or whatever it is called. Yeah, Here is my Log for HJT:: Logfile of HijackThis v1.99.1 Scan saved at 3:00:32 PM, on 6/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\WINDOWS\runservice.exe C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Gaim\gaim.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Winamp\winamp.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp103.tmp O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [763ad9de.exe] C:\WINDOWS\system32\763ad9de.exe O4 - HKLM\..\Run: [0a33c997.exe] C:\WINDOWS\system32\0a33c997.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1 O4 - HKCU\..\Run: [763ad9de.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\763ad9de.exe O4 - HKCU\..\Run: [0a33c997.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: O20 - Winlogon Notify: winuhu32 - C:\WINDOWS\SYSTEM32\winuhu32.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: McAfee AntiSpyware Real-Time Scanner (McAfeeAntiSpyware) - Network Associates, Inc. - C:\Program Files\McAfee\McAfee AntiSpyware\Msssrv.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe --- I already have Killbox.exe downloaded and on desktop. Any help you are able to extend, is greatly appreciated.
Hi Digaaz Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/ 1. Install ewido security suite 2. When installing, under "Additional Options" uncheck.. * Install background guard * Install scan via context menu 3. Launch ewido, there should be an icon on your desktop, double-click it. 4. The program will now open to the main screen. 5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment. 6. You will need to update ewido to the latest definition files. * On the left hand side of the main screen click update. * Then click on Start Update. 7. The update will start and a progress bar will show the updates being installed. (the status bar at the bottom will display ("Update successful") If you are having problems with the updater, you can use this link to manually update ewido. ewido manual updates -> http://www.ewido.net/en/download/updates/ Once the updates are installed do the following: Run Killbox.exe -> Choose Delete on Reboot -> Click All Files option. Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy) C:\WINDOWS\SYSTEM32\winzoa32.dll Then go back to Killbox -> go to File -> choose Paste from Clipboard -> Click the red-white Delete File option. -> Click Yes to Delete on Reboot question -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!) -> Restart your computer if Killbox won't do it. (If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe) When comp is running after removin, Scan hijack this and check O20 - Winlogon Notify: winuhu32 - C:\WINDOWS\SYSTEM32\winuhu32.dll Close all programs exept HijackThis and click Fix Checked Reboot your computer in SafeMode by doing the following: 1. Restart your computer 2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8. 3. Instead of Windows loading as normal, a menu should appear 4. Select the first option, to run Windows in Safe Mode. Launch ewido: * Click on scanner * Click on Complete System Scan and the scan will begin. * You will be prompted to clean the first infection. * Select "Perform action on all infections", then proceed. * Once the scan has completed, there will be a button located on the bottom of the screen named Save report * Click Save report. * Save the report .txt file to your desktop or a location where you can find it easily. Close ewido security suite. Reboot back to normal mode Send a fresh HjT log and ewido report.
Phew, finally. Hijack This:: Logfile of HijackThis v1.99.1 Scan saved at 5:11:16 PM, on 6/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\Explorer.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\runservice.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Gaim\gaim.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\Program Files\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp103.tmp O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [763ad9de.exe] C:\WINDOWS\system32\763ad9de.exe O4 - HKLM\..\Run: [0a33c997.exe] C:\WINDOWS\system32\0a33c997.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe O4 - HKCU\..\Run: [763ad9de.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\763ad9de.exe O4 - HKCU\..\Run: [0a33c997.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: O20 - Winlogon Notify: winuhu32 - winuhu32.dll (file missing) O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe ------- Ewido:: --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 4:49:42 PM, 6/9/2006 + Report-Checksum: 3362BAD0 + Scan result: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup HKU\S-1-5-21-1737644177-3205156622-1578707375-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned with backup HKU\S-1-5-21-1737644177-3205156622-1578707375-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8B6DA27E-7F64-4694-8F8F-DC87AB8C6B22} -> Adware.LinkMaker : Cleaned with backup [220] C:\WINDOWS\system32\winuhu32.dll -> Trojan.Agent.vg : Cleaned with backup :mozilla.34:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.39:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.53:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.66:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup :mozilla.67:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup :mozilla.68:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup :mozilla.106:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.112:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.157:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.159:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.160:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.162:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.163:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.165:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.166:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.171:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.172:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.174:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.175:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.176:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.177:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.178:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.179:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.180:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.181:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.182:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.183:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.184:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.185:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.186:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.187:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.188:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.189:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.190:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.192:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.193:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.194:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.195:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.196:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.197:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.198:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.199:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.200:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.201:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.204:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.205:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.206:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.207:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.208:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.209:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.210:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.212:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.213:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.241:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup :mozilla.242:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adocean : Cleaned with backup :mozilla.243:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.248:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup :mozilla.249:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup :mozilla.250:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup :mozilla.259:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.260:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup :mozilla.262:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.263:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.273:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.274:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.275:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.276:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.277:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.310:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.314:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.315:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.317:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.318:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.319:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.354:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.380:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.381:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.396:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.402:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.403:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.414:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup :mozilla.416:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.417:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.418:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.419:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.420:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.421:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.422:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.423:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.424:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.425:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.426:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.427:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.428:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.429:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.430:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.431:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.432:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.433:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup :mozilla.474:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.475:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.492:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.493:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.494:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.495:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.496:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.497:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.508:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.561:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup :mozilla.699:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.718:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.741:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.742:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.756:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup :mozilla.760:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.768:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.769:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.770:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.787:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.788:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.789:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.790:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.791:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.823:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.824:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.825:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.826:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup :mozilla.839:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup :mozilla.855:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.856:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.857:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.858:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.859:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.862:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.863:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.864:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.865:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.866:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.867:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.868:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.869:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.870:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.871:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.872:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.873:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.874:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.875:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.876:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.877:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.878:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.879:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.880:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.881:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.882:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.883:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.884:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.885:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.886:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.887:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.888:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.889:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.890:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.892:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.893:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.894:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.904:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.905:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup :mozilla.906:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.907:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.908:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.909:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.910:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.911:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.912:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.929:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.931:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.932:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.933:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.934:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.935:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.936:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.937:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.938:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.939:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.952:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.953:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.954:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.955:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.956:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\gsr331vd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned with backup C:\Documents and Settings\Owner\Cookies\owner@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Owner\Desktop\Downloads\dw22.exe -> Adware.Gator : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\F2E384.tmp/PMTInstaller.exe -> Adware.MDH : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\winD92.tmp.exe -> Hijacker.Small : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temp\winD9E.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\39SWOR37\srvaty[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\39SWOR37\YazzleActiveX[1].cab/YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\4LAF8PEJ\mulbin32[1].exe -> Hijacker.Small : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\4LAF8PEJ\srvsyi[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\4XQ301UB\srvstx[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\B4L1R0WG\wizip32[1].exe -> Hijacker.Small.kx : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\CTOY2OKX\srvfgj[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\SLAFK5UN\srvlpz[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\UOPT3JV3\srvmwc[1].exe -> Trojan.Dialer.oy : Cleaned with backup C:\Documents and Settings\Owner\Local Settings\Temporary Internet Files\Content.IE5\VEGR35GX\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup C:\Program Files\Microsoft AntiSpyware\Quarantine\949BCC21-63E9-443C-B01C-672D5E\4F4293A1-9C33-4F3B-8987-630991/1 -> Adware.IMAd : Cleaned with backup C:\Program Files\Microsoft AntiSpyware\Quarantine\949BCC21-63E9-443C-B01C-672D5E\4F4293A1-9C33-4F3B-8987-630991/2 -> Adware.Chiem : Cleaned with backup C:\Program Files\RealVNC\VNC4\winvnc4.exe -> Not-A-Virus.RemoteAdmin.Win32.WinVNC.4110 : Cleaned with backup C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup C:\WINDOWS\system32\1024\ldE838.tmp -> Trojan.Small : Cleaned with backup C:\WINDOWS\system32\atmclk.exe -> Trojan.Small : Cleaned with backup C:\WINDOWS\system32\winuhu32.dll -> Trojan.Agent.vg : Cleaned with backup C:\WINDOWS\Temp\win10E.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win15D.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win1C2.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup C:\WINDOWS\Temp\win1EF.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup ::Report End --- And yes, i did remove that one thing, apparently it came back...
Run Killbox.exe -> Choose Delete on Reboot -> Click All Files option. Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy) C:\WINDOWS\system32\763ad9de.exe C:\WINDOWS\system32\0a33c997.exe C:\Documents and Settings\Owner\Local Settings\Application Data\763ad9de.exe C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe Then go back to Killbox -> go to File -> choose Paste from Clipboard -> Click the red-white Delete File option. -> Click Yes to Delete on Reboot question -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!) -> Restart your computer if Killbox won't do it. Scan hijackthis and check these: R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: Nothing - {686a161d-5bd1-4999-8832-6393f41e564c} - C:\WINDOWS\system32\hp103.tmp O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O4 - HKLM\..\Run: [763ad9de.exe] C:\WINDOWS\system32\763ad9de.exe O4 - HKLM\..\Run: [0a33c997.exe] C:\WINDOWS\system32\0a33c997.exe O4 - HKCU\..\Run: [763ad9de.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\763ad9de.exe O4 - HKCU\..\Run: [0a33c997.exe] C:\Documents and Settings\Owner\Local Settings\Application Data\0a33c997.exe O20 - Winlogon Notify: winuhu32 - winuhu32.dll (file missing) Close all windows exept hijack and click fix checked. Boot your comp. Download SmitfraudFix.zip to your desktop -> http://siri.urz.free.fr/Fix/SmitfraudFix.zip Unzip it (folder named SmitFraudFix) to your desktop: Open the folder SmitfraudFix and doubleclick smitfraudfix.cmd Choose option #1 - Search by typing 1 and pressing "Enter"; a textfile opens and lists the infected files (if those exist) Post the contents of this textfile to here. Post a fresh hijackthis log too, (Some antiviruses recognises process.exe as a malware. It is not malware, it is a program that stops processes)
I also got this Warning: PendingFileRenameOperations registry data has been removed by external process! SmitFraudFix v2.56 Scan done at 19:35:12.73, Fri 06/09/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\dcomcfg.exe FOUND ! C:\WINDOWS\system32\hp???.tmp FOUND ! C:\WINDOWS\system32\hp????.tmp FOUND ! C:\WINDOWS\system32\ld????.tmp FOUND ! C:\WINDOWS\system32\ot.ico FOUND ! C:\WINDOWS\system32\regperf.exe FOUND ! C:\WINDOWS\system32\simpole.tlb FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Owner\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Owner\FAVORI~1 C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\SpywareQuake.com\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{5aaf6542-f4ba-4df4-873d-4902ecbe794c}"="antitragus" [HKEY_CLASSES_ROOT\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32] @="C:\WINDOWS\system32\asxbbx.dll" [HKEY_CURRENT_USER\Software\Classes\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32] @="C:\WINDOWS\system32\asxbbx.dll" »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End --- Hijack This! Log File Logfile of HijackThis v1.99.1 Scan saved at 7:36:11 PM, on 6/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\runservice.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\LXSUPMON.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Gaim\gaim.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\WINDOWS\system32\cmd.exe C:\WINDOWS\NOTEPAD.EXE C:\Program Files\HJT\HijackThis.exe R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe Did/have I miss(ed) anything so far?? XD
One line: Is this strart page wanted: R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com If not, then scan hijackthis and check and fix it . Restart your computer to the safemode -> http://www.pchell.com/support/safemode.shtml When in safemode, open SmitfraudFix folder and doubleclick the file smitfraudfix.cmd Choose option #2 - Clean by typing 2 and pressing "Enter" in order to remove the infected files. You are asked: "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove your desktop wallpaper and the infected registry keys. The tool checks if wininet.dll file is infected. You might be asked to replace the infected .dll (if found); answer "Yes" by typing Y and press "Enter". The tool might have to restart your computer; if it won't do it, restart your computer back to normal mode. A textfile will appear after the cleaning process, copy this file and paste it to here. Tha log is saved to your local diskdrive, usually C:\rapport.txt. Warning : Running option 2 in a clean computer will delete your desktop wallpaper. Send C:\rapport.txt and fresh hijackthis log
Eh, I don't use IE anyways, but thanks for pointing it out so I could remove it. ------------------------- Rapport SmitFraudFix v2.56 Scan done at 20:18:43.87, Fri 06/09/2006 Run from C:\Documents and Settings\Owner\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT Fix ran in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{5aaf6542-f4ba-4df4-873d-4902ecbe794c}"="antitragus" [HKEY_CLASSES_ROOT\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32] @="C:\WINDOWS\system32\asxbbx.dll" [HKEY_CURRENT_USER\Software\Classes\CLSID\{5aaf6542-f4ba-4df4-873d-4902ecbe794c}\InProcServer32] @="C:\WINDOWS\system32\asxbbx.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\dcomcfg.exe Deleted C:\WINDOWS\system32\hp???.tmp Deleted C:\WINDOWS\system32\ld????.tmp Deleted C:\WINDOWS\system32\ot.ico Deleted C:\WINDOWS\system32\regperf.exe Deleted C:\WINDOWS\system32\simpole.tlb Deleted C:\DOCUME~1\Owner\FAVORI~1\Antivirus Test Online.url Deleted C:\Program Files\SpywareQuake.com\ Deleted »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri C:\WINDOWS\system32\asxbbx.dll -> Missing File »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End ----------------------- Hijack This! Logfile of HijackThis v1.99.1 Scan saved at 8:29:12 PM, on 6/9/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\runservice.exe C:\Program Files\Norton AntiVirus\navapsvc.exe C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS C:\WINDOWS\system32\LXSUPMON.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\Yahoo!\Messenger\ypager.exe C:\Program Files\Gaim\gaim.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\HJT\HijackThis.exe R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Program Files\ICQToolbar\toolbaru.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\system32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [Gaim] C:\Program Files\Gaim\gaim.exe O4 - Startup: Check For Dope Wars Updates.lnk = C:\Program Files\Dopewars\WiseUpdt.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Program Files\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing) O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing) O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123 O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary/Bankshot.cab31267.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe ------------ Is this almost a happy computer again?? Heh.