\MCROSO~1\csrss.exe" -vt yazb
O4 - HKCU\..\Run: [Bmmfhmb] C:\Program Files\Common Files\?racle\?ttrib.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\TIELT001.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1155404062674
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: ferrateen - {27321538-5739-4aa1-b84c-7d18e4383f1f} - C:\WINDOWS\system32\rrtcany.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - C:\WINDOWS\system32\urroxtl.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\Sm9zaHVh\command.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton AntiVirus\navapsvc.exe (file missing)
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
  • 0

Advertisements


#2
loophole

loophole

    Malware Expert

  • Retired Staff
  • 9,798 posts
Hi there :whistling:

Quite a bit going on here. These are a long set of instructions but should clear up most of the garbage. Just stick with it and take your time. If you have trouble getting any of the programs let me know and we may be able to do things a different way:)

Please print out or copy these instructions/tutorial to Notepad as the internet will not be available to you at certain points of the removal process (while in Safe Mode). Make sure to work through all the Steps in the exact order in which they are listed below. .


1. Download and update Ewido.

First download Ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run Ewido and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close Ewido anti-spyware, Do Not run a scan just yet

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.



Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
3. RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

Then, please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon Posted Image and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.

    Run Smitfraud Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
    Select option #2 - Clean by typing 2 and press Enter.
    Wait for the tool to complete and disk cleanup to finish.
    You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
    The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

    A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

    Clean out your Temporary Internet files. Proceed as follows:[list]
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Note: IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
8. Close Ewido and Reboot back into Normal Windows Mode


Please Post the following logs:
  • c:\rapport.txt
  • Ewido log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

  • 0

#3
Hero Link

Hero Link

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Alrighty, I went through all of the things that you told me to do, and it did a pretty good job, but I still have something that keeps wanting the internet to be connected, so it can most likely download more of it's webbed virus's/etc. Here are the logs you wanted.

[quote name='rapport.txt']SmitFraudFix v2.117

Scan done at 0:10:28.51, Wed 11/01/2006
Run from C:\Documents and Settings\Hero Link\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End[/quote]


[quote name='Ewido log']---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 2:21:18 AM 11/1/2006

+ Scan result:



C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP66\A0007146.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP66\A0007147.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP66\A0007148.exe -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-10.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-11.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-12.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-13.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-14.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-15.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-16.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-17.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-18.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-19.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-199.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-20.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-21.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-22.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-23.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-24.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-4.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-40.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-41.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-42.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-43.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-44.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-45.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-46.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-47.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-48.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-49.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-5.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-50.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-51.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-52.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-53.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-54.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-55.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-56.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-58.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-59.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-6.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-60.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-61.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-7.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-8.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP84\snapshot\MFEX-9.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\A0007774.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-10.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-11.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-12.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-13.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-14.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-15.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-16.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-17.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-18.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-19.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-199.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-20.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-21.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-22.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-23.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-24.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-4.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-40.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-41.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-42.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-43.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-44.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-45.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-46.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-47.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-48.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-49.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-5.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-50.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-51.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-52.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-53.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-54.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-55.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-56.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-58.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-59.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-6.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-60.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-61.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-7.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-8.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\snapshot\MFEX-9.DAT -> Adware.CommAd : Cleaned with backup (quarantined).
HKU\S-1-5-21-1659004503-688789844-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8BF5B8FC-11CB-409F-8C91-4D4CA04A1B6D} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-1659004503-688789844-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C3703265-4671-4858-92A4-CBA6A7B3BB45} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\SXARG5EV\unstall[1].exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temp\mit61.tmp/NNBar_VCSetup_876057.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\WHU3C1IB\MirarSetup_876057[1].exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\MirarSetup_876057.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Hero Link\Desktop\ZC, ZQ\freehomepages.com.html -> Adware.SearchPage : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP81\A0007642.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP81\A0007643.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP81\A0007644.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\8923O5IJ\TIELT001[1].exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP78\A0007617.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP78\A0007619.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\TIELT001.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\Registration\svcvga.dll -> Downloader.Agent.bai : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\WHU3C1IB\ac3_0002[1].exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP87\A0008137.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP78\A0007614.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP78\A0007607.exe -> Downloader.VB.anl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\A0007778.exe -> Downloader.Zlob.adq : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\WHU3C1IB\antzom[1].exe -> Hijacker.Small.lr : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temporary Internet Files\Content.IE5\WHU3C1IB\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP81\A0007645.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf15B.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf166.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf16E.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf176.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf17E.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf189.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf191.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf1A4.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf279.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf281.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\Documents and Settings\Guest\Local Settings\Temp\laf289.tmp -> Not-A-Virus.Hoax.Win32.Renos.dv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP67\A0007200.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP67\A0007202.exe -> Not-A-Virus.Hoax.Win32.Renos.eo : Cleaned with backup (quarantined).
C:\Documents and Settings\Jess\Local Settings\Temp\mst10.tmp -> Not-A-Virus.Hoax.Win32.Renos.fw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP85\A0007783.dll -> Not-A-Virus.Hoax.Win32.Renos.fw : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1659004503-688789844-725345543-1004\Dc241.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1659004503-688789844-725345543-1004\Dc242.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007407.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007431.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007439.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007447.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007455.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007463.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007472.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{346E8776-D458-4369-865F-289D3D6C8CFB}\RP74\A0007480.exe -> Not-A-Virus.Hoax.Win32.Renos.fx : Cleaned with backup (quarantined).
:mozilla.277:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.320:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.107:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.147:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.150:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.151:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.154:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.155:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.254:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.408:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.427:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.254:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.255:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.597:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.598:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.144:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.145:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.146:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.147:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.148:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.149:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.150:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.151:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.152:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.153:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.154:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.155:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.156:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.157:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.158:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.159:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.160:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.124:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.125:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.44:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.45:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.46:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.471:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.472:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.672:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.673:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.681:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.527:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.634:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.635:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.636:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.186:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.187:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.188:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.339:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.340:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.341:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.342:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.343:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.100:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.101:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.102:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.103:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.105:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.106:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.466:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.467:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.468:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.469:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.470:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.88:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.89:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.91:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.94:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.95:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.96:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.344:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.345:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.124:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.125:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.126:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.127:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.128:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.90:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.92:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.93:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.97:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.98:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.101:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.29:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.106:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.447:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.400:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.401:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.402:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.403:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.409:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.434:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.435:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.436:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.473:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.330:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.346:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jess\Cookies\jess@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.151:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.416:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.417:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.418:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.485:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.486:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.487:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.488:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.258:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.23:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.58:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Jess\Cookies\jess@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.670:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.685:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
:mozilla.711:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Dbbsrv : Cleaned.
:mozilla.41:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.83:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.243:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.269:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.270:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.271:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.272:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.273:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.274:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Jess\Cookies\[email protected][2].txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.139:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.40:C:\Documents and Settings\Hero Link\Application Data\Mozilla\Firefox\Profiles\oh2ynriz.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.162:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.168:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.172:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.36:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.37:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.38:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.39:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.40:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.41:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.42:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.43:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.609:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.137:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.138:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.19:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.20:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.211:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.22:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.247:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.276:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.533:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.697:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.726:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.776:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.113:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.115:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.116:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.117:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.252:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.253:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.366:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.367:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\isqwwlb6.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.423:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.425:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.587:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.763:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.764:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.765:C:\Documents and Settings\Jess\Application Data\Mozilla\Firefox\Profiles\ljbowtti.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.798:C:\Documents and
  • 0

#4
loophole

loophole

    Malware Expert

  • Retired Staff
  • 9,798 posts
Hi :whistling:

Please download ComboFix and save it to your desktop.
Double click combofix.exe and follow the prompts.
When it's done running it will produce a log for you. Please post that log in your next reply with a new Hijack log.
Important Note - Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
  • 0

#5
Hero Link

Hero Link

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Here are my logs.

Hero Link - 06-11-06 22:01:46.25 Service Pack 2
ComboFix 06.10.19 - Running from: "C:\Documents and Settings\Hero Link\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Documents and Settings\LocalService\Application Data\NetMon
C:\WINDOWS\system32\components
C:\Program Files\Common Files\{38720464-07C9-1033-0718-020403020001}
C:\Program Files\Common Files\{78720464-07C9-1033-0718-020403020001}

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

C:\QooBox\Purity\Program Files\Common Files\RACLE~1


((((((((((((((((((((((((((((((( Files Created from 2006-10-06 to 2006-11-06 ))))))))))))))))))))))))))))))))))


2006-10-31 23:51 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-31 23:23 10,344 --a------ C:\WINDOWS\system32\drivers\symlcbrd.sys
2006-10-29 18:25 98,324 --a------ C:\WINDOWS\system32\eotmnggk.dll
2006-10-29 18:25 688,180 ---hs---- C:\WINDOWS\system32\sstts.dll
2006-10-29 18:25 642,271 ---hs---- C:\WINDOWS\system32\sttss.bak1
2006-10-29 18:21 49,428 --a------ C:\WINDOWS\system32\dlpcgkhu.dll
2006-10-29 18:21 122,900 --a------ C:\WINDOWS\system32\ocvmdabe.dll
2006-10-29 18:20 1,259 --a------ C:\WINDOWS\system32\oyr7dc06.sys
2006-10-29 18:18 94,208 --a------ C:\WINDOWS\system32\hqnxqoe.dll
2006-10-29 18:18 72,192 --a------ C:\WINDOWS\system32\mvfkuwn.dll
2006-10-29 18:18 40,973 ---hs---- C:\WINDOWS\system32\wvuropm.dll
2006-10-29 18:18 2 --a------ C:\WINDOWS\system32\wnsinttr.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-06 22:03 -------- d-------- C:\Program Files\Common Files
2006-11-06 02:35 -------- d-------- C:\Program Files\Mozilla Firefox
2006-10-31 23:53 -------- d-------- C:\Program Files\Common Files\Symantec Shared
2006-10-31 23:51 -------- d-------- C:\Program Files\Grisoft
2006-10-31 23:40 -------- d-------- C:\Program Files\Norton AntiVirus
2006-10-31 23:23 -------- d-------- C:\Program Files\Symantec
2006-10-30 00:40 4 --ahs---- C:\Documents and Settings\Hero Link\Application Data\430ADEFB88C147E99CBE119E94C3F8AD.rul
2006-10-30 00:40 332 --ahs---- C:\Documents and Settings\Hero Link\Application Data\430ADEFB88C147E99CBE119E94C3F8AD.sta
2006-10-29 18:43 -------- d-------- C:\Program Files\Viewpoint
2006-10-29 18:20 -------- d-------- C:\Program Files\em
2006-10-29 18:15 -------- d-------- C:\Program Files\GIF Movie Gear
2006-10-29 17:46 -------- d-------- C:\Program Files\SpywareBlaster
2006-10-29 09:46 -------- d-------- C:\Program Files\Creative
2006-10-28 23:35 -------- d-------- C:\Program Files\JessieIRC
2006-10-27 21:38 -------- d-------- C:\Program Files\mIRC
2006-10-25 15:09 -------- d-------- C:\Documents and Settings\Hero Link\Application Data\SmartFTP
2006-10-25 15:08 -------- d-------- C:\Program Files\SmartFTP Client 2.0 Setup Files
2006-10-25 15:08 -------- d-------- C:\Program Files\SmartFTP Client 2.0
2006-10-13 21:12 -------- d-------- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2006-10-09 00:45 -------- d---s---- C:\Documents and Settings\Hero Link\Application Data\Microsoft
2006-10-09 00:45 -------- d-------- C:\Program Files\MSN Messenger
2006-10-09 00:42 -------- d-------- C:\Program Files\AOD
2006-10-09 00:42 -------- d-------- C:\Program Files\AIM
2006-09-29 00:15 -------- d-------- C:\Documents and Settings\Hero Link\Application Data\LimeWire
2006-09-28 20:18 -------- d-------- C:\Program Files\Microsoft ActiveSync
2006-09-28 20:18 -------- d-------- C:\Program Files\Common Files\Microsoft Shared
2006-09-28 20:18 -------- d-------- C:\Program Files\Common Files\DESIGNER
2006-09-28 20:17 -------- d-------- C:\Program Files\Microsoft Office
2006-09-28 20:16 -------- d-------- C:\Program Files\Microsoft.NET
2006-09-28 20:16 -------- d-------- C:\Program Files\Common Files\System
2006-09-28 12:14 -------- d-------- C:\Program Files\Copy of mIRC
2006-09-28 12:11 -------- d-------- C:\Program Files\mIRC2
2006-09-27 23:40 -------- d-------- C:\Documents and Settings\Hero Link\Application Data\Help
2006-09-27 19:30 -------- d-------- C:\Program Files\Opera 8 Beta
2006-09-27 19:25 -------- d-------- C:\Program Files\MessengerPlus! 3
2006-09-22 23:36 -------- d--h----- C:\Program Files\InstallShield Installation Information
2006-09-22 23:29 -------- d-------- C:\Program Files\WIZET
2006-09-05 00:13 2180224 --a------ C:\WINDOWS\system32\kernel1.exe
2006-08-21 06:21 16896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-08-21 03:14 23040 --a------ C:\WINDOWS\system32\fltmc.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"AIM"="C:\\PROGRA~1\\AIM\\aim.exe -cnetwait.odl"
"STYLEXP"="C:\\Program Files\\TGTSoft\\StyleXP\\StyleXP.exe -Hide"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\" /WinStart"
"msnmsgr"="\"C:\\Program Files\\MSN Messenger\\msnmsgr.exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"DIAGENT"="C:\\Program Files\\Creative\\SBLive\\Creative Diagnostics 2.0\\DIAGENT.EXE startup"
"UpdReg"="C:\\WINDOWS\\Updreg.exe"
"AHQInit"="C:\\Program Files\\Creative\\SBLive\\Program\\AHQInit.exe"
"AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\""
"NAV Agent"="C:\\PROGRA~1\\NORTON~1\\navapw32.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"MessengerPlus3"="\"C:\\Program Files\\MessengerPlus! 3\\MsgPlus.exe\""
"ViewMgr"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"Microsoft Works Portfolio"="C:\\Program Files\\Microsoft Works\\WksSb.exe /AllUsers"
"Microsoft Works Update Detection"="C:\\Program Files\\Common Files\\Microsoft Shared\\Works Shared\\WkUFind.exe"
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvMcTray.dll,NvTaskbarInit"
"VirtualCloneDrive"="\"C:\\Program Files\\Elaborate Bytes\\VirtualCloneDrive\\VCDDaemon.exe\" /s"
"{20-04-46-64-ZN}"="c:\\windows\\system32\\oldsregk.exe ELT001"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"ccApp"="\"C:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"NAV CfgWiz"="\"C:\\Program Files\\Norton AntiVirus\\CfgWiz.exe\" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE \"REBOOT\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Windows Secure Connection"="winsc.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"Windows Secure Connection"="winsc.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{2B1B63E0-D818-4FB0-A504-DB8546149ABB}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=hex:5f,00,00,00
@=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091
"CDRAutoRun"=dword:00000000

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeviceDiscovery]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpotdd01"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\Digital Imaging\\bin\\hpotdd01.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="HPWuSchd"
"hkey"="HKLM"
"command"="C:\\Program Files\\Hewlett-Packard\\HP Software Update\\HPWuSchd.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPDJ Taskbar Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpztsb08"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb08.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SIDEBAR]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="sidebar"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\Resources\\Themes\\DameK UltraBlue\\Desktop Sidebar\\sidebar.exe"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\sstts
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\winowl32
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuropm

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Hero Link.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer.job

Completion time: 06-11-06 22:05:45.28
C:\ComboFix.txt ... 06-11-06 22:05


Logfile of HijackThis v1.99.1
Scan saved at 10:12:40 PM, on 11/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\CTsvcCDA.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\AIM\aim.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\taskmgr.exe
C:\WINDOWS\system32\rundll32.exe
C:\DOCUME~1\HEROLI~1\LOCALS~1\Temp\~nsu.tmp\Au_.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Opera Wannabe
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [DIAGENT] C:\Program Files\Creative\SBLive\Creative Diagnostics 2.0\DIAGENT.EXE startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] C:\Program Files\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s
O4 - HKLM\..\Run: [{20-04-46-64-ZN}] c:\windows\system32\oldsregk.exe ELT001
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [STYLEXP] C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop...p/PCPitStop.CAB
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.micros...b?1155404062674
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: StyleXPService - Unknown owner - C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe


It's still bringing up the internet connection prompt. I'm wondering if it is my Norton trying to update. I'm gonna check that. (I've been posting from my laptop, and the issue is on my desktop, just in case you were wondering. ^_^)
  • 0

#6
loophole

loophole

    Malware Expert

  • Retired Staff
  • 9,798 posts
Hi :whistling:

Please Rightclick Hijackthis.exe. and rename it to HJT.exe

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP