This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] popups from adserving.cpinteractive

14 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

——————————————————————————– KASPERSKY ONLINE SCANNER 7 REPORT Friday, April 3, 2009 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Friday, April 03, 2009 21:01:30 Records in database: 2006772 ——————————————————————————– Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ Scan statistics: Files scanned: 86037 Threat name: 2 Infected objects: 3 Suspicious objects: 0 Duration of the scan: 01:45:25 File name / Threat name / Threats count C:\Documents and Settings\Owner.Mickdawg\Local Settings\Temporary Internet Files\Content.IE5\A0YBDR5O\brikas[1].gif Infected: Trojan-Downloader.Win32.FraudLoad.vnla 1 C:\WINDOWS\syssvc.exe Infected: Trojan-Downloader.Win32.FraudLoad.vnla 1 D:\i386\Apps\App00577\comps\toolbar\toolbr.exe Infected: not-a-virus:AdWare.Win32.SearchIt.t 1 The selected area was scanned.
Please download the OTMoveIt3 by OldTimer.
  • Save it to your desktop.
  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

    :processes
    explorer.exe
    
    :files
    C:\Documents and Settings\Owner.Mickdawg\Local Settings\Temporary Internet Files\Content.IE5\A0YBDR5O\brikas[1].gif 
    C:\WINDOWS\syssvc.exe 
    D:\i386\Apps\App00577\comps\toolbar\toolbr.exe
    
    :commands
    [purity]
    [emptytemp]
    [start explorer]
    [reboot]
  • Return to OTMoveIt3, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTMoveIt3
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Also run HJT and post the log. Let me know how it's running now too please.
no popups since last night, cool


========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Temporary Internet Files\Content.IE5\A0YBDR5O\brikas[1].gif moved successfully.
C:\WINDOWS\syssvc.exe moved successfully.
D:\i386\Apps\App00577\comps\toolbar\toolbr.exe moved successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Arj.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\avlib.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Avp1.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\AvpMgr.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\btimages.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\CAB.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\dmap.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\dtreg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FsDrvPlg.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HashCont.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HashMD5.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HCCMP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\ichk2.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\iChkSA.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Inflate.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\IWGen.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\lha.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\L_llio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\mdb.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MDMAP.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MemModSc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MemScan.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\minizip.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MKavIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\msoe.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\nfio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\NTFSstrm.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prKernel.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prseqio.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\PrUtil.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Quantum.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\rar.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\ScanningProcess.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\sfdb.PPL scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\TempFile.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\thpimpl.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UniArc.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UnLZX.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UnStored.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\WDiskIO.ppl scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\hsperfdata_Owner\3368 scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_878.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_ca0.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_cac.dat scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\PR66.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\History\History.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temp\Cookies\index.dat scheduled to be deleted on reboot.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
File delete failed. C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\mcafee_Nc9HbSiedmtgHBZ scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\mcmsc_erhaOSwCjn6IpV2 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_7b8.dat scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\WFV2.tmp scheduled to be deleted on reboot.
Windows Temp folder emptied.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Application Data\Sun\Java\Deployment\cache\6.0\21\66415395-24917f30 scheduled to be deleted on reboot.
Java cache emptied.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.10.0 log created on 04032009_192224

Files moved on Reboot…
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Arj.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\avlib.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Avp1.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\AvpMgr.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\btimages.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\CAB.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\dmap.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\dtreg.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FsDrvPlg.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\FSSync.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HashCont.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HashMD5.PPL moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\HCCMP.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\ichk2.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\iChkSA.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Inflate.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\IWGen.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kave.dll moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\kosglue-7.0.25.0.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\lha.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\L_llio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\mdb.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MDMAP.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MemModSc.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MemScan.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\minizip.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\MKavIO.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\msoe.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\nfio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\NTFSstrm.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prKernel.ppl moved successfully.
DllUnregisterServer procedure not found in C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll NOT unregistered.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prLoader.dll moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\prseqio.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\PrUtil.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\Quantum.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\rar.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\ScanningProcess.exe moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\sfdb.PPL moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\TempFile.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\thpimpl.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UniArc.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UnLZX.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\UnStored.ppl moved successfully.
C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\jkos-Owner\binaries\WDiskIO.ppl moved successfully.
File C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\hsperfdata_Owner\3368 not found!
File C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_878.dat not found!
File C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_ca0.dat not found!
File C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\Perflib_Perfdata_cac.dat not found!
File move failed. C:\DOCUME~1\OWNER~1.MIC\LOCALS~1\Temp\PR66.tmp scheduled to be moved on reboot.
File C:\WINDOWS\temp\mcafee_Nc9HbSiedmtgHBZ not found!
File C:\WINDOWS\temp\mcmsc_erhaOSwCjn6IpV2 not found!
File move failed. C:\WINDOWS\temp\Perflib_Perfdata_7b8.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\WFV2.tmp not found!
C:\Documents and Settings\Owner.Mickdawg\Application Data\Sun\Java\Deployment\cache\6.0\21\66415395-24917f30 moved successfully.
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Owner.Mickdawg\Local Settings\Application Data\Mozilla\Firefox\Profiles\d44hkspq.default\XUL.mfl moved successfully.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:31:24 PM, on 4/3/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\WINDOWS\Explorer.EXE
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\BigFix\bigfix.exe
C:\Program Files\REALTEK RTL8187 Wireless LAN Driver and Utility\RtWLan.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Mozilla Firefox\firefox.exe
c:\PROGRA~1\mcafee\msc\mcuimgr.exe
C:\hjt\HiJackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\windows\system32\BAE.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Reminder] %WINDIR%\Creator\Remind_XP.exe
O4 - HKLM\..\Run: [Recguard] %WINDIR%\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [Blubster] C:\Program Files\Blubster\Blubster.exe SILENT
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Power2GoExpress] NA
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\bigfix.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: REALTEK RTL8187 Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner.Mickdawg\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\Owner.Mickdawg\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\PROGRA~1\mcafee\SPAMKI~1\mcapfbho.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\WildTangent\Apps\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

–
End of file - 9368 bytes
Looks good from here. Some cleanup and final words of wisdom.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTCleanIt to your desktop and run it
  • A list of tool components used in the Cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTCleanUp to reach the Internet, please allow the application to do so.
  • Click Yes to beging the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. If you are asked to reboot the machine choose Yes.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.


  • [external image: Posted Image]
The above procedure will:
  • Delete the following:
    • ComboFix and its associated files and folders.
    • VundoFix backups, if present
    • The C:\Deckard folder, if present
    • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


You have pretty good protection in place. I think you just need to watch what you download.

In addition to updating and using what you currently have you may want to consider the following:

Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Install Winpatrol -
Use Winpatrol to take control of your PC and provide another layer of security.
Help file and tutorial can be found Here

Block unwanted parasites with a custom hosts file -
http://www.mvps.org/winhelp2002/hosts.htm

Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly or set your computer to receive automatic updates. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Update all of your Anti-Malware programs regularly - Make sure you update all the programs I have listed and the ones you are currently running regularly. Without regular updates you Will Not be protected when new malicious programs are released.

Keep your applications up to date -
Use Secunia Personal Software Inspector to help stay on top of application updates that could leave your PC vulnerable to attack.

I'll leave the thread open a few days in case you have questions or issues.

Regards,
Dave
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI