I believe there are some hidden hijacks on my aunt's computer. I've scanned with spybot and ad-aware and it has removed WinAntivirus, etc. But I still can't scan on antivirus.com. Here's my log. Thanks for the help.
Logfile of HijackThis v1.99.1
Scan saved at 10:05:47 AM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DosSpecFolder Object - {1AE6D7D5-0C28-4DB6-9FD1-33B870A4C5F2} - C:\WINDOWS\System32\gebyx.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O20 - Winlogon Notify: gebyx - C:\WINDOWS\System32\gebyx.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe
Download
VundoFix.exe to your desktop from here:
VundoFix.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
1. Double-click
VundoFix.exe to run it.
2. Click the
Scan for Vundo button.
3. Once it's done scanning, click the
Remove Vundo button.
4. If it doesn't find anything, in the main program window, choose "
Add more files? ".
Type the next line in the box
EXACTLY AS SHOWN :
C:\WINDOWS\System32\gebyx.dll
Click
Close Window , then
Remove Vundo .
5. You will receive a prompt asking if you want to remove the files, click
YES .
6. Once you click yes, your desktop will go blank as it starts removing Vundo.
7. When completed, it will prompt that it will shutdown your computer, click
OK .
8. Turn your computer back on.
Post a new HijackThis! log , along with the contents of this file:
C:\vundofix.txt
into this thread .
Thanks for your help.
Here's my new hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 11:29:02 AM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\RAMASST.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: DosSpecFolder Object - {1AE6D7D5-0C28-4DB6-9FD1-33B870A4C5F2} - C:\WINDOWS\System32\gebyx.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe
Here is my VundoFix Log:
VundoFix V6.1.2
Checking Java version…
Scan started at 10:43:27 AM 8/29/2006
Listing files found while scanning….
C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\xybeg.ini
C:\WINDOWS\system32\xybeg.bak1
C:\WINDOWS\system32\xybeg.bak2
C:\WINDOWS\system32\xybeg.ini2
C:\WINDOWS\system32\xybeg.tmp
C:\WINDOWS\system32\campppid.exe
C:\WINDOWS\system32\ciagqwgm.exe
C:\WINDOWS\system32\kaqpmlqv.exe
C:\WINDOWS\system32\pbjpotwp.exe
C:\WINDOWS\system32\xpenbxrh.exe
C:\WINDOWS\system32\xygmoehc.exe
C:\WINDOWS\system32\yiypdljy.exe
Beginning removal…
Attempting to delete C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\gebyx.dll Could not be deleted.
Attempting to delete C:\WINDOWS\system32\xybeg.ini
C:\WINDOWS\system32\xybeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\xybeg.bak1
C:\WINDOWS\system32\xybeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xybeg.bak2
C:\WINDOWS\system32\xybeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xybeg.ini2
C:\WINDOWS\system32\xybeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xybeg.tmp
C:\WINDOWS\system32\xybeg.tmp Has been deleted!
Attempting to delete C:\WINDOWS\system32\campppid.exe
C:\WINDOWS\system32\campppid.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\ciagqwgm.exe
C:\WINDOWS\system32\ciagqwgm.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\kaqpmlqv.exe
C:\WINDOWS\system32\kaqpmlqv.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\pbjpotwp.exe
C:\WINDOWS\system32\pbjpotwp.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\xpenbxrh.exe
C:\WINDOWS\system32\xpenbxrh.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\xygmoehc.exe
C:\WINDOWS\system32\xygmoehc.exe Has been deleted!
Attempting to delete C:\WINDOWS\system32\yiypdljy.exe
C:\WINDOWS\system32\yiypdljy.exe Has been deleted!
Performing Repairs to the registry.
Done!
VundoFix V6.1.2
Checking Java version…
Scan started at 11:06:32 AM 8/29/2006
Listing files found while scanning….
C:\WINDOWS\system32\gebyx.dll
Beginning removal…
Attempting to delete C:\WINDOWS\system32\gebyx.dll
C:\WINDOWS\system32\gebyx.dll Has been deleted!
Performing Repairs to the registry.
Done!
Disable teatimer .
on the Teatimer icon in the system tray and "exit".
Then do this:
Disable Teatimer
After we have cleaned your system, please be sure to reverse this process, and re-enable Teatimer.
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "
Do a systen scan only ".
Then "check" the box to the left of these item(s):
O2 - BHO: DosSpecFolder Object - {1AE6D7D5-0C28-4DB6-9FD1-33B870A4C5F2} - C:\WINDOWS\System32\gebyx.dll (file missing)
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O15 - Trusted Zone: http://locator.cdn.imageservr.com
Then click "
Fix checked ".
Reboot and "copy/paste" a new HijackThis log file
into this thread .
Things running better now?
Securing Your PC After An Attack
Here's my new log:
Logfile of HijackThis v1.99.1
Scan saved at 1:20:40 PM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\WINDOWS\system32\wscntfy.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe
Things are running better now. I haven't seen any more WinAntiVirus pop-ups. And it seems to load up faster, but still not really fast. She may have too many programs running at start up though.
Looks good.
Thank you for choosing TomCoyote for your malware removal solutions.
M68
Securing Your PC After An Attack
Thanks for all your help. I tried to do a housecall scan on antivirus.com and when I press the launch housecall button my browser window is closed. This happens with firefox and IE. Do you think i have some more malware, or do I need to upgrade something or turn something off.
It could be just a setting someplace…..
The only other thing I can think of to check for something that might cause that would be to download/install/run the trial version of Ewido Trojan Scanner…..
You game for that?
If so, here are the directions:
Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Don't run it yet.
Please download, install, and update the NEW free version of Ewido trojan scanner:
When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK . We will fix this in a moment. From the main ewido screen, click on update in the left menu, then click the Start update button. After the update finishes (the status bar at the bottom will display "Update successful") Close Ewido. Boot in "safe" mode Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All . Click the Empty Selected button. Close the program. Run Ewido. Click on the Scanner button in the left menu, then click on Complete System Scan . This scan can take quite a while to run. If ewido finds anything, it will pop up a notification. Select "clean" and check the boxes "Perform action with all infections" and "Create encrypted backup" before clicking on OK. When the scan finishes, click on "Save Report" . This will create a text file. Make sure you know where to find this file again. Boot in normal mode.
Please post the results from
ewido and a new
hijackthis log .
I downloaded ewido, but there was no place for "Additional Options", so I could not uncheck "background guard" and "install scan via context menu". Should I continue with the rest of the instructions, or download another version?
The directions may be a bit out dated.
Please continue.
Ok here are my new logs:
Logfile of HijackThis v1.99.1
Scan saved at 5:50:21 PM, on 8/29/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\System32\DVDRAMSV.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\SAVScan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
c:\toshiba\ivp\swupdate\swupdtmr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\00THotkey.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\TFNF5.exe
C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\TOSHIBA Controls\TFncKy.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\TOSHIBA\IVP\ISM\pinger.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshiba.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\System32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [PadTouch] "C:\Program Files\TOSHIBA\PadTouch\PadExe.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [TFncKy] TFncKy.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\B'SCLI~1\Win2K\BSCLIP.exe
O4 - HKLM\..\Run: [Pinger] C:\TOSHIBA\IVP\ISM\pinger.exe /run
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Swupdtmr - Unknown owner - c:\toshiba\ivp\swupdate\swupdtmr.exe
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 5:05:30 PM 8/29/2006
+ Scan result:
HKU\S-1-5-21-3358472075-22471022-299754906-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : No action taken.
C:\WINDOWS\system32\actskn45.ocx -> Downloader.IstBar : No action taken.
C:\VundoFix Backups\campppid.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\kaqpmlqv.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\xpenbxrh.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\xygmoehc.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\system32\asrrsvcj.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\ywwajrld.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
:mozilla.29:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.185:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.304:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.30:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.31:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.32:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.33:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.34:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.35:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.36:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.37:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.384:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.38:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.39:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.40:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.41:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.42:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.43:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.44:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.45:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.46:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.47:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.48:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.49:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.50:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.51:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.52:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.53:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.54:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.55:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.56:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.63:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.73:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.642:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.643:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.644:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.645:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.646:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.647:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.648:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.649:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.72:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.591:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.592:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.593:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.129:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.611:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.697:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.121:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.122:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.157:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.158:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.159:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.160:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.161:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.162:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.163:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.164:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.165:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.166:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.167:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.168:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.169:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.170:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Esomniture : No action taken.
:mozilla.70:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.103:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.193:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Findwhat : No action taken.
:mozilla.673:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.674:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.675:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.640:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Masterstats : No action taken.
:mozilla.676:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.677:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.378:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.379:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.394:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.74:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.75:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.76:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.77:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.400:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.401:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.403:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.404:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.405:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.406:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.407:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.678:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.679:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.680:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.681:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.682:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.465:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.466:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.467:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.468:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.180:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.181:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.182:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.183:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.184:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.120:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.482:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.483:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.484:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.485:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.71:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.202:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.203:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.685:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.496:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.497:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.498:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.499:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.500:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.501:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.502:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.503:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.504:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.505:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.506:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.507:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.508:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.509:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.510:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.511:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.512:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.513:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.514:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.515:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.516:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.517:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.518:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.519:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.520:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.521:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.530:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.531:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.537:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.538:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.539:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.540:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.541:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.542:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.543:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.544:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.545:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.547:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.459:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.460:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.461:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.462:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.463:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.597:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.598:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.599:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.600:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.601:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.602:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.603:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.62:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.594:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.595:C:\Documents and Settings\Tina Massengale\Application Data\Mozilla\Firefox\Profiles\3dlbzyji.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\VundoFix Backups\ciagqwgm.exe -> Trojan.Small.ju : No action taken.
C:\VundoFix Backups\pbjpotwp.exe -> Trojan.Small.ju : No action taken.
C:\VundoFix Backups\yiypdljy.exe -> Trojan.Small.ju : No action taken.
::Report end
It says no Action taken, but I think it ran the report before I deleted the files. It quarantined all the trojans. And deleted the cookies.
Delete these files (if still present):
C:\WINDOWS\system32\actskn45.ocx -> Downloader.IstBar : No action taken.
C:\VundoFix Backups\campppid.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\kaqpmlqv.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\xpenbxrh.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\VundoFix Backups\xygmoehc.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\system32\asrrsvcj.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\ywwajrld.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\VundoFix Backups\ciagqwgm.exe -> Trojan.Small.ju : No action taken.
C:\VundoFix Backups\pbjpotwp.exe -> Trojan.Small.ju : No action taken.
C:\VundoFix Backups\yiypdljy.exe -> Trojan.Small.ju : No action taken.
I don't suppose your online virus scan problem is fixed?
Nope, It still doesn't work. I'm guessing that it is some kind of setting. Thank you again for all of your help. I think all the malware is gone now. You can consider this topic closed.