This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan.Zlob.D help needed

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was browsing the net, when my browser closed and came up with an error, with some stick***.dll and I closed it and no sooner than clicking the box AVG come up with this Trojan.Zlob.D. I quarantined it and locked down my connection to the net. Spybot s&d teatimer kept on squawking about a registry change and no matter how many times I didnt allow it it kept comming back. so I pushed it off to the side and ran adaware and spybot. removed some malware and ran avg and wiped the virus from the vault. shut down the restore points. rsboot and I still have the mssearchnet.exe running. I want to know if there is something else I should be looking for instead of just randomly deleting reg keys and enkytion keys and the sort.
here is my HJT log.

Thanks for your time in advance.

Logfile of HijackThis v1.99.1
Scan saved at 10:22:56 PM, on 4/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Michael\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: cleantemp.bat
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} -
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O16 - DPF: {3C403675-B43C-410B-BF56-D4D1FB68356C} -
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{00F8BD24-A082-4367-A013-4969A16193AD}: NameServer = 207.230.192.251 209.206.136.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{00F8BD24-A082-4367-A013-4969A16193AD}: NameServer = 207.230.192.251 209.206.136.8
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Download smitRem.exe ©noahdfear, and save the file to your desktop.
Double click on the file to extract it to it's own folder on the desktop.

Place a shortcut to Panda ActiveScan on your desktop.

Please download the trial version of ewido anti-malware here:
http://www.ewido.net/en/download/

Please read Ewido Setup Instructions
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

If you have not already installed Ad-Aware SE 1.06, follow these download and setup instructions, otherwise, check for updates:
Ad-Aware SE Setup
Don't run it yet!

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen.
Wait for the tool to complete and disk cleanup to finish.

The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


Open Ad-aware and do a full scan. Remove all it finds.


Run Ewido:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Close ewido anti-malware.

Next go to Control Panel click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.

Reboot back into Windows and click the Panda ActiveScan shortcut.
  • Once you are on the Panda site click the Scan your PC button.
  • A new window will open…click the Check Now button.
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When the download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Post the contents of the Panda scan report, along with a new HijackThis Log, the contents of smitfiles.txt and the Ewido Log by using Add Reply.
Let us know if any problems persist.
ok, the panda scan caught one reg key and some cookies at the end and Spybot had 2 attempt at an it toolbar chnage but I denied them both. here are the three logs after all was done. figuring I should delete the reg key but will wait for other opinions.

—————————————————————————————————————
Activescan

Incident Status Location

Potentially unwanted tool:application/spywarequake Not disinfected HKEY_LOCAL_MACHINE\SOFTWARE\SPYWAREQUAKE
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt[]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Michael\Desktop\smitrem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Michael\Desktop\smitRem.exe[Process.exe]
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Stephanie\Cookies\stephanie@banner[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Stephanie\Cookies\stephanie@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Stephanie\Cookies\[removed][2].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Stephanie\Cookies\stephanie@target[2].txt
—————————————————————————————————————
Logfile of HijackThis v1.99.1
Scan saved at 2:21:10 AM, on 4/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\D-Tools\daemon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Documents and Settings\Michael\Desktop\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: cleantemp.bat
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15015/CTSUEng.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} -
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} -
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.1.1.74.cab
O16 - DPF: {3C403675-B43C-410B-BF56-D4D1FB68356C} -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15016/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{00F8BD24-A082-4367-A013-4969A16193AD}: NameServer = 207.230.192.251 209.206.136.8
O17 - HKLM\System\CS1\Services\Tcpip\..\{00F8BD24-A082-4367-A013-4969A16193AD}: NameServer = 207.230.192.251 209.206.136.8
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

———————————————————————————————————-
I goofed a step(update ewido defintions) so I started the smitrem over after I had updated ewido.
here are both log files for the two runs.

First Run

smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Fri 04/07/2006
The current time is: 23:56:14.20

Running from
C:\Documents and Settings\Michael\Desktop\smitrem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}"="USB Ware"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}\InProcServer32]
@="C:\WINDOWS\system32\stickrep.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!


Second Run

smitRem © log file
version 2.8

by noahdfear


Microsoft Windows XP [Version 5.1.2600]
The current date is: Sat 04/08/2006
The current time is: 0:19:25.65

Running from
C:\Documents and Settings\Michael\Desktop\smitrem

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run SharedTask Export

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}"="USB Ware"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}\InProcServer32]
@="C:\WINDOWS\system32\stickrep.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

checking for ShudderLTD key

ShudderLTD key not present!

checking for PSGuard.com key


PSGuard.com key not present!


checking for WinHound.com key


WinHound.com key not present!

spyaxe uninstaller NOT present
Winhound uninstaller NOT present
SpywareStrike uninstaller NOT present

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Existing Pre-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Command Line Process Viewer/Killer/Suspender for Windows NT/2000/XP V2.03
Copyright© 2002-2003 [removed]
Killing PID 728 'explorer.exe'

Starting registry repairs

Registry repairs complete

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

SharedTask Export after registry fix

(GetSTS.exe) SharedTaskScheduler exporter by Lawrence Abrams (Grinler)
Copyright© 2006 BleepingComputer.com

Registry Pseudo-Format Mode (Not a valid reg file):

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"
"{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}"="USB Ware"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{438755C2-A8BA-11D1-B96B-00A0C90312E1}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8C7461EF-2B13-11d2-BE35-3078302C2030}\InProcServer32]
@="%SystemRoot%\System32\browseui.dll"


[HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}\InProcServer32]
@="C:\WINDOWS\system32\stickrep.dll"


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Deleting files

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Remaining Post-run Files


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~


~~~ Wininet.dll ~~~

CLEAN! :)

—————————————————————————————————————
———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 1:19:56 AM, 4/8/2006
+ Report-Checksum: 907F1563

+ Scan result:

HKU\S-1-5-21-1960408961-412668190-839522115-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.93:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.94:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.95:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.107:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.135:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.148:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.166:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.167:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.169:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.285:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.294:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.355:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.360:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.367:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.374:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.377:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.378:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.379:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Spinbox : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.410:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.411:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.427:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.428:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.433:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.434:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.435:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Trafic : Cleaned with backup
:mozilla.443:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.468:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.595:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.596:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.597:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.598:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.599:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.600:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.602:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.603:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.604:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.605:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.610:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.611:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.615:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.620:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\ze4wxokw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
C:\Documents and Settings\Michael\My Documents\mIRC\antispambot.mrc -> Backdoor.Kelebek.ad : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.92:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.101:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.102:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Stephanie\Application Data\Mozilla\Firefox\Profiles\6vi2djzn.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Stephanie\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Stephanie\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Stephanie\Cookies\stephanie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\WINDOWS\system32\dfrgsrv.exe -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\interf.tlb -> Trojan.Small : Cleaned with backup
C:\WINDOWS\system32\stickrep.dll -> Trojan.Small : Cleaned with backup


::Report End
————————————————————————————————————-

so whats the prognosis?
Open Notepad copy and paste the following.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}"=-

[-HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{E2CA7CD1-1AD9-F1C4-3D2A-DC1A33E7AF9D}]


save it as fix.reg to the desktop save it as type all files then go to the desktop and double click it it will ask to merge the infomation into the registery allow it to do so.

Then Your log is clean :)

Here are some tips, to reduce the potential for spyware infection in the future, I strongly recommend installing the following applications:
  • Spywareblaster <= SpywareBlaster will prevent spyware from being installed.
  • Spywareguard <= SpywareGuard offers realtime protection from spyware installation attempts.
  • How to use Ad-Aware to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Ad-Aware.
  • How to use Spybot to remove Spyware <= If you suspect that you have spyware installed on your computer, here are instructions on how to download, install and then use Spybot. Similar to Ad-Aware, I strongly recommend both to catch most spyware.
To protect yourself further:
  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
I also suggest that you delete any files from "temp", "tmp" folders. In Internet Explorer, click on "Tools" => "Internet Options" => "Delete Files" and select the box that says "Delete All Offline Content" and click on "OK" twice. Also, empty the recycle bin by right clicking on it and selecting "Empty Recycle Bin". These steps should be done on a regular basis.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI