sorry another W32.Myzor.FK@yf virus.

Discussion in 'Windows - Virus and spyware problems' started by dcho787, Jun 13, 2006.

  1. dcho787

    dcho787 Member

    Joined:
    Aug 27, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    I noticed that you guys can pinpoint the exact files i need to get rid of - can you help me? Here are the HJT and SmitFraudfix logs.

    Logfile of HijackThis v1.99.1
    Scan saved at 11:52:21 AM, on 6/13/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\System32\brsvc01a.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\brss01a.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\WINDOWS\system32\Brmfrmps.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Microsoft IntelliType Pro\type32.exe
    C:\WINDOWS\System32\RUNDLL32.EXE
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\Program Files\D-Tools\daemon.exe
    C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
    C:\Program Files\Brother\ControlCenter2\brctrcen.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\PROGRA~1\MUSICA~1\mac.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\159a032.exe
    C:\WINDOWS\System32\1a6723e6.exe
    C:\Program Files\eAcceleration\Station\station.exe
    C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\AIM\aim.exe
    C:\WINDOWS\System32\ctfmon.exe
    C:\DOCUME~1\DAVIDC~1\MYDOCU~1\SSTEM~1\dvdplay.exe
    C:\Documents and Settings\David Cho\Application Data\??mbols\e?plorer.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\HJT\HijackThis_v1.99.1.exe

    R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [159a032.exe] C:\WINDOWS\System32\159a032.exe
    O4 - HKLM\..\Run: [1a6723e6.exe] C:\WINDOWS\System32\1a6723e6.exe
    O4 - HKLM\..\Run: [SoftwareStation] "C:\Program Files\eAcceleration\Station\station.exe" /b Startup
    O4 - HKLM\..\Run: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus
    O4 - HKLM\..\Run: [webscan] "C:\Program Files\Acceleration Software\Anti-Virus\stopsignav.exe" -k
    O4 - HKLM\..\RunOnce: [StopSignSsTsMon] Rundll32.exe "C:\Program Files\Acceleration Software\Anti-Virus\sstsmon.dll",VerifyStatus /ro
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - HKCU\..\Run: [159a032.exe] C:\Documents and Settings\David Cho\Local Settings\Application Data\159a032.exe
    O4 - HKCU\..\Run: [Urop] "C:\DOCUME~1\DAVIDC~1\MYDOCU~1\SSTEM~1\dvdplay.exe" -vt yazr
    O4 - HKCU\..\Run: [1a6723e6.exe] C:\Documents and Settings\David Cho\Local Settings\Application Data\1a6723e6.exe
    O4 - HKCU\..\Run: [Lreof] C:\Documents and Settings\David Cho\Application Data\??mbols\e?plorer.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/XTools_2006_02_11.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C197BAF3-6B8A-4491-93D2-680D9254795B}: NameServer = 216.104.64.5,216.104.72.5
    O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe


    Here is the SmitFraudfix log.


    SmitFraudFix v2.60

    Scan done at 11:41:19.07, Tue 06/13/2006
    Run from C:\Documents and Settings\David Cho\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  2. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi dcho787

    Remove via add/remove-application

    StopSign
    eAcceleration
    SoftwareStation

    PuritySCAN By OIN, OuterInfo, OIN Or program similar name.

    If there is not in add/remove panel that kind off program,

    Please download uninstaller :
    http://www.outerinfo.com/OiUninstaller.exe

    Instructions :
    http://www.outerinfo.com/howto.html


    Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/

    1. Install ewido security suite
    2. When installing, under "Additional Options" uncheck..
    * Install background guard
    * Install scan via context menu
    3. Launch ewido, there should be an icon on your desktop, double-click it.
    4. The program will now open to the main screen.
    5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    6. You will need to update ewido to the latest definition files.
    * On the left hand side of the main screen click update.
    * Then click on Start Update.
    7. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")

    If you are having problems with the updater, you can use this link to manually update ewido.
    ewido manual updates -> http://www.ewido.net/en/download/updates/

    Once the updates are installed do the following:


    Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip
    Unzip it to your desktop.

    Run Killbox.exe
    -> Choose Delete on Reboot
    -> Click All Files option.

    Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)

    C:\WINDOWS\System32\159a032.exe
    C:\WINDOWS\System32\1a6723e6.exe
    C:\Documents and Settings\David Cho\Local Settings\Application Data\159a032.exe
    C:\DOCUME~1\DAVIDC~1\MYDOCU~1\SSTEM~1\dvdplay.exe
    C:\WINDOWS\SYSTEM32\winrvc32.dll

    Then go back to Killbox
    -> go to File
    -> choose Paste from Clipboard
    -> Click the red-white Delete File option.
    -> Click Yes to Delete on Reboot question
    -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
    -> Restart your computer if Killbox won't do it.

    (If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)


    When comp is running after removin, Scan hijack this and check

    O4 - HKLM\..\Run: [159a032.exe] C:\WINDOWS\System32\159a032.exe
    O4 - HKLM\..\Run: [1a6723e6.exe] C:\WINDOWS\System32\1a6723e6.exe
    O4 - HKCU\..\Run: C:\Documents and Settings\David Cho\Local Settings\Application Data\159a032.exe
    O4 - HKCU\..\Run: [Urop] "C:\DOCUME~1\DAVIDC~1\MYDOCU~1\SSTEM~1\dvdplay.exe" -vt yazr
    O4 - HKCU\..\Run: [1a6723e6.exe] C:\Documents and Settings\David Cho\Local Settings\Application Data\1a6723e6.exe
    O4 - HKCU\..\Run: [Lreof] C:\Documents and Settings\David Cho\Application Data\??mbols\e?plorer.exe
    O20 - Winlogon Notify: winrvc32 - C:\WINDOWS\SYSTEM32\winrvc32.dll

    Close all programs exept HijackThis and click Fix Checked


    Reboot your computer in SafeMode by doing the following:

    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.

    Delete folders
    C:\Program Files\ >>PurityScan\
    C:\Documents and Settings\David Cho\Application Data\ >>??mbols\
    C:\DOCUME~1\DAVIDC~1\MYDOCU~1\ >>SSTEM~1\

    Launch ewido:

    * Click on scanner
    * Click on Complete System Scan and the scan will begin.
    * You will be prompted to clean the first infection.
    * Select "Perform action on all infections", then proceed.
    * Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    * Click Save report.
    * Save the report .txt file to your desktop or a location where you can find it easily.

    Close ewido security suite.

    Reboot back to normal mode

    Send a fresh HjT log and ewido report
     
    Last edited: Jun 13, 2006
  3. dcho787

    dcho787 Member

    Joined:
    Aug 27, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    I couldn't find these two...

    O4 - HKCU\..\Run: [Urop] "C:\DOCUME~1\DAVIDC~1\MYDOCU~1\SSTEM~1\dvdplay.exe" -vt yazr
    O4 - HKCU\..\Run: [Lreof] C:\Documents and Settings\David Cho\Application Data\??mbols\e?plorer.exe

    is it ok? can i just fix check the rest of the list?
     
  4. dcho787

    dcho787 Member

    Joined:
    Aug 27, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    ok here is the ewido report

    ------------------------------------------------------

    ---
    ewido anti-malware - Scan report
    ------------------------------------------------------

    ---

    + Created on: 4:25:17 PM, 6/13/2006
    + Report-Checksum: F778CCF0

    + Scan result:

    HKLM\SOFTWARE\Clickspring -> Adware.PurityScan

    : Cleaned with backup
    [228] C:\WINDOWS\system32\winrvc32.dll ->

    Trojan.Agent.vg : Cleaned with backup
    C:\!KillBox\159a032.exe -> Downloader.

    Obfuscated.a : Cleaned with backup
    :mozilla.5:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.6:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.7:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.12:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Com : Cleaned

    with backup
    :mozilla.13:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Com : Cleaned

    with backup
    :mozilla.15:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Ru4 : Cleaned

    with backup
    :mozilla.16:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Ru4 : Cleaned

    with backup
    :mozilla.17:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Ru4 : Cleaned

    with backup
    :mozilla.28:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Questionmarket :

    Cleaned with backup
    :mozilla.36:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.37:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.38:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.39:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.40:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.41:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Trafficmp :

    Cleaned with backup
    :mozilla.57:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.58:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.59:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    :mozilla.60:C:\Documents and Settings\David

    Cho\Application Data\Mozilla\Firefox\Profiles\x1bqb8gn

    .default\cookies.txt -> TrackingCookie.Yieldmanager :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@112.2o7[2].txt -> TrackingCookie

    .2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@247realmedia[1].txt ->

    TrackingCookie.247realmedia : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@2o7[1].txt -> TrackingCookie.2o7

    : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@ad.yieldmanager[2].txt ->

    TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@ad1.clickhype[2].txt ->

    TrackingCookie.Clickhype : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@adopt.euroclick[2].txt ->

    TrackingCookie.Euroclick : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@adopt.specificclick[1].txt ->

    TrackingCookie.Specificclick : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@adrevolver[3].txt ->

    TrackingCookie.Adrevolver : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@ads.addynamix[1].txt ->

    TrackingCookie.Addynamix : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@ads.pointroll[2].txt ->

    TrackingCookie.Pointroll : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@ads.realcastmedia[1].txt ->

    TrackingCookie.Realcastmedia : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@adtech[2].txt -> TrackingCookie.

    Adtech : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@anat.tacoda[1].txt ->

    TrackingCookie.Tacoda : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@as-eu.falkag[2].txt ->

    TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@as-us.falkag[1].txt ->

    TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@as.casalemedia[1].txt ->

    TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@as1.falkag[2].txt ->

    TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@bluestreak[2].txt ->

    TrackingCookie.Bluestreak : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@bs.serving-sys[1].txt ->

    TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@burstnet[2].txt ->

    TrackingCookie.Burstnet : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@buycom.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@c5.zedo[1].txt -> TrackingCookie

    .Zedo : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@casalemedia[1].txt ->

    TrackingCookie.Casalemedia : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@centrport[1].txt ->

    TrackingCookie.Centrport : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@chicagosuntimes.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@citi.bridgetrack[1].txt ->

    TrackingCookie.Bridgetrack : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@cnn.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@com[2].txt -> TrackingCookie.Com

    : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@cpvfeed[2].txt -> TrackingCookie

    .Cpvfeed : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@cz3.clickzs[2].txt ->

    TrackingCookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@cz4.clickzs[2].txt ->

    TrackingCookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@cz5.clickzs[1].txt ->

    TrackingCookie.Clickzs : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@data1.perf.overture[2].txt ->

    TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@data2.perf.overture[1].txt ->

    TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@data3.perf.overture[2].txt ->

    TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfkiahczclq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfkiclcjwcp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfkoekdpifq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfkyqkajcbo.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wflickc5kbq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfloekdzwfp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfloemcpmlp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wflowidjgbp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wfmykmd5slq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wgkyuoczmep.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjk4emdjecq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkoaidzgcp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkoeocjcgo.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkogpazigq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkowlajicp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkychdpghp.stats.

    esomniture[1].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkyggdzobp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkyohajibp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjkyomajibp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjl4knajaho.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjl4oidzkco.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjligicjmko.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjlykpc5abp.stats.

    esomniture[1].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjlyqlcpsbp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjmicocjodp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjny-1gdjkl.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjny-1kd5ad.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjny-1sdjgh.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnyamcpgeo.stats.

    esomniture[1].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnyanc5efo.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnychd5kkp.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnycmcjoaq.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnycmczcco.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnygicpslo.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@e-2dj6wjnywgd5cgo.stats.

    esomniture[2].txt -> TrackingCookie.Esomniture :

    Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@edge.ru4[1].txt ->

    TrackingCookie.Ru4 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@entrepreneur.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@estat[1].txt -> TrackingCookie.

    Estat : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@etronics.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@falkag[1].txt -> TrackingCookie.

    Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@findwhat[1].txt ->

    TrackingCookie.Findwhat : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@fl01.ct2.comclick[1].txt ->

    TrackingCookie.Comclick : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@gateway.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@hotlog[1].txt -> TrackingCookie.

    Hotlog : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@hypertracker[2].txt ->

    TrackingCookie.Hypertracker : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@meetupcom.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@metacafe.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@microsofteup.112.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@msnportal.112.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@nbcuniversal.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@partygaming.122.2o7[1].txt ->

    TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@paypopup[1].txt ->

    TrackingCookie.Paypopup : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@perf.overture[1].txt ->

    TrackingCookie.Overture : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@premiumnetworkrocks.valuead[2].

    txt -> TrackingCookie.Valuead : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@primediabusiness.122.2o7[1].txt

    -> TrackingCookie.2o7 : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@qksrv[2].txt -> TrackingCookie.

    Qksrv : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@questionmarket[2].txt ->

    TrackingCookie.Questionmarket : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@reduxads.valuead[1].txt ->

    TrackingCookie.Valuead : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@revenue[1].txt -> TrackingCookie

    .Revenue : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@rotator.adjuggler[2].txt ->

    TrackingCookie.Adjuggler : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@sales.liveperson[2].txt ->

    TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@sec1.liveperson[2].txt ->

    TrackingCookie.Liveperson : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@sel.as-eu.falkag[1].txt ->

    TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@sel.as-us.falkag[1].txt ->

    TrackingCookie.Falkag : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@serving-sys[2].txt ->

    TrackingCookie.Serving-sys : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@stat.onestat[2].txt ->

    TrackingCookie.Onestat : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@statcounter[2].txt ->

    TrackingCookie.Statcounter : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@tacoda[1].txt -> TrackingCookie.

    Tacoda : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@tradedoubler[2].txt ->

    TrackingCookie.Tradedoubler : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@trafficmp[2].txt ->

    TrackingCookie.Trafficmp : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@trafic[1].txt -> TrackingCookie.

    Trafic : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@tribalfusion[1].txt ->

    TrackingCookie.Tribalfusion : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@valuead[1].txt -> TrackingCookie

    .Valuead : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@valueclick[1].txt ->

    TrackingCookie.Valueclick : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@vdn.valuead[1].txt ->

    TrackingCookie.Valuead : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@web4.realtracker[2].txt ->

    TrackingCookie.Realtracker : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@webstat[3].txt -> TrackingCookie

    .Web-stat : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@www.burstbeacon[2].txt ->

    TrackingCookie.Burstbeacon : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@www.myaffiliateprogram[1].txt ->

    TrackingCookie.Myaffiliateprogram : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@www.smartadserver[1].txt ->

    TrackingCookie.Smartadserver : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@www.web-stat[2].txt ->

    TrackingCookie.Web-stat : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@yadro[2].txt -> TrackingCookie.

    Yadro : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@yieldmanager[2].txt ->

    TrackingCookie.Yieldmanager : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@z1.adserver[1].txt ->

    TrackingCookie.Adserver : Cleaned with backup
    C:\Documents and Settings\David

    Cho\Cookies\david cho@zedo[1].txt -> TrackingCookie.

    Zedo : Cleaned with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Application Data\159a032.exe -> Downloader.

    Obfuscated.a : Cleaned with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\3NXHT5

    PM\srvwos[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\3NXHT5

    PM\YazzleActiveX[1].cab/YazzleActiveX.ocx -> Adware.

    MediaTickets : Cleaned with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\4Z2

    RQHAX\srvqwq[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\5RX2GE96

    \wizp32[1].exe -> Downloader.IstBar.eq : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\F4YB0O8

    C\srvjop[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\JZQWAF9

    J\mulbin32[1].exe -> Hijacker.Small : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\JZQWAF9

    J\podutil_keygen[1].exe -> Trojan.Agent.vg : Cleaned

    with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\JZQWAF9

    J\srvxck[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\U5

    CFINEN\wizip32[1].exe -> Hijacker.Small.kx : Cleaned

    with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\UN8V61

    WT\srvhbg[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\VHVVY8

    DC\wlzip32[1].exe -> Downloader.Obfuscated.a : Cleaned

    with backup
    C:\Documents and Settings\David Cho\Local

    Settings\Temporary Internet Files\Content.IE5\X20MN5

    PC\srvbcy[1].exe -> Trojan.Dialer.oy : Cleaned with

    backup
    C:\WINDOWS\system32\159a032.exe -> Downloader.

    Obfuscated.a : Cleaned with backup
    C:\WINDOWS\system32\winrvc32.dll -> Trojan.

    Agent.vg : Cleaned with backup
    C:\WINDOWS\system32\wuauboot.dll -> Adware.

    PurityScan : Cleaned with backup
    C:\WINDOWS\Temp\win21.tmp.exe -> Trojan.Dialer

    .oy : Cleaned with backup
    C:\WINDOWS\Temp\win26.tmp.exe -> Trojan.Dialer

    .oy : Cleaned with backup
    C:\WINDOWS\Temp\win27.tmp.exe -> Trojan.Dialer

    .oy : Cleaned with backup
    C:\WINDOWS\Temp\win3A.tmp.exe -> Trojan.Dialer

    .oy : Cleaned with backup
    C:\WINDOWS\Temp\win9.tmp.exe -> Trojan.Dialer.

    oy : Cleaned with backup


    ::Report End




    Here is the HjT log:

    Logfile of HijackThis v1.99.1
    Scan saved at 4:29:18 PM, on 6/13/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\HJT\HijackThis_v1.99.1.exe

    F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\Userinit.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [type32] "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
    O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl04a\BrStDvPt.exe
    O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Music Alarm Clock] C:\PROGRA~1\MUSICA~1\mac.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
    O16 - DPF: {9BED3AC7-E6D4-43E7-B8A1-1FA502F639E1} (XTools Control) - http://player.bugs.co.kr/install/XTools_2006_02_11.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{C197BAF3-6B8A-4491-93D2-680D9254795B}: NameServer = 216.104.64.5,216.104.72.5
    O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
    O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\System32\brsvc01a.exe
    O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe



    Is that it? I think the madness has stopped...
    Thanks so much for helping me... i don't know how to repay you.
     
  5. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Not yet finish,

    scan hijack and check :


    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O20 - Winlogon Notify: winrvc32 - winrvc32.dll (file missing)

    Close all windows exept hijackthis and click fix checked.

    Boot comp. Its ok now
     
  6. dcho787

    dcho787 Member

    Joined:
    Aug 27, 2005
    Messages:
    20
    Likes Received:
    0
    Trophy Points:
    11
    thank you for helping me!
     

Share This Page