This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log (Zlob)

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've looked at many threads on this virus and tried to use them to fix my problem. I can't seem to get rid of it on my own, help would be much appreciated. I’ve managed to kill it temporarily, but when I re-boot it comes back. Here is the log file: Logfile of HijackThis v1.99.1 Scan saved at 11:04:49 PM, on 7/15/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ishost.exe C:\WINDOWS\system32\ismon.exe C:\WINDOWS\ASEMBL~1\MCONFI~1.EXE C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\COMMON~1\ICROSO~1\msconfig.exe C:\WINDOWS\system32\issearch.exe C:\WINDOWS\system32\isnotify.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\User\Desktop\HJT.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1 R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file) O2 - BHO: (no name) - {6B8AB991-2820-4D90-B151-6B256DCEFA17} - C:\WINDOWS\system32\awvvs.dll O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt0.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing) O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [Csioq] C:\WINDOWS\ASEMBL~1\MCONFI~1.EXE O4 - HKCU\..\Run: [Usrr] "C:\PROGRA~1\COMMON~1\ICROSO~1\msconfig.exe" -vt ndrv O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll O20 - Winlogon Notify: awvvs - C:\WINDOWS\system32\awvvs.dll O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g84065484.dll (file missing) O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Please download VundoFix.exe from here:

http://www.atribune.org/ccount/click.php?id=4

and save it to your desktop


Double-click VundoFix.exe to run it.

Checkmark the box "Run Vundo as task"

You will receive a message saying vundofix will close and re-open in a minute or less. Click OK

When VundoFix re-opens, click the Scan for Vundo button

Once it's done scanning, click the Remove Vundo button.

You will receive a prompt asking if you want to remove the files, click YES

Once you click yes, your desktop will go blank as it starts removing Vundo.

When completed, it will prompt that it will shutdown your computer, click OK.

Turn your computer back on.

NEXT

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
    Please post the contents of C:\vundofix.txt and a new hijackthis log.
I killed ismon.exe, ishost.exe and isnotify.exe with killbox… they'll come back when i re-boot though. Logfile of HijackThis v1.99.1 Scan saved at 11:33:08 PM, on 7/15/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\ewido anti-spyware 4.0\guard.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\wanmpsvc.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\COMMON~1\ICROSO~1\msconfig.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Program Files\Microsoft Office\Office\WINWORD.EXE C:\Documents and Settings\User\Desktop\HJT.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1 R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file) O2 - BHO: (no name) - {6B8AB991-2820-4D90-B151-6B256DCEFA17} - C:\WINDOWS\system32\awvvs.dll O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt1.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing) O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [Csioq] C:\WINDOWS\ASEMBL~1\MCONFI~1.EXE O4 - HKCU\..\Run: [Usrr] "C:\PROGRA~1\COMMON~1\ICROSO~1\msconfig.exe" -vt ndrv O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll O20 - Winlogon Notify: awvvs - C:\WINDOWS\system32\awvvs.dll O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g84065484.dll (file missing) O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing) O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe Vundofix: no infected files were found (i even tried to add the files listed in another post and preform 'remove vundo' but that also failed. ewido anti-spyware - Scan Report ——————————————————— + Created at: 2:34:27 PM 7/14/2006 + Scan result: HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temp\ICD1.tmp\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\EL4LPT4J\YazzleActiveX[1].cab/YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\YazzleActiveX.ocx -> Adware.MediaTickets : Cleaned with backup (quarantined). C:\WINDOWS\system32\__delete_on_reboot__c_h_k_n_t_f_s_._d_l_l_ -> Adware.PurityScan : Cleaned with backup (quarantined). [1024] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1120] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1132] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1196] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1800] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1916] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [1960] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [224] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [2356] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [2700] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [2936] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [3108] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [3192] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [3512] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [392] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [476] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [664] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [688] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [720] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [768] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [780] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [940] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. [988] C:\WINDOWS\system32\chkntfs.dll -> Adware.PurityScan : Error during cleaning. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\EL4LPT4J\anti4[1].exe -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\system32\wvutsrq.dll -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\Cache(2)\B23E4567d01 -> Downloader.Agent.alr : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\MSW963Q9\WinAntiVirusPro2006FreeInstall[1].cab/UWA6P_0001_N85M0307NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N85M0307NetInstaller.exe -> Downloader.Agent.alr : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temp\remove.exe -> Downloader.Keenval.f : Cleaned with backup (quarantined). C:\!!!Max's Stuff\Shadow Mailer 1.1.exe -> Not-A-Virus.EmailFlooder.Win32.Shadow.11 : Ignored. C:\RECYCLER\S-1-5-21-1609710031-84597072-109732076-1005\Dc46.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Ignored. :mozilla.185:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.32:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.33:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.34:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.35:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.36:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.435:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.65:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.66:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.67:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.68:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.69:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.70:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.71:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.72:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.38:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.164:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned. :mozilla.165:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned. :mozilla.45:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.49:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.50:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.52:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.54:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.83:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.84:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.85:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.93:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.97:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.111:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.112:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.381:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adtrak : Cleaned. :mozilla.382:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Adtrak : Cleaned. :mozilla.116:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.117:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.118:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.119:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.120:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.121:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.23:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.24:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.25:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.155:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.22:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.341:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. :mozilla.439:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.124:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.282:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.283:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.284:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.179:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.188:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.342:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.408:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.23:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.38:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.371:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.372:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.241:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.388:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.389:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.390:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.391:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.66:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.275:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.68:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.69:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.98:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.101:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.102:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.103:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.43:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.44:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.45:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.46:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.99:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.247:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.47:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.48:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.293:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.22:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.39:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.93:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.94:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.302:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned. :mozilla.224:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.226:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.227:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.231:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.234:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.383:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Popuptraffic : Cleaned. :mozilla.384:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Popuptraffic : Cleaned. :mozilla.385:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Popuptraffic : Cleaned. :mozilla.85:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.86:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.122:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.123:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.124:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.26:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.27:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.28:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.29:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.30:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.31:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.32:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.33:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\User\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.218:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.40:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.73:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.74:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.75:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.76:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.180:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.181:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.182:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.183:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.19:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned. :mozilla.20:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned. :mozilla.351:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.352:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.248:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Spylog : Cleaned. :mozilla.373:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.88:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.232:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.233:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.235:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.236:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.237:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.353:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.47:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned. :mozilla.48:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned. :mozilla.53:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned. :mozilla.203:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.204:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.205:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.206:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.207:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.208:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.209:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.210:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.211:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.142:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.143:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.145:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.148:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.149:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.150:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.151:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.340:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.368:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.369:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.250:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.252:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.41:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.42:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.43:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.44:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.46:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.51:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.55:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.215:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.216:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.217:C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.64:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.65:C:\Documents and Settings\Fred\Application Data\Mozilla\Firefox\Profiles\8vxxpbhu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\EL4LPT4J\bgates[1].exe -> Trojan.Dialer.pz : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temp\!update.exe -> Trojan.PurityAd : Cleaned with backup (quarantined). C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YXQEEVAA\!update-4020[1].0000 -> Trojan.PurityAd : Cleaned with backup (quarantined). C:\Program Files\Common Files\Μicrosoft\msconfig.exe -> Trojan.PurityAd : Cleaned with backup (quarantined). [404] C:\PROGRA~1\COMMON~1\ICROSO~1\msconfig.exe -> Trojan.PurityAd : Error during cleaning. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\\kernel32.dll -> Trojan.Small : Cleaned with backup (quarantined). ::Report end VundoFix V5.1.4 Checking Java version… Java version is 1.4.2.4 Java version is 1.4.2.5 Java version is 1.4.2.6 Java version is 1.5.0.2 Scan started at 9:58:05 PM 7/15/2006 Listing files found while scanning…. No infected files were found. Beginning removal… VundoFix V5.1.4 Running as SYSTEM from c:\windows\system32\VundoFix.exe Checking Java version… Java version is 1.4.2.4 Java version is 1.4.2.5 Java version is 1.4.2.6 Java version is 1.5.0.2 Scan started at 10:07:47 PM 7/15/2006 Listing files found while scanning…. No infected files were found. Beginning removal… Beginning removal… VundoFix V5.1.4 Running as SYSTEM from c:\windows\system32\VundoFix.exe Checking Java version… Java version is 1.4.2.4 Java version is 1.4.2.5 Java version is 1.4.2.6 Java version is 1.5.0.2 Scan started at 10:13:33 PM 7/15/2006 Listing files found while scanning…. No infected files were found. Beginning removal… VundoFix V5.1.4 Checking Java version… Java version is 1.4.2.4 Java version is 1.4.2.5 Java version is 1.4.2.6 Java version is 1.5.0.2 Scan started at 11:24:30 PM 7/15/2006 Listing files found while scanning…. VundoFix V5.1.4 Running as SYSTEM from c:\windows\system32\VundoFix.exe Checking Java version… Java version is 1.4.2.4 Java version is 1.4.2.5 Java version is 1.4.2.6 Java version is 1.5.0.2 Scan started at 11:28:02 PM 7/15/2006 Listing files found while scanning…. No infected files were found.
Please print these instructions out for use in Safe Mode.

Please download VundoFix.exe to your desktop
from the link below:
http://www.atribune.org/downloads/VundoFix.exe
  • Double-click VundoFix.exe to extract the files
  • This will create a VundoFix folder on your desktop.
  • After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
  • Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
  • You will first be presented with a warning.
    It should look like this

    VundoFix V2.15 by Atri
    By using VundoFix you agree that you are doing so at your own risk
    Press enter to continue….



  • At this point press enter one time.


  • Next you will see:

    Please Type in the filepath as instructed by the forum staff
    and then press enter:



  • At this point please type the following file path (make sure to enter it exactly as below!):
    • C:\WINDOWS\system32\awvvs.dll
  • Press Enter to continue with the fix.


  • Next you will see:

    Please type in the second filepath as instructed by the forum
    staff then press enter:

  • At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\system32\svvwa.dll
  • Press Enter to continue with the fix.
  • The fix will run then HijackThis will open, if it does not open automatically please open it manually.
  • In HiJackThis, please place a check next to the following items and click FIX CHECKED:

    R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file)

    O2 - BHO: (no name) - {6B8AB991-2820-4D90-B151-6B256DCEFA17} - C:\WINDOWS\system32\awvvs.dll
    O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt1.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

    O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll
    O20 - Winlogon Notify: awvvs - C:\WINDOWS\system32\awvvs.dll
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g84065484.dll (file missing)
    O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll

    O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing)

  • After you have fixed these items, close Hijackthis.
  • Press enter to exit the program then manually reboot your computer.
  • Once your machine reboots please continue with the instructions below.
Download and install CleanUp!

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options…"
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
  • Empty Recycle Bins
  • Delete Cookies
  • Delete Prefetch files
  • Cleanup! All Users
Click OK
Press the CleanUp! button to start the program.

It may ask you to reboot at the end, click NO.

Then, please run this online virus scan: ActiveScan; make sure you scan "My Computer". Click on "See report", then on "Save report".

NEXT


Look in your control panels add/remove programs for PuritySCAN By OIN, OuterInfo, OIN or similar , click on it and click remove.
Reboot and delete this folder if found:
C:\Program Files\PurityScan

If not listed, download and run this uninstaller:
http://www.outerinfo.com/OiUninstaller.exe

Tutorial for the uninstaller if needed

Reboot when done and delete this folder if found:
C:\Program Files\PurityScan

Post a fresh HJT log.


Copy the results of the ActiveScan and paste them here along with a new HiJackThis log and the vundofix.txt file from the vundofix folder into this topic.

Also, you have disabled files at start up as seen by this line


O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto

Open msconfig and make sure all start up files are disabled or I will not be able to see them.
Currently Scanning with active scan. The ishost/ismon have not regenerated on re-boot. i've received a few popups, but my IE homepage is back to normal. will reply with logs soon [Going to have to scratch that… the scan is taking far longer than anticipated. Going to bed…] In the mean time, thank you for your help. It's very much appreciated… but i'm sure you know that :lol:
Logfile of HijackThis v1.99.1
Scan saved at 12:02:02 PM, on 7/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\User\Desktop\HJT.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1
R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file)
O2 - BHO: (no name) - {79766846-B086-4FD9-B856-BC48CA8BA58E} - C:\WINDOWS\system32\awvvs.dll (file missing)
O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt1.dll (file missing)
O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00309} - C:\WINDOWS\g42061765.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll
O20 - Winlogon Notify: awvvs - C:\WINDOWS\system32\awvvs.dll (file missing)
O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g84065484.dll (file missing)
O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll
O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe


Incident Status Location

Adware:Adware/PurityScan Not disinfected c:\progra~1\common~1\icroso~1\msconfig.exe
Adware:Adware/SuperSpider Not disinfected C:\WINDOWS\system32\winxna32.dll
Adware:adware/securityerror Not disinfected c:\windows\system32\ot.ico
Spyware:spyware/virtumonde Not disinfected c:\windows\system32\ssqpp.dll
Dialer:dialer.avv Not disinfected c:\windows\downloaded program files\gdnUS2339.exe
Potentially unwanted tool:application/bestoffer Not disinfected c:\windows\smdat32a.sys
Adware:adware/emediacodec Not disinfected c:\documents and settings\all users\favorites\desktop\Online Security Guide.url
Adware:adware/yazzle Not disinfected Windows Registry
Adware:adware/miamore Not disinfected Windows Registry
Potentially unwanted tool:application/altnet Not disinfected hkey_classes_root\clsid\{3f4d4f88-0198-4921-b630-957f3eb814e0}
Adware:adware/ist.istbar Not disinfected Windows Registry
Hacktool:Flooder Program Not disinfected C:\!!!Max's Stuff\Shadow Mailer 1.1.exe
Adware:Adware/SystemDoctor Not disinfected C:\!KillBox\3c93c74.exe
Adware:Adware/MediaTickets Not disinfected C:\!KillBox\Cowabanga\uninstaller.exe
Adware:Adware/SuperSpider Not disinfected C:\!KillBox\winxna32.dll
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[.sextracker.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[counter5.sextracker.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\dvlf1gan.default\cookies.txt[.2o7.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\User\Cookies\[removed][1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\User\Cookies\[removed][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\User\Cookies\user@doubleclick[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\User\Desktop\VundoFix\VundoFix\process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\User\Desktop\VundoFix-1.exe[process.exe]
Adware:Adware/SystemDoctor Not disinfected C:\Documents and Settings\User\Local Settings\Application Data\3c93c74.exe
Dialer:Dialer.HIX Not disinfected C:\Documents and Settings\User\Local Settings\Temporary Internet Files\Content.IE5\YL7R7LK8\bgates[1].exe
Adware:Adware/PurityScan Not disinfected C:\Program Files\Common Files\?icrosoft\msconfig.exe
Virus:Trj/Deldir.A Disinfected C:\WINDOWS\system32\oobe\emachines\Preinstall.cmd
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\temp\win289.tmp.exe
Adware:Adware/SystemDoctor Not disinfected C:\WINDOWS\temp\win2DA.tmp.exe



VundoFix V2.15 by Atri
————————————————————————————–

Listing files contained in the vundofix folder.
————————————————————————————–

killvundo.bat
process.exe
ReadMe.txt
vundo.reg
vundofix.txt

————————————————————————————–

Filepaths entered
————————————————————————————–

The filepath entered was C:\Windows\system32\awvvs.dll

The second filepath entered was C:\WINDOWS\system32\svvwa.dll

————————————————————————————–

Log from Process
————————————————————————————–


Killing PID 128 'smss.exe'

Killing PID 792 'explorer.exe'
Killing PID 792 'explorer.exe'
Killing PID 792 'explorer.exe'


Killing PID 248 'winlogon.exe'
————————————————————————————–

C:\Windows\system32\awvvs.dll Deleted sucessfully.
C:\WINDOWS\system32\svvwa.dll Deleted sucessfully.

Fixing Registry
————————————————————————————–
Have you enabled everything in start up with msconfig? Scan with hijackthis and put a check beside these lines and choose FIX R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file) O2 - BHO: (no name) - {79766846-B086-4FD9-B856-BC48CA8BA58E} - C:\WINDOWS\system32\awvvs.dll (file missing) O2 - BHO: (no name) - {873eb32d-ae1a-4183-89bd-45a77f761be4} - C:\WINDOWS\system32\ixt1.dll (file missing) O2 - BHO: (no name) - {A4F94C0C-54A7-4DB1-9AF3-B22E63D00309} - C:\WINDOWS\g42061765.dll O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file) O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll O20 - Winlogon Notify: awvvs - C:\WINDOWS\system32\awvvs.dll (file missing) O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g84065484.dll (file missing) O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll O21 - SSODL: cinnamomum - {93ac7c30-3878-4eaa-9420-7977285df5b1} - C:\WINDOWS\system32\pmnqguh.dll (file missing) Then reboot and a new hijackthis log please.

Open msconfig and make sure all start up files are disabled or I will not be able to see them.

Disable or enable?

When attempting to fix the hijack log i received an error:

An unexpected error has occurred at procedure: modBackup_MakeBackup(sItem=O20 - AppInit_DLLs: C:\WINDOWS\system32\chkntfs.dll)
Error #5 - Invalid procedure call or argument

Please email me at [removed], reporting the following:
* What you were trying to fix when the error occurred, if applicable
* How you can reproduce the error
* A complete HijackThis scan log, if possible

Windows version: Windows NT 5.01.2600
MSIE version: 6.0.2900.2180
HijackThis version: 1.99.1

This message has been copied to your clipboard.
Click OK to continue the rest of the scan.
Logfile of HijackThis v1.99.1
Scan saved at 3:13:49 PM, on 7/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\User\Desktop\HJT.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1
R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
Download http://swandog46.geekstogo.com/avenger.zip by Swandog46, and save it to your Desktop. Extract avenger.exe from the Zip file and save it to your desktop

Run avenger.exe by double-clicking on it.
Check the 'Input script manually' box.
Click on the magnifying glass icon.
Copy everything in the code box below (don't copy the word "CODE in the box header, just the box contents starting at Files to delete) and paste it in the box that opens:

WARNING: This script is not a general fix. If you are not this user, running this script could damage your system

Files to delete:
C:\WINDOWS\SYSTEM32\winxna32.dll

Now click the 'Done' button.
Click on the traffic light icon and OK the prompt.
You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it manually.

Please post a new HijackThis log and the log file from Avenger at C:\avenger.txt
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\qqkuuqsc

*******************

Script file located at: myavyuqx

Could not open script file! Error

Could not open script file! Status: 0xc000003b Abort!

Logfile of HijackThis v1.99.1
Scan saved at 4:52:27 PM, on 7/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Updater.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\TEMP\win289.tmp.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\User\Desktop\HJT.exe
C:\WINDOWS\System32\imapi.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1
R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file)
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [SpyQuake2.com] C:\Program Files\SpyQuake2.com\Spy-Quake2.exe /h
O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\1st SMTP Server\SMTPServer.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [3c93c74.exe] C:\WINDOWS\system32\3c93c74.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Csioq] C:\WINDOWS\ASEMBL~1\MCONFI~1.EXE
O4 - HKCU\..\Run: [BricksOfAtlantisSetup.exe] C:\DOCUME~1\USER\DESKTOP\BRICKS~1.EXE /r
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\America Online 9.0a\aoltray.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
Scan with hijackthis and put a check beside these lines and choose FIX

R3 - URLSearchHook: (no name) - {AA0C6D0E-A2E2-FF61-9E48-FFBADB134FC6} - (no file)


O4 - HKLM\..\Run: [3c93c74.exe] C:\WINDOWS\system32\3c93c74.exe


O20 - Winlogon Notify: winxna32 - C:\WINDOWS\SYSTEM32\winxna32.dll

NEXT

Please download Asquared from the link below.

http://www.emsisoft.com/en/software/download/

Safe it to your desktop. Next open and check for updates.

Boot to safe mode (tap f8 while bios loads)

Then scan your system (this will take some time) after the scan is compelte allow it to fix what it has found. If there is something that it can not clean please let me know what it was.

Then reboot and post a new hijackthis log.
Logfile of HijackThis v1.99.1
Scan saved at 2:54:44 PM, on 7/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Updater.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Documents and Settings\User\Desktop\HJT.exe
C:\Program Files\a-squared Anti-Malware\a2guard.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\BigFix\BigFix.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.0.1
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll (file missing)
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Program Files\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [updmgr] C:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [smtpsrv] C:\Program Files\1st SMTP Server\SMTPServer.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iRiver Updater] \Updater.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKLM\..\Run: [a-squared] "C:\Program Files\a-squared Anti-Malware\a2guard.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Csioq] C:\WINDOWS\ASEMBL~1\MCONFI~1.EXE
O4 - HKCU\..\Run: [BricksOfAtlantisSetup.exe] C:\DOCUME~1\USER\DESKTOP\BRICKS~1.EXE /r
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\America Online 9.0a\aoltray.exe
O4 - Global Startup: BigFix.lnk = C:\Program Files\BigFix\BigFix.exe
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Program Files\ICQ\ICQ.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.emachines.com
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI