Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Help me Clean "Worm.Win32.NetSky"


  • Please log in to reply

#1
agordona

agordona

    Member

  • Member
  • PipPip
  • 25 posts
My computer is infected with Worm.Win32.NetSky. It changed my desktop, while surfing on internet, with this red wallpaper showing only one option: to download a new malware program that I have never heard of. Windows Security alerts keep going with these popup that are slowing my computer and it's showing some website for downloading this new software that might repair this problem.
I followed the instructions you gave someone previously, that is running smitfraud.exe in safe mode and running wininet.dll.
Please find the logs the two programs generated:

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\privacy_danger\ Deleted
C:\DOCUME~1\GORDON~1\Desktop\Error Cleaner.url Deleted
C:\DOCUME~1\GORDON~1\Desktop\Privacy Protector.url Deleted
C:\DOCUME~1\GORDON~1\Desktop\Spyware?Malware Protection.url Deleted
C:\DOCUME~1\GORDON~1\FAVORI~1\Error Cleaner.url Deleted
C:\DOCUME~1\GORDON~1\FAVORI~1\Privacy Protector.url Deleted
C:\DOCUME~1\GORDON~1\FAVORI~1\Spyware?Malware Protection.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End






-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 5 Restore Point(s) --
84: 2008-01-09 23:53:39 UTC - RP471 - Deckard's System Scanner Restore Point
83: 2008-01-09 22:53:51 UTC - RP470 - Software Distribution Service 3.0
82: 2008-01-07 00:46:02 UTC - RP469 - Installed McAfee VirusScan Enterprise
81: 2008-01-07 00:36:30 UTC - RP468 - Installed AVG 7.5
80: 2008-01-07 00:36:00 UTC - RP467 - Removed AVG 7.5


-- First Restore Point --
1: 2007-11-02 21:07:38 UTC - RP388 - Installed CVS Photo Editor Plus


Backed up registry hives.
Performed disk cleanup.



-- HijackThis Clone ------------------------------------------------------------


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2008-01-09 18:00:28
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\MarkAny\ContentSafer\MaAgent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\hpwuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmgr.exe
C:\Program Files\Gizmo Project\Gizmo.exe
C:\Program Files\Lexmark 1200 Series\LXCZbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\VoipBuster.com\VoipBuster\voipbuster.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\McAfee\Common Framework\Mctray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\LogiShrd\LQCVFX\COCIManager.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\Documents and Settings\Gordon Akudibillah\Desktop\dss.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearsh...ar.html?src=ssb
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.microsoft...amp;ar=iesearch
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://home.microsof...search.asp?p=%s
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Go






What do I do next? Thanks in advance for your help.

Warm Regards
Gordon
  • 0

Advertisements


#2
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
I'd start by posting a full HJT log as yours isn't. Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

  • 0

#3
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Thanks for your help please find below the two logs you requested staring with the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:53:21, on 10/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Gizmo Project\Gizmo.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearsh...ar.html?src=ssb
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:0/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: The ensfolr - {3723900A-B26F-40EC-B606-B7B37132B83F} - C:\WINDOWS\ensfolr.dll (file missing)
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Gizmo Project] "C:\Program Files\Gizmo Project\Gizmo.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\CVS\CVS Photo Editor Plus\Corel Photo Downloader.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.h...DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2p...bs/QOLCheck.ocx
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com...e/KooPlayer.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163503698125
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E6182DB0-BE70-4EA3-A8FB-D402C6D951D5} (VUploader Control) - http://photofiddle.c...loaderProj1.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...200/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia....upv2.0.0.10.cab?
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com...ookImporter.CAB
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.co...0.94_signed.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: bklgvsf - {AE0786B4-4AB7-46E0-B879-D89DC99366F1} - C:\WINDOWS\bklgvsf.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.5.709.30344 (GoogleDesktopManager-093007-112848) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Hrotesc - Hewlett-Packard Development Company, L.P. - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 18178 bytes





p5 Card Slingo from Hewlett-Packard Laptops (remove only)
ABBYY FineReader 6.0 Sprint
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS
Adobe Photoshop CS3
Adobe Photoshop CS3
Adobe Reader 8.1.1
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Adobe® Photoshop® Album Starter Edition 3.2
Apple Mobile Device Support
Apple Software Update
AudibleManager
Avery Wizard 3.1
Bejeweled 2 Deluxe from Hewlett-Packard Laptops (remove only)
Big Kahuna Reef from Hewlett-Packard Laptops (remove only)
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only)
Blasterball 2 from Hewlett-Packard Laptops (remove only)
Boggle Supreme from Hewlett-Packard Laptops (remove only)
Bookworm Deluxe from Hewlett-Packard Laptops (remove only)
Bounce Symphony from Hewlett-Packard Laptops (remove only)
Chuzzle Deluxe from Hewlett-Packard Laptops (remove only)
Cisco Clean Access Agent
Conexant HD Audio
Cozi Central
Creative Commons Add-in for Microsoft Office
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
Crystal Maze from Hewlett-Packard Laptops (remove only)
Customer Experience Enhancement
CVS Photo Editor Plus
ĐÂÀËÖ±²¥
Digimax L60 /Kenox X60
Digimax Master
DivX
DivX Content Uploader
DivX Web Player
Easy Internet Sign-up
EndNote 8.0.2
ESPNMotion
FATE from Hewlett-Packard Laptops (remove only)
Final Drive Nitro from Hewlett-Packard Laptops (remove only)
Flickr Uploadr 2.3
Flip Words from Hewlett-Packard Laptops (remove only)
GDR 1406 for SQL Server Analysis Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Database Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Integration Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Notification Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Tools and Workstation Components 2005 ENU (KB932557)
GemMaster Mystic
Gizmo Project 4.0
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB910728)
Hotfix for Windows XP (KB912436)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB916089)
Hotfix for Windows XP (KB926239)
hp deskjet 3600
HP Game Console and games
HP Help and Support
HP Imaging Device Functions 6.0
HP Memories Disc
HP Photo and Imaging 2.0 - Deskjet Series
HP Photosmart Premier Software 6.0
hp print screen utility
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Rhapsody
HP Update
HP User Guides 0032
HP Wireless Assistant 2.00 G2
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
Intel® Debugger for applications running on IA-32, Version 10.0
Intel® Fortran Compiler for IA-32 applications, Version 10.0.025
Intel® Fortran Compiler for Intel® 64 applications, Version 10.0.025
Intel® Visual Fortran Compiler 10.0 Integrations in Microsoft Visual Studio*
ISI ResearchSoft - Export Helper
iTunes
Java™ 6 Update 3
Jewel Quest from Hewlett-Packard Laptops (remove only)
Lame ACM MP3 Codec
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only)
Lexmark 1200 Series
Lexmark Fax Solutions
LimeWire 4.14.8
Logitech Audio Echo Cancellation Component
Logitech Desktop Messenger
Logitech QuickCam
Logitech Video Enumerator
Logitech® Camera Driver
Macromedia Flash Player 8
Macromedia Shockwave Player
Mah Jong Quest from Hewlett-Packard Laptops (remove only)
Manolito 1.1.9
Mathematica 5
MathType 5
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Device Emulator version 1.0 - ENU
Microsoft Document Explorer 2005
Microsoft Document Explorer 2005
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office 2003 Web Components
Microsoft Office Converter Pack
Microsoft Office XP Professional with FrontPage
Microsoft Outlook 2002
Microsoft SQL Server 2005
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Analysis Services
Microsoft SQL Server 2005 Backward compatibility
Microsoft SQL Server 2005 Books Online (English)
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Integration Services
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
Microsoft SQL Server 2005 Notification Services
Microsoft SQL Server 2005 Tools
Microsoft SQL Server 2005 Upgrade Advisor (English)
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual Studio 2005 Professional Edition - ENU
Microsoft Works
Mozilla Firefox (2.0.0.11)
MSDN Library for Visual Studio 2005
MSDN Library for Visual Studio 2005
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
muvee autoProducer 5.0
MVision
MyFreeCodec
MyPublisher BookMaker
NetWaiting
NVIDIA Drivers
Oasis from Hewlett-Packard Laptops (remove only)
Office 2003 Trial Assistant
openModeller Desktop 1.0.6
OpenVPN 2.1_beta16-gui-1.0.3
Otto
overland
Paint.NET v3.10
Pcast P2P Á÷Ă½̀å¿Ø¼₫ 1.0.0.17
PDF Settings
Picasa 2
Polar Bowler from Hewlett-Packard Laptops (remove only)
Polar Golfer from Hewlett-Packard Laptops (remove only)
PPStream
Puzzle Express from Hewlett-Packard Laptops (remove only)
Quicken 2006
QuickTime
RealPlayer
Samsung Media Studio
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB925674)
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB937060)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Shutterfly Plugin
Slingo Deluxe from Hewlett-Packard Laptops (remove only)
Slyder from Hewlett-Packard Laptops (remove only)
Snowboard SuperJam
Soft Data Fax Modem with SmartCP
Sonic Audio module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SonicAC3Encoder
SonicMPEGEncoder
SopCore 1.0.1
SQLXML4
Super Granny from Hewlett-Packard Laptops (remove only)
Symantec KB-DocID:2003093015493306
Synaptics Pointing Device Driver
The Weather Channel Desktop
TourSetup
Tradewinds from Hewlett-Packard Laptops (remove only)
TVAnts 1.0
TVUPlayer 2.3.4.1
UMVPLStandalone
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911164)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
USB PC Camera (SN9C102)
VeohTV BETA
VOIP080
VoipBuster
Vonage Easy Setup Guide
Vongo
Weather Services
WebVideo Support
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Sign-in Assistant
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix - KB895316
Windows Media Player 11
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890546
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891220
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
Windows XP Media Center Edition 2005 KB925766
Wireless Home Network Setup
XviD MPEG-4 Video Codec
ZENcast Organizer
Zoom ADSL Modem
Zoom ADSL Modem
Zuma Deluxe from Hewlett-Packard Laptops (remove only)
  • 0

#4
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

If you already have a copy, open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then <ENTER> to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, continue with the scan, "option 1", below.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue..."
Press "1" and then <ENTER> to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Please Note: Some security programs will incorrectly identify this tool as potentially or actually malicious due to some of it's components. Although these files can be used maliciously, they are an integral part of the fix and I recommend you tell your scanner to mind it's own business this time.
  • 0

#5
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Thanks fpr your reply. Please ind below the "rapport.txt":

SmitFraudFix v2.274

Scan done at 14:31:24.89, 11/01/2008
Run from C:\Documents and Settings\Gordon Akudibillah\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gordon Akudibillah


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gordon Akudibillah\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GORDON~1\FAVORI~1

C:\DOCUME~1\GORDON~1\FAVORI~1\Error Cleaner.url FOUND !
C:\DOCUME~1\GORDON~1\FAVORI~1\Privacy Protector.url FOUND !
C:\DOCUME~1\GORDON~1\FAVORI~1\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\GORDON~1\Desktop\Error Cleaner.url FOUND !
C:\DOCUME~1\GORDON~1\Desktop\Privacy Protector.url FOUND !
C:\DOCUME~1\GORDON~1\Desktop\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"
"LoadAppInit_DLLs"=dword:00000001


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.15.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0

#6
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
Apologies for the delay - it appears the email notifications are down again. Will you post a fresh HJT log and another Smitfraud scan and i'll monitor this thread to ensure I get the reply directly. Sorry again. :)
  • 0

#7
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
That explains my endless wait to hear from you. The pop up caused by "Worm.Win32.NetSky" have suddenly stopped, i was surprised because I did nothing but just wait for you.
Anyway find below the two new logs you requested:

Full HJT list

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 07:17:08, on 19/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam\Quickcam.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Gizmo Project\Gizmo.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearsh...ar.html?src=ssb
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:0/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: The ensfolr - {3723900A-B26F-40EC-B606-B7B37132B83F} - C:\WINDOWS\ensfolr.dll (file missing)
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [Gizmo Project] "C:\Program Files\Gizmo Project\Gizmo.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\CVS\CVS Photo Editor Plus\Corel Photo Downloader.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [VoipBuster] "C:\Program Files\VoipBuster.com\VoipBuster\VoipBuster.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.h...DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2p...bs/QOLCheck.ocx
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com...e/KooPlayer.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163503698125
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E6182DB0-BE70-4EA3-A8FB-D402C6D951D5} (VUploader Control) - http://photofiddle.c...loaderProj1.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...200/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia....upv2.0.0.10.cab?
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com...ookImporter.CAB
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.co...0.94_signed.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O21 - SSODL: bklgvsf - {AE0786B4-4AB7-46E0-B879-D89DC99366F1} - C:\WINDOWS\bklgvsf.dll (file missing)
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Hrotesc - Hewlett-Packard Development Company, L.P. - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 18328 bytes




Uninstall_list.txt

5 Card Slingo from Hewlett-Packard Laptops (remove only)
ABBYY FineReader 6.0 Sprint
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS
Adobe Photoshop CS3
Adobe Photoshop CS3
Adobe Reader 8.1.1
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Shockwave Player
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Adobe® Photoshop® Album Starter Edition 3.2
Apple Mobile Device Support
Apple Software Update
AudibleManager
Avery Wizard 3.1
Bejeweled 2 Deluxe from Hewlett-Packard Laptops (remove only)
Big Kahuna Reef from Hewlett-Packard Laptops (remove only)
Blackhawk Striker 2 from Hewlett-Packard Laptops (remove only)
Blasterball 2 from Hewlett-Packard Laptops (remove only)
Boggle Supreme from Hewlett-Packard Laptops (remove only)
Bookworm Deluxe from Hewlett-Packard Laptops (remove only)
Bounce Symphony from Hewlett-Packard Laptops (remove only)
Chuzzle Deluxe from Hewlett-Packard Laptops (remove only)
Cisco Clean Access Agent
Conexant HD Audio
Cozi Central
Creative Commons Add-in for Microsoft Office
Creative MediaSource 5
Creative Removable Disk Manager
Creative System Information
Creative ZEN V Series (R2)
Crystal Maze from Hewlett-Packard Laptops (remove only)
Customer Experience Enhancement
CVS Photo Editor Plus
ĐÂÀËÖ±²¥
Digimax L60 /Kenox X60
Digimax Master
DivX
DivX Content Uploader
DivX Web Player
Easy Internet Sign-up
EndNote 8.0.2
ESPNMotion
FATE from Hewlett-Packard Laptops (remove only)
Final Drive Nitro from Hewlett-Packard Laptops (remove only)
Flickr Uploadr 2.3
Flip Words from Hewlett-Packard Laptops (remove only)
GDR 1406 for SQL Server Analysis Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Database Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Integration Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Notification Services 2005 ENU (KB932557)
GDR 1406 for SQL Server Tools and Workstation Components 2005 ENU (KB932557)
GemMaster Mystic
Gizmo Project 4.0
Google Desktop
Google Earth
Google Toolbar for Internet Explorer
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB909095)
Hotfix for Windows XP (KB910728)
Hotfix for Windows XP (KB912436)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB916089)
Hotfix for Windows XP (KB926239)
hp deskjet 3600
HP Game Console and games
HP Help and Support
HP Imaging Device Functions 6.0
HP Memories Disc
HP Photo and Imaging 2.0 - Deskjet Series
HP Photosmart Premier Software 6.0
hp print screen utility
HP Quick Launch Buttons 6.10 A2
HP QuickPlay 2.3
HP Rhapsody
HP Update
HP User Guides 0032
HP Wireless Assistant 2.00 G2
Insaniquarium Deluxe from Hewlett-Packard Laptops (remove only)
Intel® Debugger for applications running on IA-32, Version 10.0
Intel® Fortran Compiler for IA-32 applications, Version 10.0.025
Intel® Fortran Compiler for Intel® 64 applications, Version 10.0.025
Intel® Visual Fortran Compiler 10.0 Integrations in Microsoft Visual Studio*
ISI ResearchSoft - Export Helper
iTunes
Java™ 6 Update 3
Jewel Quest from Hewlett-Packard Laptops (remove only)
Lame ACM MP3 Codec
Lemonade Tycoon 2 from Hewlett-Packard Laptops (remove only)
Lexibox Deluxe from Hewlett-Packard Laptops (remove only)
Lexmark 1200 Series
Lexmark Fax Solutions
LimeWire 4.14.8
Logitech Audio Echo Cancellation Component
Logitech Desktop Messenger
Logitech QuickCam
Logitech Video Enumerator
Logitech® Camera Driver
Macromedia Flash Player 8
Macromedia Shockwave Player
Mah Jong Quest from Hewlett-Packard Laptops (remove only)
Manolito 1.1.9
Mathematica 5
MathType 5
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Device Emulator version 1.0 - ENU
Microsoft Document Explorer 2005
Microsoft Document Explorer 2005
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office 2003 Primary Interop Assemblies
Microsoft Office 2003 Web Components
Microsoft Office Converter Pack
Microsoft Office XP Professional with FrontPage
Microsoft Outlook 2002
Microsoft SQL Server 2005
Microsoft SQL Server 2005
Microsoft SQL Server 2005 Analysis Services
Microsoft SQL Server 2005 Backward compatibility
Microsoft SQL Server 2005 Books Online (English)
Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)
Microsoft SQL Server 2005 Integration Services
Microsoft SQL Server 2005 Mobile [ENU] Developer Tools
Microsoft SQL Server 2005 Notification Services
Microsoft SQL Server 2005 Tools
Microsoft SQL Server 2005 Upgrade Advisor (English)
Microsoft SQL Server Native Client
Microsoft SQL Server Setup Support Files (English)
Microsoft SQL Server VSS Writer
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Visual J# 2.0 Redistributable Package
Microsoft Visual Studio 2005 Professional Edition - ENU
Microsoft Works
Mozilla Firefox (2.0.0.11)
MSDN Library for Visual Studio 2005
MSDN Library for Visual Studio 2005
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 6.0 Parser (KB933579)
muvee autoProducer 5.0
MVision
MyFreeCodec
MyPublisher BookMaker
NetWaiting
NVIDIA Drivers
Oasis from Hewlett-Packard Laptops (remove only)
Office 2003 Trial Assistant
openModeller Desktop 1.0.6
OpenVPN 2.1_beta16-gui-1.0.3
Otto
overland
Paint.NET v3.10
Pcast P2P Á÷Ă½̀å¿Ø¼₫ 1.0.0.17
PDF Settings
Picasa 2
Polar Bowler from Hewlett-Packard Laptops (remove only)
Polar Golfer from Hewlett-Packard Laptops (remove only)
PPStream
Puzzle Express from Hewlett-Packard Laptops (remove only)
Quicken 2006
QuickTime
RealPlayer
Samsung Media Studio
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB925674)
Security Update for Microsoft Visual Studio 2005 Professional Edition - ENU (KB937060)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944653)
Shutterfly Plugin
Slingo Deluxe from Hewlett-Packard Laptops (remove only)
Slyder from Hewlett-Packard Laptops (remove only)
Snowboard SuperJam
Soft Data Fax Modem with SmartCP
Sonic Audio module
Sonic Data Module
Sonic Express Labeler
Sonic MyDVD Plus
Sonic Update Manager
SonicAC3Encoder
SonicMPEGEncoder
SopCore 1.0.1
SQLXML4
Super Granny from Hewlett-Packard Laptops (remove only)
Symantec KB-DocID:2003093015493306
Synaptics Pointing Device Driver
The Weather Channel Desktop
TourSetup
Tradewinds from Hewlett-Packard Laptops (remove only)
TVAnts 1.0
TVUPlayer 2.3.4.1
UMVPLStandalone
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911164)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925720)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
USB PC Camera (SN9C102)
VeohTV BETA
VOIP080
VoipBuster
Vonage Easy Setup Guide
Vongo
Weather Services
WebVideo Support
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live installer
Windows Live Sign-in Assistant
Windows Media Connect
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10 Hotfix - KB895316
Windows Media Player 11
Windows Media Player 11
Windows Media Player Firefox Plugin
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885855
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888239
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890546
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891220
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB892559
Windows XP Media Center Edition 2005 KB925766
Wireless Home Network Setup
XviD MPEG-4 Video Codec
ZENcast Organizer
Zoom ADSL Modem
Zoom ADSL Modem
Zuma Deluxe from Hewlett-Packard Laptops (remove only)



Rapport.txt


SmitFraudFix v2.274

Scan done at 7:35:43.82, 19/01/2008
Run from C:\Documents and Settings\Gordon Akudibillah\Desktop\worm.win32.netsky repair\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gordon Akudibillah


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Gordon Akudibillah\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\GORDON~1\FAVORI~1

C:\DOCUME~1\GORDON~1\FAVORI~1\Error Cleaner.url FOUND !
C:\DOCUME~1\GORDON~1\FAVORI~1\Privacy Protector.url FOUND !
C:\DOCUME~1\GORDON~1\FAVORI~1\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~2\\GOEC62~1.DLL"
"LoadAppInit_DLLs"=dword:00000001


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.15.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0

#8
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
I've just popped in to check the thread - i'll be back in a couple of hours with some instructions to clean the crud up once i've dealt with an issue or two elsewhere.
  • 0

#9
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then <ENTER> to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.

2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted. If this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.c...rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

O3 - Toolbar: The ensfolr - {3723900A-B26F-40EC-B606-B7B37132B83F} - C:\WINDOWS\ensfolr.dll (file missing)

O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto

O21 - SSODL: bklgvsf - {AE0786B4-4AB7-46E0-B879-D89DC99366F1} - C:\WINDOWS\bklgvsf.dll (file missing)


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

4) Remove any/all of the following files/folders that you can find:

Folders

C:\Program Files\winupdates

As an example:
To delete C:\WINDOWS\system32\foldertogo
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on foldertogo and from the menu that appears, click on 'Delete'


5) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

6) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

7) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

8) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you should see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

9) Empty the Recycle Bin.

10) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

11) Reboot into Normal Mode.

12) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.

Will you also confirm for me that you no longer have any Symantec software on your PC. There a re what would appear to be leftovers on your system which need removing. They are quite common, and quite easy to deal with, but i'd like to be sure before I ruin something that you actually need.
  • 0

#10
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
While running the cleaning process of Smithfraudfix in "Safe Mode" my laptop keeps shutting down. I tried this four times and my computer keeps shutting down
what can i do about this?
  • 0

Advertisements


#11
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
Try it in Normal Mode and then boot into Safe Mode after that step - if you can. If not, run the whole fix in Normal Mode and we'll see what's what then.
  • 0

#12
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
I couldn’t operate in “safe mode” so I had to perform all the istrustion as you suggested in the “Nornal Mode”.
My computer seems to be working fine, I stalled on sending these reports because I wanted to see how my computer was holding up.
Please find below the logs you requested:

HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:20:26, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:0/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.h...DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2p...bs/QOLCheck.ocx
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com...e/KooPlayer.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163503698125
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E6182DB0-BE70-4EA3-A8FB-D402C6D951D5} (VUploader Control) - http://photofiddle.c...loaderProj1.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...200/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia....upv2.0.0.10.cab?
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com...ookImporter.CAB
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.co...0.94_signed.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Hrotesc - Hewlett-Packard Development Company, L.P. - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 16424 bytes


AVG A-S log

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 22:53:40 19/01/2008

+ Scan result:



C:\Program Files\music_now\inetchk.exe -> Hijacker.Small : No action taken.
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : No action taken.
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP464\A0159335.exe -> Not-A-Virus.Hoax.Win32.Renos.wx : No action taken.
:mozilla.603:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.604:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.204:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.205:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.206:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.207:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.208:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.209:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.210:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.211:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.212:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.213:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.214:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.215:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.216:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.217:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.218:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.219:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.220:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.221:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.222:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.223:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.224:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.225:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.226:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.227:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.228:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.229:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.230:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.231:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.232:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.233:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.434:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.605:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.802:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.814:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.301:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.302:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.303:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.304:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.82:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.83:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.84:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.85:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.86:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.87:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.88:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.89:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adtech[1].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.174:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.175:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.176:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.177:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.178:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.21:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.391:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.681:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.686:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.687:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.688:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.67:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.68:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.69:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.70:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.71:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.72:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.73:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.74:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.75:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.76:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.77:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.78:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.79:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.80:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.733:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.342:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Dealtime : No action taken.
:mozilla.16:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.37:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.38:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.39:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.40:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.41:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.42:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.44:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.45:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.46:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.47:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.48:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.202:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.338:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.417:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.611:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.701:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.816:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.184:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.185:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.186:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.187:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.188:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.345:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.346:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.347:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.348:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.349:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.350:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.351:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.352:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.19:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.20:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.544:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.551:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.552:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.554:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.706:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.727:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.81:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.7:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Netflame : No action taken.
:mozilla.8:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Netflame : No action taken.
:mozilla.566:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.567:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.397:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.398:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.399:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@overture[1].txt -> TrackingCookie.Overture : No action taken.
:mozilla.251:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.252:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.253:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.254:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.255:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.256:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.257:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.258:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.259:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.577:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.578:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.590:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.591:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.592:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.593:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.594:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.595:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.596:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.597:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.598:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.599:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.600:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.260:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.261:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.262:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.263:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.264:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.265:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.266:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.267:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.268:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.269:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.270:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.271:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.272:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.273:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.734:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@revsci[2].txt -> TrackingCookie.Revsci : No action taken.
:mozilla.615:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.616:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.617:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.618:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.619:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.620:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.621:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.104:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.105:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.106:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:
  • 0

#13
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Looks like i can't get all the reports at one go so I will just post them separately
below is the HJT log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:20:26, on 20/01/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Gizmo Project\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\lxczcoms.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe
C:\Program Files\Lexmark 1200 Series\lxczbmon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL.3\OLAP\bin\msmdsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PSIService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\msftesql.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:0/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SMSTray] C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [openvpn-gui] C:\Program Files\OpenVPN\bin\openvpn-gui.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [MAAgent] C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\HP\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [lxczbmgr.exe] "C:\Program Files\Lexmark 1200 Series\lxczbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [IETI] C:\Program Files\Skype\Phone\IEPlugin\unins000.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART (User 'Default user')
O4 - .DEFAULT User Startup: Vongo Tray.lnk = C:\Program Files\Vongo\Tray.exe (User 'Default user')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://a1540.g.akama...ex/qtplugin.cab
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative....030/CTSUEng.cab
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.h...DataManager.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O16 - DPF: {483EB14D-AF1C-4951-81B0-4E2B41829FF6} (QOLCheck Control) - https://www.select2p...bs/QOLCheck.ocx
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.tvkoo.com...e/KooPlayer.ocx
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163503698125
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {E6182DB0-BE70-4EA3-A8FB-D402C6D951D5} (VUploader Control) - http://photofiddle.c...loaderProj1.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcaf...200/mcfscan.cab
O16 - DPF: {F137B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://cvs.pnimedia....upv2.0.0.10.cab?
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative....15030/CTPID.cab
O16 - DPF: {FDD6CEF8-3C6E-42E0-BC7B-D730085CFABC} (Jaxtr Outlook Importer) - http://www.jaxtr.com...ookImporter.CAB
O16 - DPF: {FEE1002D-90A5-4A5D-AABE-01803FFBCF7A} - http://ps.itv.mop.co...0.94_signed.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.aka...vex-2.2.1.6.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Gizmo Project\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Desktop Manager 5.7.801.1629 (GoogleDesktopManager-010108-205858) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Hrotesc - Hewlett-Packard Development Company, L.P. - (no file)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\OpenVPN\bin\openvpnserv.exe
O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe

--
End of file - 16424 bytes
  • 0

#14
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
AVG A-S log
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 22:53:40 19/01/2008

+ Scan result:



C:\Program Files\music_now\inetchk.exe -> Hijacker.Small : No action taken.
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : No action taken.
C:\System Volume Information\_restore{3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP464\A0159335.exe -> Not-A-Virus.Hoax.Win32.Renos.wx : No action taken.
:mozilla.603:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.604:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.204:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.205:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.206:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.207:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.208:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.209:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.210:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.211:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.212:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.213:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.214:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.215:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.216:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.217:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.218:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.219:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.220:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.221:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.222:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.223:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.224:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.225:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.226:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.227:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.228:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.229:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.230:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.231:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.232:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.233:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.434:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.605:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.802:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.814:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.301:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.302:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.303:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.304:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.82:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.83:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.84:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.85:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.86:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.87:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.88:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.89:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@adtech[1].txt -> TrackingCookie.Adtech : No action taken.
:mozilla.174:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.175:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.176:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.177:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.178:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.21:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.391:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.681:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.686:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.687:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.688:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.67:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.68:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.69:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.70:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.71:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.72:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.73:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.74:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.75:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.76:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.77:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.78:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.79:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.80:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.733:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.342:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Dealtime : No action taken.
:mozilla.16:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@doubleclick[2].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.37:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.38:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.39:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.40:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.41:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.42:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.44:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.45:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.46:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.47:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.48:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.202:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.338:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.417:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.611:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.701:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.816:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.184:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.185:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.186:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.187:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.188:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.345:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.346:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.347:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.348:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.349:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.350:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.351:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.352:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.19:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.20:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.544:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.551:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.552:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.554:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.706:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.727:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.81:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.7:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Netflame : No action taken.
:mozilla.8:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Netflame : No action taken.
:mozilla.566:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.567:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.397:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.398:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.399:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@overture[1].txt -> TrackingCookie.Overture : No action taken.
:mozilla.251:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.252:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.253:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.254:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.255:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.256:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.257:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.258:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.259:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.577:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.578:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.590:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.591:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.592:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.593:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.594:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.595:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.596:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.597:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.598:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.599:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.600:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.260:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.261:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.262:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.263:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.264:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.265:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.266:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.267:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.268:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.269:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.270:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.271:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.272:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.273:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
:mozilla.734:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@revsci[2].txt -> TrackingCookie.Revsci : No action taken.
:mozilla.615:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.616:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.617:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.618:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.619:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.620:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.621:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.104:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.105:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.106:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.107:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.108:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.109:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.110:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.111:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.112:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.113:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.114:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.115:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.116:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.117:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.118:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.119:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.120:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.121:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.122:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.123:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.124:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.125:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.126:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.127:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.128:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.129:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.130:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.131:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.420:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.421:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.422:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.423:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.424:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.425:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.606:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.607:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.608:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.609:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.610:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.298:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.381:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.53:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.54:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.55:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.56:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.57:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.58:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.59:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.60:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.680:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.682:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.683:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.684:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.685:C:\Documents and Settings\Gordon Akudibillah\Application Data\Mozilla\Firefox\Profiles\rkh6juyu.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Gordon Akudibillah\Cookies\gordon_akudibillah@zedo[2].txt -> TrackingCookie.Zedo : No action taken.


::Report end
  • 0

#15
agordona

agordona

    Member

  • Topic Starter
  • Member
  • PipPip
  • 25 posts
Rapport.txt

SmitFraudFix v2.274

Scan done at 19:39:57.03, 19/01/2008
Run from C:\Documents and Settings\Gordon Akudibillah\Desktop\worm.win32.netsky repair\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» IEDFix

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: NVIDIA nForce Networking Controller - Packet Scheduler Miniport
DNS Server Search Order: 192.168.15.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{5BAF12BC-5397-48FC-9AB7-098DC522C800}: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.15.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP