Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93101 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Baseline HIjackTHis log


  • This topic is locked This topic is locked
16 replies to this topic

#1 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 15 March 2006 - 03:58 PM

Hello,
I'm new here and I hope you can help. First symptoms were the random redirecting while on the internet to other pages. Click on a link and it goes somewhere else. I've seen this before and usually was able to scan with Adaware or other spyware program and resolve the problem. Now all of my antivirus programs identify that I have howiper.exe on my pc but none of them let me delete or fix the problem. Also now, adaware is freezing mid scans. Also my Firefox bookmarks dissappeared for some reason. I've lurked here a bit but I don't want to mess up my computer. I did a HJT log and here it is. I hope you can help. Thanks in advance.

Mike

Logfile of HijackThis v1.99.1
Scan saved at 4:35:14 PM, on 3/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINNT\srvany.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLServiceHost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\Sprint Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {64F7415A-95DE-E27D-F036-A4A70B13EE8C} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RtlFindVal] corrida.exe
O4 - HKCU\..\Run: [powerdll] qwe.exe
O4 - HKCU\..\Run: [sysconf16] barint.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sprint FastConnect virtual assistant.lnk = C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ConferenceRoom Java Client - http://chat.strictly...080/java/cr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093548914968
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.konti...current/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9960BF0D-6F1B-4F5F-B3AA-3FD9FAB380CE}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F64EB74-F5F0-4551-B424-F349086AFF86}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CS1\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows - Unknown owner - C:\WINNT\srvany.exe

    Advertisements

Register to Remove


#2 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 21 March 2006 - 07:59 PM

Mike, :D

Welcome to the Tom Coyote Forum, sorry about the delay but we have been overwhelmed with logs and sometimes we cant get to you as fast as we would like to.


Your computer is being Hijacked by the lovely folks in the Ukraine by a Wareout Infection.
85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine



Lets do this.

Please download FixWareout from one of these sites:
http://downloads.sub.../Fixwareout.exe
http://swandog46.gee.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.
Once the desktop loads post the text that will open (report.txt) and a new Hijackthis log in the forum please.

Ken :D

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#3 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 22 March 2006 - 07:39 PM

Thanks for the reply Ken. I installed and ran Fixwareout. Here's the report from that.

Fixwareout ver 1.003
Last edited 2/15/2006
Post this report in the forums please

Reg Entries that were deleted
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\ndimd
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ruins\dnfbj
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\xedocne
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\gib_ogol
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\repiwoh
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\nbilbaj
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\llun
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\23plhps
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\mgcppp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\tesvaf
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Urls\32refaselif
...

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dmidn.exe"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
...

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Search by size and names...





Here's the latest HijackThis log
Logfile of HijackThis v1.99.1
Scan saved at 8:33:01 PM, on 3/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\srvany.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLServiceHost.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {64F7415A-95DE-E27D-F036-A4A70B13EE8C} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [RtlFindVal] corrida.exe
O4 - HKCU\..\Run: [powerdll] qwe.exe
O4 - HKCU\..\Run: [sysconf16] barint.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sprint FastConnect virtual assistant.lnk = C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ConferenceRoom Java Client - http://chat.strictly...080/java/cr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093548914968
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.konti...current/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9960BF0D-6F1B-4F5F-B3AA-3FD9FAB380CE}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F64EB74-F5F0-4551-B424-F349086AFF86}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CS1\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows - Unknown owner - C:\WINNT\srvany.exe


Hope you can help again. Thanks

Mike

#4 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 22 March 2006 - 08:11 PM

Hello Mike, :D

That fix cleaned up entries in the registry but was not successful cleaning out the infection, I would like you to run a different fix, this one I am sure will work.


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
http://forums.subrat...e=post&id=43811
http://swandog46.gee.../Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan Only, and check the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = google.com
R3 - URLSearchHook: (no name) - {64F7415A-95DE-E27D-F036-A4A70B13EE8C} - (no file)
O4 - HKCU\..\Run: [RtlFindVal] corrida.exe
O4 - HKCU\..\Run: [powerdll] qwe.exe
O4 - HKCU\..\Run: [sysconf16] barint.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9960BF0D-6F1B-4F5F-B3AA-3FD9FAB380CE}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{9F64EB74-F5F0-4551-B424-F349086AFF86}: NameServer = 85.255.113.147,85.255.112.76
O17 - HKLM\System\CS1\Services\Tcpip\..\{18BBEFAD-893A-47A9-ACCE-DFA905AF4EFA}: NameServer = 85.255.113.147,85.255.112.76


Click Fix Checked. Close HijackThis, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.

Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.


Hope fully this will get it,

Ken :D

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#5 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 23 March 2006 - 06:54 PM

Ken,
did you what you asked and here's the results.

fixwareout log

Fixwareout ver 1.003
Last edited march/15/2006
Post this report in the forums please

Reg Entries that were deleted
...

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
...

PLEASE NOTE THAT ALL FILES FOUND BY THIS METHOD ARE NOT BAD FILES, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.

»»»»» Search by size and names...
C:\WINDOWS\SYSTEM32\DMIDN.EXE
C:\WINDOWS\SYSTEM32\CSEWI.EXE
C:\WINDOWS\SYSTEM32\JBNCM.EXE
* csr.exe C:\WINDOWS\System32\CSEWI.EXE
* jaba_full C:\WINDOWS\System32\JBNCM.EXE

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool


HJT log after fix...

Logfile of HijackThis v1.99.1
Scan saved at 7:47:01 PM, on 3/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\srvany.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLServiceHost.exe
C:\Program Files\Sprint Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sprint FastConnect virtual assistant.lnk = C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ConferenceRoom Java Client - http://chat.strictly...080/java/cr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093548914968
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.konti...current/kdx.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows - Unknown owner - C:\WINNT\srvany.exe



Looking forward to hearing back again. THanks

Mike

#6 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 23 March 2006 - 07:59 PM

Hello Mike,

It looks like the fix worked but we still have a few things to get rid of .

C:\WINDOWS\SYSTEM32\DMIDN.EXE
C:\WINDOWS\SYSTEM32\CSEWI.EXE
C:\WINDOWS\SYSTEM32\JBNCM.EXE


Mike, highlight all three files with the ENTIRE paths in the quote box by pressing Ctrl C and paste them into FULL PATH OF FILE TO DELETE.



Download Pocket Killbox

* Open Pocket Killbox
* Copy and paste this entire path into Full Path of File to delete
* Set it to Delete on Reboot
* Tick the box that says End Explorer shell while killing file
* Click on the Red circle with the white X
* It will ask you to confirm the deletion...Say yes
* It will ask you to reboot, say yes


Lets be on the safeside and run the trial of Ewido, it will show if something is hidden that is not showing up on your log.


Download and install Ewido Anti-Malware
Ewido Anti-Malware
* When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu
* Launch Ewido, there should be an icon on your desktop for it to double-click.
o Click on update
o You should see Update Complete when done.
o Now close out the program <-- Dont run it yet


Now reboot into Safemode
To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD


Now open Ewido
o Click on scanner.
o Run a full system scan
o Let the program scan the machine.
o While the scan is in progress you will be prompted to clean files, click OK.
o Once the scan has completed, there will be a button located on the bottom of the screen named Save report.
o Click Save report.
o Save the report to your desktop.



Reboot normally


Download and Install CCleaner

* Click on Run Cleaner
* Run the Issues Scan < When it asks you to backup the Registry..Say Yes

Tutorial for CCleaner


Post back with the Ewido Report and a new HJT log.

Ken :D

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#7 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 24 March 2006 - 05:53 PM

Hey Ken,
Here's the HJT log. THe ewido report is too long and I'm hitting the max allowable characters here in the forum. I'll separate it into two posts. Hopefully that's OK. Thanks again.

Mike


---------------------------------------------------------
HJT log

Logfile of HijackThis v1.99.1
Scan saved at 6:44:27 PM, on 3/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLServiceHost.exe
C:\Program Files\Sprint Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sprint FastConnect virtual assistant.lnk = C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ConferenceRoom Java Client - http://chat.strictly...080/java/cr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093548914968
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.konti...current/kdx.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows - Unknown owner - C:\WINNT\srvany.exe

#8 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 24 March 2006 - 05:59 PM

Ken, I checked and the ewido file is huge and I'd have to chunk it up into many posts here. Can I email it to you or upload it somewhere? Or is the Hijackthis log all you need to see? Mike

#9 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 24 March 2006 - 06:16 PM

Mike , You can break it up into as many posts as you need, most likely it isall cookies. Ken

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#10 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 24 March 2006 - 06:21 PM

Mike,

The ewido report is in Notepad, look through it and you can remove all the cookie entries, I am just interested in everything else on the log.

Ken :D

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

    Advertisements

Register to Remove


#11 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 24 March 2006 - 06:29 PM

Ken, I took out all the "tracking cookie" entries. Here's what's left. --------------------------------------------------------- ewido anti-malware - Scan report --------------------------------------------------------- + Created on: 6:28:40 PM, 3/24/2006 + Report-Checksum: 43111AE0 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{00A8711A-6850-059A-543F-7899E1455BA9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{03433DF4-52B3-D7BA-CE65-5B6EADF47ABE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{035E66F7-FD55-5690-77E4-55B4D846010E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{05C150CD-544C-36B1-CA46-2353C69AE959} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{061C880C-9214-661C-A5E5-D5955C8EB912} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{07DA44E0-3BFC-A455-CD97-F7B7B8790347} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{07E65FDF-2A73-7925-24D8-A81B2D818986} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{08211965-D6A7-563C-FBDA-97E9626FA453} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{095AEAC7-0EE3-5E2C-CE96-56983CF29ED9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0A28BEB8-1EA0-A145-1D54-2B42E5843DD8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0A8D0092-6F79-27C0-3B9C-D542A7FC6907} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0ABBF74F-5521-80E9-A448-F010122AC646} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B3798A2-69E9-E91E-D230-89C13C63C169} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B480D7D-6240-7BB5-B32C-EE5F2407D9D8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B4DACA1-181A-DBF9-29CD-2BF9C12D5462} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0B660373-E1F0-C963-AE63-9622A8DECA96} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0D6DF7B4-0791-C370-E841-7B9D73209399} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0D6ECE59-7291-07DE-DCA0-00ABE0C14F46} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0DA9D9AB-FC9B-6669-8DBD-7B54039C083D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0E4CBB05-BB4B-5EB7-6197-AE4117072F99} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0F256558-7E09-5485-D9FC-EBA690873428} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{0F9785C1-F999-8194-47E8-A0F96E941AC1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{10CEAD4B-16A8-5B31-5CFD-A4413DCD0151} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{10F0CAB6-9AE9-16D3-B085-4E1F259941CA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{12FA5173-DA8B-B1C3-C3D1-08A50FF6E095} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{12FA8EE3-A02B-CF1E-DA5F-AEB55869AB79} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{13B849C1-8710-E1DB-94A7-65402EF986A8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{14904EFE-9DA6-9139-BAC4-85A8B149E69E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{15441FF2-7B4A-9558-4AB1-B594DAA19E8A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{181EDD6C-335B-6475-7B7C-B04EFA3C4F99} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{197D8794-D77F-B916-2937-349E10E13AF2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1D32FBDC-FBBF-FF3B-CE7F-5DC711A25A15} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1DFFBD4D-E8D2-D6F9-3733-F3C0A037E369} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{1EDBFE12-619A-B05D-D81A-42593402A991} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{20346D4E-082E-DCC2-8477-CA2FA5F3D1F4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2067DEDB-34F7-9CC4-7353-3E1E927B32A3} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2121F517-8EB0-C7D8-66ED-2DA4574066BE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{229A699F-EDC6-7278-F8D2-335DEE8BA464} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{24BFC623-B375-B36B-78B2-69AF83E92821} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{279FD406-3E66-6632-B92E-52FA0C47B825} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{27E4633B-37DB-09B0-10DB-1674088EC3BA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{28263ADC-061F-622A-0FBE-4277E57E29DA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2A992854-C120-2344-3A53-938F60435FED} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{2CE711D5-3677-6478-9DBE-8A8DEE743E69} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{306F87C5-2A68-9C39-CFB9-0CD040D569C1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{30E5DB07-3737-DBEB-B619-F7C396F8F6D5} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{30EF01ED-8EBD-E880-F3DF-92A81A3F3DD3} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3213B86A-4C92-0F29-D1AD-4AC65FBE45AF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{338E9F9A-BBF9-233A-33C3-E48A66C94FFA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{348150DC-F288-4403-AB8F-29365FF75DBE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{348385B4-1D00-F877-6E9F-5DC720AC5FF6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{36CEB92A-6484-F014-64AB-89A7177FF19B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3708CD34-8174-A47E-9567-68786B0AE85F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3827C3F7-DFA4-9D8D-9E66-CC737E5E91FF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3834AA13-4038-9320-1E93-D1D572E3A1CA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{38C5B834-A322-B57E-5E70-389C168DEC39} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{397ACE10-AC4F-6D02-B07D-9C18F19A967C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{39C21146-72F9-C00B-D47C-F100644447AE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3A259714-8197-822B-1F45-481A82927866} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3B092820-33F4-D1C6-2308-63513EC22B4F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3BCE675C-69C4-1D11-7D6D-7C148449CF48} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3C733A18-BA69-B034-3516-D68F69A95735} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3C73D315-DD9F-9F82-0398-D2936B2878B2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3D4E083C-1675-13A0-513B-459B912F9DA1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3DD4847F-E570-B70E-18E9-D072FE0C3AFF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3EAF3A17-CC8D-5DC9-285D-C38B83233D28} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3F18D253-A986-C896-9157-85378BE2E152} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{3FF0B32B-4F42-6F99-B6F4-C207F166CA3E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{405C427D-7AE4-A1A7-D322-793595EC6979} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{410D9F00-8C94-E956-4B57-588F19CDCBA5} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{41C07D8C-8EDF-B6D0-22A4-63477AD33BCB} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{41C681D5-C708-9E50-FBCC-937429365153} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{42B625C4-F206-ADFA-4FA4-AC97FDC73591} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{433B812D-C2D5-F83D-9B48-A30CDA52F0FB} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{44D767DC-8C97-9091-E72C-2AA3721330FE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{46015205-9C0D-68F5-0714-0BA8A0DA3C56} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{499CBA68-0CDC-4376-9119-E07B6BD9CBB4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4A8EE67B-69E8-FF78-E4FC-BDA9715152A9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4B118F46-F4FC-AB84-7871-B58A68ED1E7F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4C0D800A-53EB-A6A4-2A98-EA9927B4BBFA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4D1B1005-4C66-86D2-0123-8C1F255C711B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4D563CE3-2AA6-0070-058D-1EB255E989CD} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{4E2100AF-9CDE-6F52-674F-5BCEAF4A8D08} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{50A0058B-9B7D-653D-AB07-A0A98CADC978} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{50CEBE40-0931-C174-0942-791226F19C0F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{50CF1CA4-BAC9-318B-D8F3-18958B04D18A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{52C881AE-E0BB-A519-E212-711BD6265712} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{53D1A229-2575-8DC7-EF0E-EDD19936A81F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{547AD346-410C-3E62-4513-8C74102C30E0} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{54EC2000-824C-7ABC-DA9D-E7D8479CD36D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{55B602D6-4282-BE22-DEE6-C95DFCA166A1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{55E87116-EB4C-8F69-397B-DEC458BCE908} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{57CF02A6-E431-029F-E097-C2B2B7B83230} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5899D6C8-2875-45AF-8736-13BE0C3BA5EC} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{59AC6BEF-5B61-2B7A-2C62-D55A9708772D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5A0AC97D-0AA0-51E4-63F2-65CE7E50B635} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5B264A71-ACA3-B02C-C94B-CE36D3C130D4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5B697B5C-438E-D818-F3DD-98A5E6A976F7} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5B9E0C16-59F9-60E5-8F5C-49AC8DF80372} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5B9FD345-F3DE-D005-2ECE-CAB9FE8750CF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5C19DA3A-627A-8F16-BA65-30D8566CB9E4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5F07395A-D985-8E7F-592F-1318F18930CF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5F3F4883-B89C-77E8-8766-7DD920A2659A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{5FF9D913-AF6D-6D79-5A3A-75BA7425C8DF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{603713DB-4BD5-544A-66D3-C39C456D92CC} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6063B540-F6FC-513E-26EA-016F982EFF4A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{62B92B1B-2FF4-C0C0-407F-FD1EF3FDEB7A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{649CC735-3654-3678-18DF-8F6ECCFF3B90} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{64CE588E-CBDA-117F-C18F-09D6A368569B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6518F4B3-A15F-E14C-71F3-61A49FC2A684} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{65E38C5A-C2E5-319D-507E-7617213EEC42} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{668BB616-1BCE-82D5-2851-8A2342910F1A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{66B2F006-8D10-B63E-B2AB-28BE00E949E9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{677CE132-C5E8-235B-2CEB-FBDAA2BD1708} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{67AD8EEC-DBC9-81F8-1EAB-6D24CF242AC2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{696F735F-7662-8432-DD3E-DAA24E182345} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6B315769-33A2-0406-A039-366CA0B26BB1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6CB6FA3E-4E06-6264-2A77-866A236736C8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6CEBC165-91F6-1D4D-F490-A0F961E0C302} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D4CF4A6-172A-29B3-00AF-32FB4DF6D1E9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D4FA3A0-BE29-2407-A0C1-4CFF3DD6BA5D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D77CFED-194C-C677-1144-FFB12029F02A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D791183-0FD4-50B4-E2B5-5933BB059404} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6D845FD0-BC22-0382-EA0D-9398A77E1266} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6EE72087-0DA7-7F33-C49E-EE85CE8C8F74} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{6F854F82-41AB-C366-B3F3-7E4633BE37DB} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7088E183-99D9-0B62-5F0D-9852B624FA9A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{713BB4D3-0B7C-1D3D-8240-26C661FA80FC} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{72D633DF-F78E-4CB0-8219-60FA41D1EFE7} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{72E44A98-81DE-D1D0-869D-7ADD55F30AF8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{73374308-91E6-5E66-411F-8EDBA399652C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7339C21E-5D1D-F6EF-29FC-8E7E97E8C4F9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7362274A-09FE-F00A-89C1-FD2AC372C937} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{736A732C-C2C9-6CE6-0C3D-D550CF0B4ECE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{738D8853-5874-6844-0AF4-5E619600256A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{73A137E3-16AA-E19B-E2FC-BA6992E4EC3A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{79062573-086D-5A0F-D7B9-40FCC3638669} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7941CA3D-DE09-D3B7-ABB4-A41A008C96ED} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7A015144-5175-E3B9-7DB4-7366A22AC500} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{7B30C370-FA75-1822-2540-7558BEE71EA1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{801513CF-9E0B-0971-FC2D-5B81BD8202A7} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{81ECC258-D5E1-4FEE-C740-206797087285} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{833E964D-0405-6D34-83F1-6CF3B8219653} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{83C364AB-D985-F976-8699-75648550E500} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8569B350-A235-C3D0-C976-91F197E58D58} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{87660378-C0D8-4042-E8EE-3B0499FCC8D2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{880FB29E-7E3C-ECF4-5735-4595B6AFF507} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8A20AF55-2593-F55B-C66B-2FD5BCB53A15} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8B818F6C-9632-19DE-8680-233C397A97AD} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8D2AADC8-5DBE-E870-1462-5E5624EFD2B6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8EABB85C-4D63-D1BB-01F2-AE33BBD7CE6A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8F3F86E9-61D5-FA76-4B27-E8BB6258BB1C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{8F9D9D9C-9CCD-9854-E15E-1EE63F21E720} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9037343E-6802-1EC2-D767-E57CC2D9D83C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{906797F2-8B34-E847-8C8D-3155F09D9D9E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{90904DF3-6B8E-1818-E44F-2A9AA166D4DA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{94FA4010-B3F3-C483-2777-51238C74EE13} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{97DAA3DE-A992-3146-9C21-5C71F1A38D2F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9A5E8E21-FFA8-D3FC-F198-BA99F9AEA168} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9A678796-707F-D256-27D0-BF6E13722D82} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9AA00E8E-DF77-92FE-007F-550C36210091} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9ABD69B7-3078-E340-94CB-F16AA6983B61} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9AE8740F-6C73-7F58-A431-D7A96ECE744F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9B248F4A-0E2F-E6AC-4C93-30FA3E8832F5} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9B25BCAB-D3CF-F3E7-5310-C70A87FBFEEA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9B2B511B-5C73-FBA9-E2FD-33BC0CE5C060} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9B43427D-0FEC-732D-61D6-4CDB41DBCD4F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9B49E3CB-0644-7E8D-7874-A5140FECDE14} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9CBB4BED-3078-BC62-C651-22791481A3D1} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9D6A4232-5595-7E6F-2779-C942DCAB8455} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9E38D3F2-BCDA-AD28-DCF3-B4DA7091010E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9FA37D52-3768-0C3C-21F8-0E04D88140FB} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{9FF525C4-DA3A-A482-0793-0178BE517407} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A0B5AE4D-89E5-F22A-060E-06256A646F77} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A0D6035B-399F-77CC-3D27-652A6827CD9A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A2566F14-7DD6-3E7E-0848-F809CAF5FBA6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A30E09EF-197E-B658-38C6-C38B368232DA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A39786E1-B3F2-5AA0-9792-D30FF78E0B7B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A3E59314-F18B-E35B-1289-B3D8F43C3B9D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A491446E-5B83-7344-6DED-66F77121F386} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A767C372-E131-DC66-D1AB-430AD36BFD03} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A84E11D6-D474-456C-AE4D-E4EDE2FA3B78} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{A8D08A14-55CC-81EB-BF8B-F83DC9F8EC18} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ABCBB0F9-7C5F-B2A8-A985-DBEE7DA8035D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ABE2DA2C-85E3-CA0C-79FC-63F0410FA2E0} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ABFE0A70-E434-9846-C0AE-F9DCC2E3AF39} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AC0966F9-9343-A74E-2826-7AC2FAD8C372} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AC662854-759A-EAF6-1698-C303A1550DD6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AC662AA0-0898-E8A0-B9EF-228B42C3EB3D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AC6D47C6-68C5-3897-7287-0428547AB788} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ADF8A017-24E2-9B52-4DF3-46D32D833008} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AE65210B-2870-3EC4-9658-261BE1153BB2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AEAE8BDF-EB6D-3455-2CB9-63C74F8A0DBF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AEE98A84-9A76-BE17-DF76-A88F982D2404} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{AF5FDECD-1ED9-A1EC-D3B8-8211759346FD} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B1D3DC92-F445-F8C6-A5E2-BC0A8A2E2A41} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B1EBC237-3650-5E5C-6534-F15F6F9B3DC7} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B41F60FA-6DED-6A3D-8737-C716CB55B622} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B57D4547-53A2-CE5F-B929-72FEAA007FF8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B66EB824-64D7-FEB5-0E40-6198A99D4A9A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B796386A-3A52-4CE4-BD8A-3662ABFFA8E6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B85396EA-22B1-1A27-067A-B8F1A2D6BD90} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B86CC519-D46E-0419-6010-B64FD4791F26} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{B9117FC9-B02C-936C-F1BC-6D227B226339} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BA6A7285-A488-F292-5E38-FED53B83902B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BB6563EC-D9E3-897E-4B1F-D6D5562283D4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BBEF567C-D9B6-3F24-E746-686C933C74EE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BCA0B7D8-D1AB-9FA2-340F-BE19B55DF43E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BD3E3466-1538-E065-4AB1-0D5369E59114} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BD9D4C0F-F323-B9BF-3F31-9E15DB1A3C20} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BE2BEA96-036C-1422-910E-62600A0061B9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BEB8A8DE-743E-9BF5-DBA7-230CFF21DEDA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{BFB5D2CE-194B-C74E-63C1-C2F668F52093} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C10E70B6-0A9C-EFB9-C902-4055C2D7F322} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C2B4381A-624D-8F51-B758-89C0C91258DE} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C2CC1826-44AA-2597-F243-7FEE13F6D54D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C5B507CE-7D99-C0A1-E430-1A0E0AEE7CEA} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C68539AC-6CD1-A082-BEB2-8A3A1C72F103} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C7F1F514-C22B-1A47-60E2-4A74FEB1C8A4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C8DD1A3C-80E3-1DD2-0279-631BC954EC39} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{C9927A71-926F-63DD-BAF8-F1DFAA3A18E5} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CA9321F5-9849-30AD-6D1F-008B13CFD1D4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CAC3AE7E-DEF2-72E1-A0C8-DA72B4E1834A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CBC927A6-1167-82ED-E0C3-DBCBD9A6CF4B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CC369B91-C8F7-50DC-8770-169933934AED} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CC53C364-0498-434A-F962-F0D884823228} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CE6205AA-DD2B-C25A-D877-9FFBD331CB9B} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CEC2B27A-883F-E124-1F3F-2CBA3C952B4F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CF30C520-DB2C-D18C-D86C-3486CBAC7398} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{CFF45521-4565-338C-29CE-C8D195624A80} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D1E8711C-CA24-0648-63F6-72B649D9E734} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D6CA544F-A4AC-91F4-115C-804625BCE963} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D80E67B9-34F4-C1CD-D196-FA71FE8A43E9} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{D90C207B-4860-3A1B-DA99-A2F041C2D231} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DA141BE1-D853-5A91-AD61-7C455BB2A8BF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DA81932E-29FB-B935-6516-E875DF84849C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DB1E7E37-F479-7571-F0B4-BE2B286CBAA2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DB307D03-7868-5DF7-BFB1-F83D4E3BAA3C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DD4B1E58-8316-27DC-4B57-7B256202DDAD} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{DD8456CE-983B-407E-4FA1-3FD05A16A796} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E0C18BC0-1202-8747-343F-BA677E05684E} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E33988EA-105D-44A7-9FD0-113D658D407D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E442A80F-74FB-5A16-58DF-7A013C8A2209} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E4D02D4D-F4CA-5C75-BF5E-2EB5899148E7} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E4F78A3B-E4C9-A50B-F62B-9CD76792AA50} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E5872A98-7703-9F71-70B4-ACA15181A0DB} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E5AFDF80-07CE-2536-3668-6A46D26F50CD} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E5F499C9-52D4-E935-124C-655897AC38DF} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E616513A-40E1-2657-5238-EAF908483D9A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E61BC869-33C7-AC36-F015-C0910E22E342} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E66033D3-0B56-750C-2254-9C91038A086C} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E7E0557E-BEFF-47AA-E8A8-547E32BED9E2} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E805B64D-52F9-FE92-3C46-452087A31638} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E8995C66-89E4-D9B5-D987-CB89F2AF8546} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E8D60F02-B624-2C7E-A7EF-0C465710C12F} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{E9288E70-5BA5-6326-846F-3AC0878A4536} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EAADD167-D492-D64A-6508-6BCC2A6B4D56} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EB6F84A8-01F1-4D7E-CBCE-4B02B1BB0094} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EC3DDF47-5645-BD30-F6EE-3A2152B02861} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{ECDBD93B-30EF-D196-FC96-85492CDB4F6A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EE055B7A-58F8-B9E1-4CDD-84A44E1735F0} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{EF010CB5-057C-9C15-994C-AEA2292E8DF4} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F1B29D9E-77D4-3911-26FA-4DF52CC3DF6D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F2FAA6D4-BBEE-5987-18DD-2FCF87AEA166} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F30D81A9-0A97-7DD6-ABAA-D25624EAD4C8} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F4CB7C39-0C3C-C715-7E2F-0A007AC6D839} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F55BC142-6DAC-87A2-D58A-4ADF205AA1D3} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F6D9089D-FF9B-AADD-2E2E-CE965672C18A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F6E2FCAE-1198-A1BC-63E6-EFD2567AC69A} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F75E72A9-3C6C-F756-D77B-5683929F8E8D} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F8143114-CDD3-F1BE-E167-AB80E5C3C6A3} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{F8EA4B26-A394-AA9E-10DB-155FDEB474C6} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FA6D4AD5-F1DF-A18C-48C0-68516A397B35} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FABE0E4B-31BD-F3E9-72B8-A4A70532BF43} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FD3F2341-3770-E86A-8787-02D9055C5E87} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FDEEBCF1-BD77-3F48-90AD-29EE05803428} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FF534564-71EA-B589-BFE1-B3735E7B4CF5} -> Adware.CoolWebSearch : Cleaned with backup HKLM\SOFTWARE\Classes\CLSID\{FFD546EC-FB9C-77B7-E8C5-9C46B980AA6C} -> Adware.CoolWebSearch : Cleaned with backup C:\!KillBox\DMIDN.EXE -> Trojan.Pakes : Cleaned with backup :mozilla.22:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.23:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.24:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.25:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.26:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.27:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.28:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.29:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.30:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.31:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.32:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.33:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.34:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.35:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup :mozilla.50:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.51:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.52:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.53:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.56:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.57:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.58:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.59:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.62:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.63:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.64:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.65:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup :mozilla.78:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.6:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.7:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.8:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.9:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.10:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.11:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.32:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.33:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.34:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.35:C:\Documents and Settings\Mike & Cori\Application Data\Phoenix\Profiles\default\rapuv6l9.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup C:\Documents and Settings\Mike & Cori\Cookies\mike & cori@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike & Cori\Cookies\mike & cori@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup C:\Documents and Settings\Mike & Cori\Cookies\mike & cori@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike & Cori\Desktop\win\KeyGen\Files\Windows.exe -> Not-A-Virus.NetTool.Win32.CalcFolding@Home : Cleaned with backup C:\RECYCLER\S-1-5-21-1708537768-1958367476-1417001333-1004\Dc10.exe -> Hijacker.Small : Cleaned with backup C:\RECYCLER\S-1-5-21-1708537768-1958367476-1417001333-1004\Dc11.exe -> Trojan.Small.gq : Cleaned with backup C:\WINDOWS\$NtServicePackUninstall$\winhlp32.exe:jiywy -> Trojan.Agent.bi : Cleaned with backup C:\WINDOWS\$NtUninstallKB896358_0$\hh.exe:tjhwv -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\66665350.msi:hypbb -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\66665350.msi:kkwrh -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\bootstat.dat:zzige -> Downloader.Agent.ap : Cleaned with backup C:\WINDOWS\FeatherTexture.bmp:aatrt -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\iis6.log:tjfrr -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\Q323255.log:fhvqi -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\Q331953.log:yzndk -> Downloader.Agent.ap : Cleaned with backup C:\WINDOWS\Q816843.log:mabrw -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\River Sumida.bmp:ajiuv -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\sessmgr.setup.log:tkshx -> Downloader.Agent.ap : Cleaned with backup C:\WINDOWS\setupact.log:xqprr -> Downloader.Agent.an : Cleaned with backup C:\WINDOWS\setuperr.log:vhcrt -> Downloader.Agent.ap : Cleaned with backup C:\WINDOWS\SYMEVENT.LOG:irabn -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\system.ini:zonfd -> Downloader.Agent.an : Cleaned with backup C:\WINDOWS\tsoc.log:mzgbv -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\tsoc.log:rpxtf -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\tsoc.log:yvaec -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\twain.dll:jvygz -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\twain.dll:kqnvt -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\twunk_16.exe:ezqgx -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\twunk_16.exe:mzgtk -> Downloader.WinShow.ak : Cleaned with backup C:\WINDOWS\UNWISE.EXE:hosbx -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\UNWISE.EXE:nktfz -> Downloader.Agent.al : Cleaned with backup C:\WINDOWS\vbaddin.ini:flmkb -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\Windows Update.log:qhfrv -> Downloader.Agent.bc : Cleaned with backup C:\WINDOWS\wlvls.dat:rfhdz -> Downloader.Agent.bq : Cleaned with backup C:\WINDOWS\Zapotec.bmp:kxsib -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\{F90FA6FF-24CA-4CBC-B5B1-232EF63C4F2F}.dat:hobwv -> Downloader.Agent.bc : Cleaned with backup C:\WINDOWS\{F90FA6FF-24CA-4CBC-B5B1-232EF63C4F2F}.dat:oxhug -> Downloader.Agent.cd : Cleaned with backup C:\WINDOWS\{F90FA6FF-24CA-4CBC-B5B1-232EF63C4F2F}.dat:spegs -> Downloader.Agent.cd : Cleaned with backup C:\WINNT\Windows.exe -> Not-A-Virus.NetTool.Win32.CalcFolding@Home : Cleaned with backup ::Report End

#12 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 24 March 2006 - 08:16 PM

Mike,

Ewido cleaned out a bunch of garbage, but lets make sure its all gone.


I would like you to download the stand alone version of CWShredder
to your desktop. Run the tool and let it remove all it finds.



I also would like you to run Ewido again in Safemode to make sure that everything it cleaned is gone. The report should not be as large as it was last time.



Mike, forgot to mention that you are running two anti virus programs, with AV MORE IS NOT BETTER they will at times conflict with one another, give you false reports not to mention the huge amount of system resouces that they will use up. Your call but you need to remove one of them.


So post the new Ewido report and a new HJT log and at that point if all looks good, I have some tips and free tools for you to install to help keep your system more secure.


Ken :D

Edited by ken545, 24 March 2006 - 08:22 PM.


 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#13 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 24 March 2006 - 10:22 PM

OK here's the latest ewido and HJT log

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 11:05:49 PM, 3/24/2006
+ Report-Checksum: 82236BFB

+ Scan result:

:mozilla.13:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Mike & Cori\Application Data\Mozilla\Firefox\Profiles\99i26wpt.mike\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00083976.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00083976.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00083978.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00083978.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00083978.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00083978.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00083981.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00083981.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00083981.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00083981.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00083982.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00083982.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00083982.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00083982.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00083982.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00083991.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00083991.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00083991.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00083991.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00083991.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00083993.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00083994.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.7:C:\RECYCLER\NPROTECT\00084432.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084432.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.8:C:\RECYCLER\NPROTECT\00084444.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084444.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084445.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084445.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084448.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084448.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084449.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084449.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084450.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084450.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084461.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084461.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084462.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084462.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084470.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084470.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084517.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00084517.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084521.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084521.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084524.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084524.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084587.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084587.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084596.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084596.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084618.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084618.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084618.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00084618.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084619.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084619.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084619.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00084619.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084621.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084621.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084621.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00084621.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084622.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084622.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084622.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00084622.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00084622.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084624.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084624.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084624.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00084624.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00084624.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084626.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084626.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084626.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00084626.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00084626.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.9:C:\RECYCLER\NPROTECT\00084627.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084627.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084627.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.16:C:\RECYCLER\NPROTECT\00084627.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.18:C:\RECYCLER\NPROTECT\00084627.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.6:C:\RECYCLER\NPROTECT\00084658.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.10:C:\RECYCLER\NPROTECT\00084658.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084658.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00084658.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.11:C:\RECYCLER\NPROTECT\00084659.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.12:C:\RECYCLER\NPROTECT\00084659.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.17:C:\RECYCLER\NPROTECT\00084659.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00084659.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00084660.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084660.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00084660.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00084660.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\NPROTECT\00084662.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.15:C:\RECYCLER\NPROTECT\00084662.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\RECYCLER\NPROTECT\00084662.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\RECYCLER\NPROTECT\00084662.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.13:C:\RECYCLER\NPROTECT\00085114.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\RECYCLER\NPROTECT\00085114.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup


::Report End

-Logfile of HijackThis v1.99.1
Scan saved at 11:12:12 PM, on 3/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\system32\slserv.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
C:\Program Files\Common Files\AOL\1141176820\ee\AOLServiceHost.exe
C:\Program Files\Sprint Virtual Assistant\bin\mpbtn.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\HijackThis 1.99.1\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Program Files\Intel\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SPRINT~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1141176820\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Sprint FastConnect virtual assistant.lnk = C:\Program Files\Sprint Virtual Assistant\bin\matcli.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: ConferenceRoom Java Client - http://chat.strictly...080/java/cr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093548914968
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://content.konti...current/kdx.cab
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Windows - Unknown owner - C:\WINNT\srvany.exe

#14 ken545

ken545

    Forum God

  • Retired Classroom Teacher
  • 23,225 posts
  • Interests:Fighting Malware and cooking some great Italian and TexMex food
  • MVP

Posted 25 March 2006 - 07:20 AM

Mike,

Your system looks good :thumbup: , the reason I had you run CWShredder is that your Ewido log showed that your system was infected with it at one time , the files were gone and Ewido cleaned out all the entries in the windows registry. Everything Ewido found now is in either the recycle bin or in Ewidos Quarantine. Go ahead and empty them both out.


Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

* Download and Install CCleaner, Click on RUN TOOL, when you run the Issues Scan and it asks
you to back up the registry Say Yes.

Now that your clean, we need to erase all possible older infected files that may still be lurking on your system.
* Clean out your TEMP FILES
* This procedure should be run from SAFEMODE for better results.

To Enter SAFEMODE

* Go to START/ SHUT OF YOUR COMPUTER/ RESTART
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly, this will bring up a menu.
* Use the UP AND DOWN ARROW KEYS to scroll up to SAFEMODE
* Then press the ENTER KEY ON YOUR KEYBOARD

* Go to My Computer/ C: Drive/ Documents and Settings/ Every User on this Computer Local Settings
and delete all the contents of the Temp Folder and the Temporary Internet Files Folder Just the contents, not the folder itself.

* Go to My Computer/ C:/ Windows/ Temp and delete all the contents of the Temp Folder <-- But not the temp folder itself.

* Go to My Computer/ C:/ Windows/ Prefetch and remove all the contents of the Prefetch Folder.
But not the Prefetch folder itself.

NOW RE-BOOT NORMALLY


* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.

Now Empty your Recycle Bin

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your
system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

* Right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

Reboot your System

Turn ON System Restore.

* Right-click My Computer.
* ClickProperties.
* Click the System Restore tab.
* UN-Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

* Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like, something that you can remember

* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

* Here are Free Anti-Virus Programs if you need one

AVG Free Edition
AntVir Personal Edition


* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.

* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.

* Spyware Blaster It will prevent most spyware from ever being installed.

* Spyware Guard It offers realtime protection from spyware installation attempts.

* Win Patrol This program will warn you when any changes are being made to your system and
give you the option to deny the change.

* IE- Spyad IE-Spyad places over 4000 web sites and domains
in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed,
although you will still be able to connect to the sites.

* Firefox Browser
It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use
them both. When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you use this
for awhile, you will want to make it your default.

* Thunderbird Mail There companion mail program was highly favored in PCWorld Magazine,
this has a good spam filter and is more secure than Outlook Express.

* Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't
access the internet without it.

* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER/Click on PROPERTIES/ AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.

* Go to START/ CONTROL PANEL> PERFORMANCE AND MAINTENANCE> REARRANGE ITEMS ON YOUR HARD DISK TO MAKE PROGRAMS RUN FASTER
This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.


Thanks for using Tom Coyote,

Ken

 
 
The forum is staffed by volunteers who donate their time and expertise.
If you feel you have been helped, please consider a donation.
donate.gif
 
Find us on Facebook
Please LIKE and SHARE
 
 
Just a reminder that threads will be closed if no reply in 3 days.

#15 bikeman

bikeman

    Authentic Member

  • Authentic Member
  • PipPip
  • 23 posts

Posted 25 March 2006 - 09:47 AM

Ken, Thank you so much for your help. I owe you some frosty beverages! I'm gonna go ahead and follow your suggestions for a cleaner computer. I do use Firefox 100% of the time. I love it compared to IE. Thanks again. Donation sent to tom coyote. Mike

Related Topics



2 user(s) are reading this topic

0 members, 2 guests, 0 anonymous users