This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

reboot problem, automatically reboots over and over

18 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was attacked, and had many viri on my system. It took over quite quickly and caused a reboot, which in turn, caused another reboot right as windows was loading. This continued until I booted in safe mode (where I am now), and will not work.

These are the steps I took. (all in Safe Mode)

1) Ran Housecall from Trend Micro
2) followed instructions on self help.
3) Ran spybot
4) Ran Ad-Aware
5) Ran Ewido
6) Posted to this forum my log files from ewido and hijak this.

Please help.

–Marc

Logfile of HijackThis v1.99.1
Scan saved at 12:53:45 PM, on 7/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Documents and Settings\Marc\Desktop\HijackThis.exe
C:\PROGRA~1\MOZILL~2\FIREFOX.EXE

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\prefs.js)
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: (no name) - {021620B0-701C-4872-8F2B-9037E942E48A} - C:\Program Files\MSN\hoceny.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {87185E78-A61B-4DB3-965A-3235BBD7A622} - C:\WINDOWS\system32\win32hp.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [b2f06c1e.exe] C:\WINDOWS\system32\b2f06c1e.exe
O4 - HKLM\..\Run: [sound64] FLKPT.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [SysTray] c:\Program Files\kunemwse.exe
O4 - HKLM\..\Run: [defender] C:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdef_7.exe
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [win32hlp] C:\WINDOWS\system32\win32hlp.exe
O4 - HKLM\..\Run: [updwebmin] c:\windows\system32\updwebmin.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\RunServices: [updwebmin] c:\windows\system32\updwebmin.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [b2f06c1e.exe] C:\Documents and Settings\Marc\Local Settings\Application Data\b2f06c1e.exe
O4 - HKCU\..\Run: [StartCpl] scanSYS.exe
O4 - HKCU\..\Run: [backd] bnui.exe
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [updwebmin] c:\windows\system32\updwebmin.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105729392280
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{A58B082B-959A-4EC5-BDA7-BD97938CACB8}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS3\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

————
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 4:55:52 PM 7/26/2006

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP753\A0032559.exe -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP761\A0033787.exe -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033852.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\WINDOWS\system32\win32hp.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033921.exe -> Adware.Spysheriff : Cleaned with backup (quarantined).
C:\Documents and Settings\Marc\Local Settings\Temp\F9B4.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\xeymi.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mscdaux.dll -> Backdoor.Delf.aml : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033898.exe -> Downloader.Adload.cu : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033902.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP714\A0030733.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP714\A0030747.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP714\A0031747.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP714\A0031775.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP718\A0031932.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP718\A0031945.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP718\A0032025.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP724\A0032157.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0032568.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033569.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033575.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033580.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033585.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033592.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033600.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033604.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033612.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0033653.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP756\A0033666.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033850.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033871.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033883.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033908.exe -> Downloader.Agent.uj : Cleaned with backup (quarantined).
[1668] VM_009D0000 -> Downloader.Agent.uj : Error during cleaning.
[420] VM_00F30000 -> Downloader.Agent.uj : Error during cleaning.
[552] VM_00D60000 -> Downloader.Agent.uj : Error during cleaning.
[576] VM_00BF0000 -> Downloader.Agent.uj : Error during cleaning.
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP755\A0032576.exe -> Downloader.Small.ajc : Cleaned with backup (quarantined).
C:\Documents and Settings\Marc\Desktop\sdff1f -> Downloader.Small.awa : Cleaned with backup (quarantined).
C:\WINDOWS\system32\t1t.exe -> Downloader.Small.awa : Cleaned with backup (quarantined).
C:\kybrdef_7.exe -> Downloader.VB.air : Cleaned with backup (quarantined).
C:\Documents and Settings\Marc\Local Settings\Temp\gz61c607.exe -> Downloader.Zlob.sh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033869.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033899.exe -> Hijacker.VB.nh : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033892.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033893.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\WINDOWS\system32\tt.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : Ignored.
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033896.exe -> Not-A-Virus.Hoax.Win32.Renos.dc : Ignored.
C:\System Volume Information\_restore{FA26AED3-46AE-4CF8-AE12-C8A4BB41E768}\RP762\A0033901.dll -> Proxy.Wopla.s : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.282:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.384:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.49:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.50:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.52:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.53:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.54:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.55:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.56:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.57:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.59:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.60:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.61:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.62:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.63:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.64:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.65:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.90:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.15:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.45:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.46:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.47:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.48:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.671:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.672:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.673:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.674:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.93:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.42:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.43:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.608:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.609:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.647:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.648:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.649:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.650:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.651:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.652:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.172:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.230:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.112:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.113:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.261:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.767:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.768:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.769:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.770:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.771:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.772:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.773:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.774:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.775:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.776:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.683:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.684:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.685:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.689:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.690:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.691:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.692:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.693:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.694:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.695:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.395:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.396:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.397:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.398:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.411:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.656:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.403:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.404:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.415:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.416:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.417:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.418:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.419:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.420:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.421:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.422:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.423:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.19:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.20:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.21:C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.238:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.239:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.240:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.241:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.144:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.447:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.448:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.449:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.450:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.173:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.174:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.175:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.176:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.177:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.178:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.179:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.180:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.181:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.182:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.183:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.184:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.185:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.186:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.187:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.188:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.189:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.190:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.191:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.192:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.193:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.194:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.195:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.196:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.197:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.198:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.199:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.200:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.201:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.202:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.203:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.204:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.205:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.206:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.207:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.208:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.209:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.210:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.211:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.212:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.213:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.214:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.831:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.832:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.833:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.91:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.92:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.472:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.473:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.474:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.475:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.476:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.477:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.478:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.479:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.480:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.481:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.482:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.483:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.484:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.485:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.486:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.487:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.488:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.489:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.490:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.491:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.492:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.493:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.494:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.495:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.496:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.497:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.498:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.499:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.500:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.501:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.502:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.503:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.504:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.505:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.506:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.507:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.508:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.509:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.510:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.511:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.512:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.513:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.514:C:\Documents and Settings\Marc\Application Data\Mozilla\Firefox\Profiles\qtow9j13.default\cookies.txt -> TrackingCookie.S
mholmquist, :D

Welcome to Tom Coyote, sorry for the delay in responding but we are as most times just overwhelmed with logs. You have many infections on your system , the most serious is that your computer has been hijacked by the lovely people in the Ukraine.

Print this out if you can because we will be offline for part of the fix.


Your HIJACKTHIS program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix,
* just go to My Computer > YOUR C:\ DRIVE and create a new folder and name it Hijackthis.
* Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
* Now open the new folder you just created and right click within that folder and select PASTE .
* Now HJT should reside in C:\Hijackthis\Hijackthis.exe


Please do not proceed until you move HJT to it's own folder.




* Click on My Computer
* Then on your C: Drive
* Then to Tools/ Folder Options/ View
* Choose the radio button to Show Hidden Files and Folders
* Take the checkmark out of Hide Extensions for Known File Types
* Then Apply/ OK



You may have to download this to another computer and then transfer the program to the infected one.


Please download FixWareout
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, HijackThis will launch. ( If it does not launch, start HJT manually ) Please click Scan, and check the following items:

O1 - Hosts: localhost 127.0.0.1

O2 - BHO: (no name) - {021620B0-701C-4872-8F2B-9037E942E48A} - C:\Program Files\MSN\hoceny.dll (file missing)
O2 - BHO: (no name) - {87185E78-A61B-4DB3-965A-3235BBD7A622} - C:\WINDOWS\system32\win32hp.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)

O4 - HKLM\..\Run: [defender] C:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdef_7.exe
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [Windows Task Manager] c:\windows\system32\taskmgn.exe
O4 - HKLM\..\Run: [win32hlp] C:\WINDOWS\system32\win32hlp.exe
O4 - HKLM\..\Run: [updwebmin] c:\windows\system32\updwebmin.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\RunServices: [updwebmin] c:\windows\system32\updwebmin.exe
O4 - HKCU\..\Run: [KillAndClean] "C:\Program Files\KillAndClean\KillAndClean.exe"
O4 - HKCU\..\Run: [b2f06c1e.exe] C:\Documents and Settings\Marc\Local Settings\Application Data\b2f06c1e.exe
O4 - HKCU\..\Run: [StartCpl] scanSYS.exe
O4 - HKCU\..\Run: [backd] bnui.exe
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [updwebmin] c:\windows\system32\updwebmin.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{A58B082B-959A-4EC5-BDA7-BD97938CACB8}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111
O17 - HKLM\System\CS3\Services\Tcpip\..\{11B37C54-8F2B-43C6-8323-F74ADAFABBA9}: NameServer = 85.255.116.162,85.255.112.111



Click Fix Checked. Close HijackThis, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.


Reboot back into Safemode
and right click on Start> Click on Explore and Navigate to the following files and delete them.


C:\Program Files\MSN\hoceny.dll
C:\Program Files\KillAndClean

C:\defender_7.exe
C:\keybrdef_7.exe
c:\windows\system32\taskmgn.exe

C:\WINDOWS\system32\win32hp.dll
C:\WINDOWS\system32\xeymi.dll
C:\windows\system32\_zskdmwinzmxbgfhbvtav
C:\windows\system32\updwebmin.exe
C:\WINDOWS\system32\wfxqhv.exe

C:\Documents and Settings\Marc\Local Settings\Application Data\b2f06c1e.exe

bnui.exe
scanSYS.exe
<– These 2 you will have to search for.

Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.
Ken, I followed your instructions, and when the computer rebooted, it got caught up in a rebooting loop. After the Windows XP logo appears, the screen switches to the GUI for Windows, and at that moment, the machine reboots. I will attempt to have it boot in safe mode. I have another computer in the other room (the one I'm on now), so I will be comtinuously watching this thread. Please let me know if rebooting in safe mode is not ideal. –Marc
Marc, I need to see the HJT log in normal mode but if you cant boot to it, safemode will do right now. I also need to see the log from the Wareout fix. Ken :D
Ken,

I followed your instrctions, and here are my logs.


Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

»»»»» Search by size and names…
* csr.exe C:\WINDOWS\System32\CSPUY.EXE

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
C:\WINDOWS\SYSTEM32\CSPUY.EXE 51,237 2006-06-12
C:\WINDOWS\SYSTEM32\DMIRD.EXE 44,113 2004-08-04
Other suspects
Directory of C:\WINDOWS\system32


————————————-


Logfile of HijackThis v1.99.1
Scan saved at 10:40:47 AM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [sound64] FLKPT.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [SysTray] c:\Program Files\kunemwse.exe
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.5\THGuard.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105729392280
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Hello Mark,

Open HJT Scan Only and remove these entries.

O4 - HKLM\..\Run: [sound64] FLKPT.exe
O4 - HKLM\..\Run: [SysTray] c:\Program Files\kunemwse.exe
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe


In Safemode , look for and delete the following files.


C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\System32\CSPUY.EXE
C:\WINDOWS\SYSTEM32\DMIRD.EXE

c:\Program Files\kunemwse.exe
c:\windows\system32\_zskdmwinzmxbgfhbvtav


FLKPT.exe
<– This one could be in C:, C:\ windows or C:\ windows\system32



Lets run a system cleaner


This will by default install the Yahoo Toolbar, you can remove it via the Add-Remove Programs in the Control Panel if you wish.
Download and Install CCleaner
* Click on Run Cleaner
Tutorial for CCleaner




Click Start>Run, type in sfc /scannow, hit Enter.
Note: there is a space between sfc and /scannow
This should replace any corrupted/missing system files and will hopefully fix things. You may need your XP disc in your CD drive for this.


Post a new HJT log please
Ken,

I did as you asked. here is the most current HJ log. FYI, I was not required to use the Win XP CD when running the sfc command. Also, not all of the files you told me to manually remove were there.

–Marc



Logfile of HijackThis v1.99.1
Scan saved at 12:50:55 PM, on 7/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] C:\Program Files\TrojanHunter 4.5\THGuard.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105729392280
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/bejeweled…aploader_v6.cab
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
Marc,

Its imperative that you boot normally, you cant spend the rest of your computing days in Safemode. Also running HJT and posting a log in Safemode is not showing me the entire picture.

Let me ask you this..

* How old is your system? Most times when you get reboots it points to a power supply failure. This could possibly be a hardware issue.


You have both Trojan Hunter and Ewido installed, you need to open those programs and look for the preference or tools tab and disable the Background Guard feature on both programs, they may be stopping part of the fix.

Open HJT Scan Only and try removing these again.

This one is not malware itself but installs on your system without your knowledge or consent, I suggest you remove it via the the Add-Remove programs in the Control Panel.
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe

O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe

O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://www.shockwave.com/content/bejeweled…aploader_v6.cab



Run Ewido in Safemode and make sure you save the report and paste into your next reply.


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:

* Lauch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
* Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
* Ewido will now begin the scanning process, be patient this may take a little time.
* Once the scan is complete do the following:
* If you have any infections you will prompted, then select Apply all actions
* Next select the Reports icon at the top.
* Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
*** make sure to remember where you saved that file, this is important
* Close Ewido




Lets run this quick scan that may pick up if something is hidden and not showing up on your log.

Download and Save Blacklight to your desktop:

Double-click blbeta.exe then accept the agreement, click > scan then > next

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"



So….let me see the Ewido report, the report from Blacklight and a new HJT log ( hopefully in Normal mode )

Ken :D
Ken, Nor do I want to spend my days in safe mode. I would boot normally if it would let me. I am running an eMachines with an Athlon +2800, the machine is 3 or 4 years old. I rarely reboot, and needed to when I started seeing symptoms of a virus. The machine boots properly up to the point of loading the Windows graphics. A blue screen (not THE blue screen), the same color of my background pops up, and the machine reboots before the menu bar or any icons load. I am just worried that if the virus is causing this reboot, that it is reloading all of the corrupted files on the reboot. I will process your last post and post my results asap. –Marc
Blacklight is not available, 404 error. I will run the processes you told me up to the blacklight point and wait for your reply. BTW - I am working on a different computer here, and am only using the infected machine to resolve the virus issue, so no other windows or programs are open while I am doing this. Also, both of these entries never go away. It seems they are regenerating themselves after I delete. O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe And I can not find _zskdmwinzmxbgfhbvtav]mun.exe anywhere on my copmputer. –Marc
I located Blacklight.

This is what I did:

1)reboot in normal mode (failed)
2) went into F8 menu on reboot, and selected disable autorestart on system failure, rebooted (failed - Fatal System Error)
3) rebooted with F8 and selected last known good configuration (success - in normal mode)
4)turned off Resident Shield in Ewido and turned off Trojan Hunter Guard
5) Add remove programs, removed Viewpoint manager and viewpoint player
6)ran HJT, tried to remove all entries you specified.
7)ran ewido in safe mode
8)ran blacklight in normal mode
9)ran HJT in normal mode

Here are my reports:

———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 9:14:26 AM 8/1/2006

+ Scan result:



C:\WINDOWS\system32\ghynf.exe -> Adware.SearchAssistant : No action taken.
C:\kbskueek.exe -> Downloader.Agent.aox : No action taken.
C:\Program Files\Internet Explorer\lock.exe -> Downloader.Delf.ang : No action taken.
C:\WINDOWS\system32\win32hlp.exe -> Downloader.Delf.ang : No action taken.
C:\WINDOWS\system32\2204.exe -> Downloader.Small.dib : No action taken.
C:\WINDOWS\system32\tt.exe -> Not-A-Virus.Hoax.Win32.Renos.bw : No action taken.
C:\WINDOWS\system32\nbklhnjb.exe -> Proxy.Wopla.r : No action taken.
C:\Documents and Settings\Marc\Cookies\marc@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Marc\Cookies\marc@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Program Files\Common Files\Microsoft Shared\Web Folders\_ibm00003.exe -> Trojan.Sinowal.ae : No action taken.
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.dll -> Trojan.Sinowal.ae : No action taken.


::Report end

———————————–

08/01/06 09:19:29 [Info]: BlackLight Engine 1.0.42 initialized
08/01/06 09:19:29 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/01/06 09:19:33 [Note]: 7019 4
08/01/06 09:19:33 [Note]: 7005 0
08/01/06 09:19:46 [Note]: 7006 0
08/01/06 09:19:46 [Note]: 7011 608
08/01/06 09:19:46 [Note]: 7026 0
08/01/06 09:19:46 [Note]: 7026 0
08/01/06 09:19:52 [Note]: FSRAW library version 1.7.1019
08/01/06 09:29:46 [Note]: 7007 0


————————————–

Logfile of HijackThis v1.99.1
Scan saved at 9:31:08 AM, on 8/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105729392280
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A58B082B-959A-4EC5-BDA7-BD97938CACB8}: NameServer = 85.255.116.162,85.255.112.111
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
AHHHHH…now were getting someplace :D



85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine

You have a Wareout infection that was not showing up on your log in Safemode, your computer was hijacked by the not so nice folks in the Ukraine, also you should have followed my instructions for Ewido and had it remove or qurarantine those bad files.


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, then make sure "Run fixit" is checked and click Finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.

When your system reboots, follow the prompts. Afterwards, HijackThis will launch. Please click Scan, and check the following items:


O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe

O17 - HKLM\System\CCS\Services\Tcpip\..\{A58B082B-959A-4EC5-BDA7-BD97938CACB8}: NameServer = 85.255.116.162,85.255.112.111


Click Fix Checked.
Close HijackThis, and click OK to proceed.

At the end of the fix, you may need to restart your computer again.


Boot into Safemode, right click on Start….Then click on Explore and navigate to the follow files and deletet them.

C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe

C:\kbskueek.exe


C:\WINDOWS\system32\2204.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\system32\nbklhnjb.exe
C:\WINDOWS\system32\tt.exe
C:\WINDOWS\system32\win32hlp.exe

Finally, please post the contents of the logfile C:\fixwareout\report.txt, along with a new HijackThis log.


Ken :D
Ok,

I did as you said. (I had run Fixwareout before in safe mode.)

I could not locate the following files.

C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.dll
C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00003.exe

C:\kbskueek.exe


C:\WINDOWS\system32\2204.exe (did find 1076.exe, 1252.exe, 1416.exe, 1420.exe, 1612.exe, 1648.exe, 2980.exe, 3788.exe, but did not delete)
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\system32\nbklhnjb.exe
C:\WINDOWS\system32\win32hlp.exe (only found win32k.sys and win32spl.dll, but did not delete)




Fixwareout ver 1.003
Last edited 07/1/2006
Post this report in the forums please

Reg Entries that were deleted
…

Microsoft ® Windows Script Host Version 5.6
Random Runs removed from HKLM
…

PLEASE NOTE, There WILL be LEGIT FILES LISTED. IF YOU ARE UNSURE OF WHAT IT IS LEAVE THEM ALONE.
Example ipsec6.exe is legitimate

»»»»» Search by size and names…

»»»»» Misc files

»»»»» Checking for older varients covered by the Rem3 tool

»»»»»
Search five digit cs, dm and jb files
This WILL/CAN also list Legit Files, Submit them at Virustotal
Other suspects
Directory of C:\WINDOWS\system32

——————————

Logfile of HijackThis v1.99.1
Scan saved at 11:07:02 AM, on 8/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Photodex\ProShowProducer\ScsiAccess.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Winamp\Winampa.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\aim\aim.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Marc\Application Data\Mozilla\Profiles\default\2hqclqv7.slt\prefs.js)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Samsung Common SM] "C:\WINDOWS\Samsung\ComSMMgr\ssmmgr.exe" /autorun
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [eFax 4.1] "C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.5\THGuard.exe"
O4 - HKLM\..\RunServices: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\aim\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ÿ_zsknum]vatvbhfgbxmzniwmdksz_] c:\windows\system32\_zskdmwinzmxbgfhbvtav]mun.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: eFax 4.1.lnk = C:\Program Files\eFax Messenger 4.1\J2GTray.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\aim\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1105729392280
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {B1826A9F-4AA0-4510-BA77-9013E74E4B9B} - http://www.trendmicro.com/spyware-scan/as4web.cab
O16 - DPF: {CB50428B-657F-47DF-9B32-671F82AA73F7} (Photodex Presenter AX control) - http://www.photodex.com/pxplay.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI