Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93099 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


System hijacked


  • This topic is locked This topic is locked
11 replies to this topic

#1 Guest_Simon H_*

Guest_Simon H_*
  • Guests

Posted 29 November 2005 - 11:06 PM

Hi,
Before I go into my problems, can you tell me where can I learn more about the basics of checking what's good or bad in the log so that I know what I am dealing with?

Now my problems, when I open IE, i am hijacked to this "Open Search Web". If I use Fix Fox, I get a random home page that does not exist. What even I try to do in the settings, it always does the same thing after a reboot. Below is the HT log.

Logfile of HijackThis v1.99.1
Scan saved at 11:44:07 PM, on 11/29/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\Program Files\Messenger Plus! 3\MsgPlus.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
D:\Software\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.dgdpamkic...McBd6D/Vgh.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ugieujmwx...3r0FMdZCtT0.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1341D3F5-32B0-842A-CC6F-1CFF35279FFC} - C:\DOCUME~1\Simon\APPLIC~1\UPLOAD~1\ford move.exe
O2 - BHO: (no name) - {48822653-AF6E-8072-9A56-0719F1F20730} - C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe
O2 - BHO: (no name) - {69AA6F50-B566-78BA-8326-11557CF07F6E} - C:\WINDOWS\System32\fpifpxz.dll (file missing)
O2 - BHO: (no name) - {82F2908E-514C-579B-195D-5CF07CCE6C97} - C:\WINDOWS\system32\yolkwpcp.dll (file missing)
O2 - BHO: (no name) - {9D6ABD4B-7A8F-270E-DC9E-0082CB6C2EB0} - C:\WINDOWS\system32\ioixcl.dll (file missing)
O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext1.dll
O2 - BHO: (no name) - {EB457222-BBB2-B266-B9E9-924BB76B08E5} - C:\WINDOWS\system32\psy.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tyyinilmitgz] C:\WINDOWS\System32\ikvzjaf.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [bike option 1 16] C:\Documents and Settings\All Users\Application Data\mathroadbikeoption\metaenc.exe
O4 - HKLM\..\Run: [virtual] winit.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ScRunCdRomSetupExe] E:\USBDRV\..\setup.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Aim Chin Keep Part] C:\Documents and Settings\All Users\Application Data\Creative bore aim chin\typeregs.exe
O4 - HKLM\..\RunServices: [virtual] winit.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\Messenger Plus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Audio More] C:\DOCUME~1\Simon\APPLIC~1\BOLDON~1\Title Support Spam.exe
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NaturalColorLoad.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab30149.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093451320728
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126235070500
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.c...aploader_v6.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: hobbatool - hobbatool.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe


Thanks.

    Advertisements

Register to Remove


#2 Guest_Simon H_*

Guest_Simon H_*
  • Guests

Posted 15 December 2005 - 01:23 PM

I posted this request two weeks ago and waiting for a reply. Thanks.
http://forums.tomcoy...showtopic=52453

#3 tashi

tashi

    Forum God

  • Root Admin
  • 11,581 posts

Posted 24 December 2005 - 06:34 AM

Hello and sorry for the delay.

Please post in this topic following the instructions for doing so.

http://forums.tomcoy...showtopic=31622

Microsoft MVP 2006-2016. Windows Insider MVP 2016-2018. Microsoft MVP Reconnect 2018-


#4 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 25 December 2005 - 01:58 PM

Hello Cadet Simon H, Let me welcome you to TomCoyote forum and Classroom. I have to say you are at the door of where you can learn about this process here: http://forums.tomcoy...showtopic=32034 I could give you a link like this: http://www.spywarein...ogtutorial.html
but nothing will replace the process of following the training proceedures available here in Classroom. If I can answer any questions I will be glad to do so, or if you have questions after reviewing the information at that link, contact one of our great teachers for help.

Now that this is out of the way I get to tell you that you have a very infected computer and that clean up will not be easy or fast. If you wish to start the process, the first thing that must go is the LOP tool bar that was downloaded as a sponsor program along with C:\Program Files\Messenger Plus! 3\MsgPlus.exe
The first step will be to use this information: http://chooseknowled...senger-Plus.htm follow the instructions to get rid of LOP. Here is what CastleCops has to say about it. http://castlecops.co...plist-2034.html

To pave the way for the next step and to be sure you did not install this program on purpose, you also have: http://www.symantec....ockchecker.html Let me know you had nothing to do with the installation.

Once the LOP toolbar has been removed, post a new HJT log in this same thread with the information about block checker, and I will post the next step of the cleanup processs as soon as possible after that.

Thanks...pskelley
TomCoyote forum
Expert Member
MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

#5 Guest_Simon H_*

Guest_Simon H_*
  • Guests

Posted 26 December 2005 - 10:47 PM

Hi pskelley,
I have followed the steps and removed Msg Plus and here's the new log.

Logfile of HijackThis v1.99.1
Scan saved at 11:43:42 PM, on 12/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\caaviftest.exe
C:\Program Files\Internet Explorer\iexplore.exe
D:\Software\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.apleairsr...McBd6D/Vgh.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mofunzone...linearena.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {48822653-AF6E-8072-9A56-0719F1F20730} - C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe
O2 - BHO: (no name) - {69AA6F50-B566-78BA-8326-11557CF07F6E} - C:\WINDOWS\System32\fpifpxz.dll (file missing)
O2 - BHO: (no name) - {82F2908E-514C-579B-195D-5CF07CCE6C97} - C:\WINDOWS\system32\yolkwpcp.dll (file missing)
O2 - BHO: (no name) - {9D6ABD4B-7A8F-270E-DC9E-0082CB6C2EB0} - C:\WINDOWS\system32\ioixcl.dll (file missing)
O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll
O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext1.dll
O2 - BHO: (no name) - {EB457222-BBB2-B266-B9E9-924BB76B08E5} - C:\WINDOWS\system32\psy.dll (file missing)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [tyyinilmitgz] C:\WINDOWS\System32\ikvzjaf.exe
O4 - HKLM\..\Run: [bike option 1 16] C:\Documents and Settings\All Users\Application Data\mathroadbikeoption\metaenc.exe
O4 - HKLM\..\Run: [virtual] winit.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ScRunCdRomSetupExe] E:\USBDRV\..\setup.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [virtual] winit.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NaturalColorLoad.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab30149.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093451320728
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126235070500
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.c...aploader_v6.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: hobbatool - hobbatool.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe

Let me know the next step, thx in advance.

Simon

#6 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 27 December 2005 - 08:16 AM

OK Simon, You should no longer have the LOP toolbar, we will see how it goes when we remove them from the HJT log. I need to ask that you read all instructions carefully and respond to all requests for information.

Let me know you had nothing to do with the installation.

I will proceed assuming you had nothing to do with the Adware.BlockChecker installation.

You may want to read about this worm to find out how it got onboard and what damage you may have to repair on your system:
http://www.symantec....mugly.a@mm.html

Before we start, you are running HJT from here: D:\Software\HiJackThis\HijackThis.exe If D:\ is not a drive please move HJT to your C:\ where it can safely store logs and backups.

1) Thanks to Atribune and anyone who helped with this removal tool. Please follow these directions, but save the HJT log for the end of these instructions.

Please download Blockrem © Atribune from HERE
  • Unzip it to its own folder on your desktop.
  • Boot your computer to safe mode by rebooting and tapping the F8 button repeatedly until it brings up a boot menu.
    From that menu, select Safe Mode by using the arrow keys to highlight it then pressing enter.
  • Once in safe mode open the Blockrem folder on your desktop and double-click blockrem.bat (this is the file with the gear icon) to run it.
  • Once it is running please follow the onscreen instructions.
  • Reboot in normal mode and post a new HijackThis log.
2) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp and please do not run it until I ask you to.

3) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

4) Ewido scan:
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.apleairsr...McBd6D/Vgh.html
O2 - BHO: (no name) - {48822653-AF6E-8072-9A56-0719F1F20730} - C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe
O2 - BHO: (no name) - {69AA6F50-B566-78BA-8326-11557CF07F6E} - C:\WINDOWS\System32\fpifpxz.dll (file missing)
O2 - BHO: (no name) - {82F2908E-514C-579B-195D-5CF07CCE6C97} - C:\WINDOWS\system32\yolkwpcp.dll (file missing)
O2 - BHO: (no name) - {9D6ABD4B-7A8F-270E-DC9E-0082CB6C2EB0} - C:\WINDOWS\system32\ioixcl.dll (file missing)
O2 - BHO: CDLPObj Object - {BE2ED590-CA49-46B5-8CCE-244FB2E0D1AA} - C:\WINDOWS\DLP.dll
O2 - BHO: System Process - {C2EEB4FA-B6D6-41b9-9CFA-ABA87F862BCB} - C:\WINDOWS\system32\navshext1.dll
O2 - BHO: (no name) - {EB457222-BBB2-B266-B9E9-924BB76B08E5} - C:\WINDOWS\system32\psy.dll (file missing)
O4 - HKLM\..\Run: [tyyinilmitgz] C:\WINDOWS\System32\ikvzjaf.exe
O4 - HKLM\..\Run: [bike option 1 16] C:\Documents and Settings\All Users\Application Data\mathroadbikeoption\metaenc.exe
O4 - HKLM\..\Run: [virtual] winit.exe
O4 - HKLM\..\Run: [BlockChecker] C:\Program Files\Block Checker\block-checker.exe
O4 - HKLM\..\RunServices: [virtual] winit.exe
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://antu.popcap.c...aploader_v6.cab
O20 - Winlogon Notify: hobbatool - hobbatool.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

6) Enable hidden files&folders..reverse the process when finished.
http://www.xtra.co.n...1916458,00.html

RIGHT Click on Start then click on Explore. Locate and delete these items:

winit.exe >>> file (probably running from Temp or Prefetch. Use search companion to find out. This is Mugly and it must be located and deleted!!

C:\WINDOWS\System32\ikvzjaf.exe >>> file

C:\Documents and Settings\All Users\Application Data\mathroadbikeoption\ >>> folder (if there)

C:\Program Files\Block Checker\ >>> folder

C:\Windows\Prefetch\ >>> delete everything in this folder (NOT THE FOLDER)
Prefetch info: http://www.windowsne...refetch-XP.html

7) Run CCleaner, Windows & Applications when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log and the Ewido scan results in this same thread along with any feedback you have. Let me know how you are running now.

Thanks...pskelley
TomCoyote forum
Expert Member
MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

#7 Guest_Simon H_*

Guest_Simon H_*
  • Guests

Posted 01 January 2006 - 01:44 AM

Thanks for the instructions. I should let you know that I have a dilemma here. As soon as I uninstalled Msg Plus, my daughter puts it back the next day cause she needs that to talk to her friends. What I did was to uninstall the sponsor program only.

The following are the actions taken and answers to your questions.

I have nothing to do t\with Adware.BlockChecker and I did a quick read about the damage.

The HJT is moved from D drive to C drive. D drive is a partitioned drive.

I followed your instructions to download Blockrem, unzip to desktop, boot into safe mode, ran Blockrem and got the following message.
• The system cannot find the file specified.
• Could not Find C:\windows\system32\ccapp.exe
• Could not Find C:\windows\system32\navshext.dll
• Could not Find C:\windows\system32\navshext1.dll
• Could not Find C:\windows\system32\ustart.exe
• Could not Find C:\windows\system32\~ustart.exe

CCleaner is downloaded (waiting for your instruction to run).

Spybot was downloaded and run before Ad-aware. Re-boot and run Ad-aware. Then run ewido (Took several times cause it freezes at certain locations when removing files, I manually removed some of the files to get to the end).

Finished everything up to 5. Didn’t find “winit.exe” or “ikvzjaf.exe” or “Block Checker” even with hidden files turned on. Mathroadbikeoption was found and deleted. Everything in the prefetch was deleted (130 objects).

Here’s the latest HJT log

Logfile of HijackThis v1.99.1
Scan saved at 2:35:34 AM, on 1/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mofunzone...linearena.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1341D3F5-32B0-842A-CC6F-1CFF35279FFC} - C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_6_2_0.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ScRunCdRomSetupExe] E:\USBDRV\..\setup.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [Aim Chin Keep Part] C:\Documents and Settings\All Users\Application Data\Creative bore aim chin\DumbCreative.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NaturalColorLoad.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab30149.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093451320728
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126235070500
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe


…..and here’s the Ewido report.

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 2:09:39 AM, 1/1/2006
+ Report-Checksum: DFDC2001

+ Scan result:

C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231532.zip/WINDOWS/NDNuninstall6_90.exe -> Adware.NewDotNet : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/Programs/whinstaller.exe -> Adware.WebHancer : Ignored
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/programs/webhdll.to_be_deleted_x -> Adware.WebHancer : Ignored
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc127.txt -> Spyware.Cookie.Adocean : Ignored
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc130.txt -> Spyware.Cookie.Goldenpalace : Ignored
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc187.txt -> Spyware.Cookie.2o7 : Ignored
HKLM\SOFTWARE\Altnet -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Classes\ANSMTP.MassSender -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.MassSender\CLSID -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.MassSender\CurVer -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.MassSender.1 -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.OBJ -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.OBJ\CLSID -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.OBJ\CurVer -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Classes\ANSMTP.OBJ.1 -> Spyware.007Spy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKU\S-1-5-21-507921405-261903793-725345543-1006\Software\PWRSMND1 -> Spyware.KeenValue : Cleaned with backup
[552] C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe -> Downloader.Swizzor.bo : Cleaned with backup
[884] VM_00150000 -> Downloader.Swizzor.bz : Error during cleaning
:mozilla.6:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.7:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.8:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.9:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.10:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Atdmt : Error during cleaning
:mozilla.21:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.22:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.23:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.24:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.25:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Valueclick : Error during cleaning
:mozilla.26:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Mediaplex : Error during cleaning
:mozilla.27:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.28:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.29:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.32:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.33:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Doubleclick : Error during cleaning
:mozilla.38:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Targetnet : Error during cleaning
:mozilla.39:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Bluestreak : Error during cleaning
:mozilla.43:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Addynamix : Error during cleaning
:mozilla.48:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.51:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Error during cleaning
:mozilla.52:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Error during cleaning
:mozilla.53:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Error during cleaning
:mozilla.55:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.56:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.57:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.81:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Falkag : Error during cleaning
:mozilla.82:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.83:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Hitbox : Error during cleaning
:mozilla.98:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Questionmarket : Error during cleaning
:mozilla.99:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Revenue : Error during cleaning
:mozilla.100:C:\Documents and Settings\jensen\Application Data\Mozilla\Firefox\Profiles\nvej097d.default\cookies.txt -> Spyware.Cookie.Revenue : Error during cleaning
C:\Documents and Settings\jensen\Cookies\jensen@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Mediaplex : Error during cleaning
:mozilla.12:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Atdmt : Error during cleaning
:mozilla.14:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.15:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.2o7 : Error during cleaning
:mozilla.16:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Bluemountain : Error during cleaning
:mozilla.20:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Doubleclick : Error during cleaning
:mozilla.21:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.22:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.23:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.26:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Casalemedia : Error during cleaning
:mozilla.31:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.32:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.33:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.34:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.35:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Trafficmp : Error during cleaning
:mozilla.40:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Bluestreak : Error during cleaning
:mozilla.41:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Error during cleaning
:mozilla.48:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.49:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.50:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.51:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Pointroll : Error during cleaning
:mozilla.52:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Error during cleaning
:mozilla.53:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Questionmarket : Error during cleaning
:mozilla.54:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.247realmedia : Error during cleaning
:mozilla.56:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Centrport : Error during cleaning
:mozilla.59:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Serving-sys : Error during cleaning
:mozilla.60:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Serving-sys : Error during cleaning
:mozilla.61:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Serving-sys : Error during cleaning
:mozilla.62:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Serving-sys : Error during cleaning
:mozilla.68:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.69:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.70:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.71:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Advertising : Error during cleaning
:mozilla.80:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Overture : Error during cleaning
:mozilla.83:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Estat : Error during cleaning
:mozilla.87:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Fastclick : Error during cleaning
:mozilla.88:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Valueclick : Error during cleaning
:mozilla.89:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.90:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Adserver : Error during cleaning
:mozilla.117:C:\Documents and Settings\jinny\Application Data\Mozilla\Firefox\Profiles\0wg307zk.default\cookies.txt -> Spyware.Cookie.Revenue : Error during cleaning
:mozilla.6:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.123:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Simon\Application Data\Mozilla\Firefox\Profiles\9z19gvyj.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Simon\Cookies\simon@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Simon\Cookies\simon@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Simon\Cookies\simon@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Simon\Cookies\simon@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Simon\Local Settings\Temp\temp.fr5222\TBPS.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Simon\Local Settings\Temp\temp.fr5222\toolbar.dll -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Simon\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Susanne\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@ad.adocean[2].txt -> Spyware.Cookie.Adocean : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@ad.yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@adopt.euroclick[1].txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@chumtv.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@cnn.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@com[2].txt -> Spyware.Cookie.Com : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@data2.perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@gde.adocean[2].txt -> Spyware.Cookie.Adocean : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@goldenpalace[1].txt -> Spyware.Cookie.Goldenpalace : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@partygaming.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@wrigley.122.2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@www.burstbeacon[1].txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Susanne\Cookies\susanne@yieldmanager[1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Application Data\Mozilla\Firefox\Profiles\kcepwvo1.default\Cache\8674A487d01 -> Not-A-Virus.Downloader.Win32.WinFixer.b : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\ICD1.tmp\QDow_AS2.dll -> Downloader.QDown.l : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\ICD2.tmp\QDow_AS2.dll -> Downloader.QDown.l : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\remove.exe -> Downloader.Keenval.f : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\SHNT288.exe -> Spyware.NewDotNet : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\Temporary Directory 1 for Runescape%20Auto%20Cacher[1].zip\Runescape Auto cacher.exe -> Logger.SCKeyLog.u : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\wh.exe/whAgent.exe -> Spyware.WebHancer : Cleaned with backup
C:\Documents and Settings\Susanne\Local Settings\Temp\__unin__.exe -> Spyware.Altnet : Cleaned with backup
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231532.zip/Program Files/newdotnet/newdotnet6_90.dll -> Spyware.NewDotNet : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231532.zip/Program Files/newdotnet/newdotnet6_90.to_be_deleted -> Spyware.NewDotNet : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/programs/whagent.exe -> Spyware.WebHancer : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/programs/whiehlpr.dll -> Adware.WebHancer : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/Programs/webhdll.dll -> Adware.WebHancer : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\20051008231536.zip/Program Files/webhancer/programs/whiehlpr.to_be_deleted -> Adware.WebHancer : Error during cleaning
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9.tmp -> Logger.SCKeyLog.u : Cleaned with backup
:mozilla.6:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.7:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.8:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.9:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.10:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.21:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.23:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.24:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.25:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.26:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.27:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.33:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.38:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.39:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.43:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.48:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.51:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.52:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.53:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.55:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.56:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.57:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.81:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.82:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.83:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.98:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.99:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.100:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc21.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc23.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc239.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc244.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc274.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.9:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.12:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.14:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Bluemountain : Cleaned with backup
:mozilla.20:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.21:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.22:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.23:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.26:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.31:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.32:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.33:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.34:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.35:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.40:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.41:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.49:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.50:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.51:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.52:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.53:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.54:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.56:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.59:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.60:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.61:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.62:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.68:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.83:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Estat : Cleaned with backup
:mozilla.87:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.88:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.89:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.90:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.117:C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc31.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc42.txt -> Spyware.Cookie.Adocean : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc43.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc47.txt -> Spyware.Cookie.Euroclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc49.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc79.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc89.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc91.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc95.txt -> Spyware.Cookie.Com : Cleaned with backup
C:\RECYCLER\S-1-5-21-507921405-261903793-725345543-1006\Dc99.txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.PornWare.PopCap.b : Cleaned with backup


::Report End


Computer is faster now but I am still get ad bar at the bottom of screen and pop up when I open IE. Firefox seems clean now.

This clean up took over 2.5 hours. Hopefully I can flush the problems with your help. Many thx.

Simon

#8 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 01 January 2006 - 07:45 AM

Hello Simon, one of the biggest problems with doing a remote repair like this is getting the member to follow the directions. This is of paramount importance and in order to follow the directions, one first needs to read them. This is why I bold some items and highlite others in red. But I can't do that with everything. You said this:

CCleaner is downloaded (waiting for your instruction to run).

Please return to the instructions I posted and in instruction #7, read the first two words, thanks.

I also wish to go back a little further and remind you I said this:

Now that this is out of the way I get to tell you that you have a very infected computer and that clean up will not be easy or fast.

We have a ways to go from a glance I had at the ewido scan report. Take care of the instructions you missed and I will post the next instructions as soon as the fog burns off here in Florida. :rofl:

Phil
MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

#9 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 01 January 2006 - 09:36 AM

Thanks for the instructions. I should let you know that I have a dilemma here

I would say your daughter is your problem but I do know messenger plus is not required and is only an add on that is used with MSN Instant Messenger that works without it. It also has nothing to do with MSNIM or Microsoft. I for one would never use it because of the fact it installs C2Media/LOP by default. I believe your daughter is pulling your chain?

I also need to say that the block checker software had to be agreed to by someone with access to this computer.

Spybot was downloaded and run before Ad-aware. Re-boot and run Ad-aware. Then run ewido (Took several times cause it freezes at certain locations when removing files, I manually removed some of the files to get to the end).

Ewido will have issues like this when the infection is as bad as this one was. Often I will run it several times and also in safe mode which you will be doing shortly. I will comment on the ewido scan report first.

ewido anti-malware - Scan report Created on: 2:09:39 AM, 1/1/2006
What a mess. The first items which for some reason you ignored? When you run this program next, unless you know the item is not bad, delete everything. If it will not delete something then quarantine it.

The first three items is the quarantine are of a Yahoo program you have installed. Go there and delete everything in that Yahoo quarantine folder.

You also ignored many cookies. First, go here: C:\RECYCLER\ and open the bin for each user and delete everything in it (not the bin) If you don't see it, you do not have files and folders enabled.

When time permits use these links to gain some control of the cookies in Firefox:
http://privacy.getne...fdisablecookies
http://www.mozilla.o..._priv_help.html
If you need this information also for Internet Explorer let me know.

After you complete the above instructions, use this information to start the computer in safe mode:
http://www.bleepingc...tutorial61.html

Once in safe mode, run ewido again, delete everything it finds, there was nothing in the earlier scan that was any good. You should have no Yahoo quarantine items or C:\Recycler items in this scan report.

Logfile of HijackThis v1.99.1 Scan saved at 2:35:34 AM, on 1/1/2006

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O2 - BHO: (no name) - {1341D3F5-32B0-842A-CC6F-1CFF35279FFC} - C:\DOCUME~1\Susanne\APPLIC~1\UPLOAD~1\ford move.exe (file missing)
O4 - HKLM\..\Run: [Aim Chin Keep Part] C:\Documents and Settings\All Users\Application Data\Creative bore aim chin\DumbCreative.exe

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Delete these folders if there:
C:\DOCUMENTS AND SETTINGS~1\Susanne\APPLIC~1\UPLOAD~1\ >>> folder

C:\Documents and Settings\All Users\Application Data\Creative bore aim chin\ >>> folder

Empty the recycle bin and reboot the computer.

Computer is faster now but I am still get ad bar at the bottom of screen and pop up when I open IE. Firefox seems clean now.


Since you left so much junk ignored in the first ewido scan, this does not surprise me. When I say you are clean then let me know if any issues are left I can't see.

Post a new HJT and the ewido scan results. This stuff never comes off as easy as it gets on. Let's try to stay after this so it gets resolved, it has been dragging our far too long.

Since it appears you have multiple users, I need a log from each user created while signed in to that account.

Thanks...Phil

Edited by pskelley, 01 January 2006 - 09:40 AM.

MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

#10 Guest_Simon H_*

Guest_Simon H_*
  • Guests

Posted 07 January 2006 - 02:05 AM

Hi Phil,
Thanks a lot for responding to my post on New Year’s Day. Wish you a good New Year.
It is true that Messenger Plus only provides cosmetic functions to MSN, but that’s something my daughter will not give up. So I’ll have to live with it for now.

I know I didn’t do a good job the first round but I think this round is much better.

Here’s the new HJT log (looks cleaner now).

Logfile of HijackThis v1.99.1
Scan saved at 2:41:30 AM, on 1/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe
C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mofunzone...linearena.shtml
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://rogers.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://rogers.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ScRunCdRomSetupExe] E:\USBDRV\..\setup.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PowerBar] "C:\Program Files\CyberLink DVD Solution\Multimedia Launcher\PowerBar.exe" /AtBootTime
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NaturalColorLoad.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab30149.cab
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - http://www.musicnote...ad/mnviewer.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab30149.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1093451320728
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1126235070500
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab30149.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zon...ro.cab32846.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zon...oF.cab31267.cab
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD} (Photo Upload Plugin Class) - http://walmart.pnime...tupv2.0.0.9.cab?
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab30149.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe


And here’s the Ewido log.

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 3:00:26 AM, 1/7/2006
+ Report-Checksum: 41AA9D3A

+ Scan result:

HKLM\SOFTWARE\Altnet -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard -> Spyware.Altnet : Error during cleaning
HKLM\SOFTWARE\Altnet\Dashboard\Settings -> Spyware.Altnet : Error during cleaning


::Report End



I have the following questions.

1. All the scans found this Altnet ware but none of them can delete or clean it. Any idea what it is and how to get rid of it?
2. When I re-boot the machine now, I get a warning “C;\windows\system32\autoexec.nt. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose ‘close’ to terminate the application”. This never show up before.
3. After the system is cleaned, what you recommend so that I can minimize the risk in the future?
4. Should I set a restore point each time I clean the system?

Really appreciate your help. :thumbup:

Simon

#11 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 07 January 2006 - 09:12 AM

Hello Simon, We seem to be making some progress? The HJT log looks much better, I wonder if you can validate this item for me:
O4 - HKLM\..\Run: [ScRunCdRomSetupExe] E:\USBDRV\..\setup.exe

I asked in my last post about the possibility of multiple users and never got a response, can I get a yeah or neigh on that please.

ewido anti-malware - Scan report Created on: 3:00:26 AM, 1/7/2006
Altnet is a troublesome one to get rid of. You can see here all the free promises to get rid of it:
http://www.google.co...q=remove Altnet We will try again to kill it, this time in safe mode. We may have to edit the registry to remove it all? Why don't you do a search for us and see what search companion come up with. Let me know if it located elsewhere on the computer, especially the pathway.

Your feedback:
1) answered above.
2) watch your spelling > C;\ this should be C:\ Once I corrected the spelling, google returns this information:
http://www.google.co...ws applications
This looks like it may be a missing or corrupt file, let's try running System File Checker which is the first suggestion in the link below. If that does not work try the others.
http://www.cyber-rob...autoexecNT2.htm
3) I use the suggestions of some of the most respected folks in malware removal, since the HJT log is clean, I will post that information for you now.
Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://boards.cexx.o...topic.php?t=957
http://russelltexas....re/allclear.htm
http://forum.malware...wtopic.php?t=14
http://www.bleepingc...topict2520.html
Once you have reviewed this information, if you have questions, I will do my best to answer them.
4) No, to be sure nothing is backed up in System Restore, use this information to get clean SR files once we are finished with the repair.
http://service1.syma...src=sec_doc_nam

I must know if I am dealing with multiple users, an infection can be in one users HJT log and not show in another. If there are multiple users, post a log when signed in to each user, mark the logs plainly. See what your search comes up with concerning Altnet, I would like you to run ewido once more, this time in safe mode:
http://www.bleepingc...tutorial61.html and post the scan results. See what you can do with the information I provided about the error message.

Thanks...Phil

Edited by pskelley, 07 January 2006 - 09:15 AM.

MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

#12 pskelley

pskelley

    R.I.P Always in our hearts

  • Authentic Member
  • PipPipPipPipPip
  • 3,879 posts
  • Interests:Computers, fishing, biking, basketball, travel

Posted 11 January 2006 - 05:43 PM

Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoy...showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php
MS-MVP Windows Security 2007-8-9 Proud Member ASAP UNITE Member 2006

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users