This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Obviously not protected...

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

This computer has been clean for a LONG time until a few days ago. It started slowing down and I figured that it was because I had a lot of stuff running and I only have 256MB of ram. Last night, my hard drive started going crazy with processing info and the next thing I know 2 files were randomly dropped on my desktop. One was a file named "02.exe" which didn't register through AVG as a virus, but the other, named "01.exe" instantly came up as "Trojan Horse Dropper VB.3.AK". IIRC, a dropper is from an attack right? If that's the case, then someone blew past my ZA, and that's not cool. Here's my logfile. I'm pretty fluent with this stuff so don't worry about confusing me. I did notice a few files that are spyware/malware and the update.exe has me a bit worried. At the time I found the dropper, I also had something called "activate.exe" running as well. I've done a search on hidden folders and haven't found it, so I'm guessing it was deleted? There is also some junk related to Symantec and Yahoo Messenger which I no longer have. I figure it's safe to delete the yahoo, but what about the Symantec stuff? Logfile of HijackThis v1.99.1 Scan saved at 12:13:09 PM, on 12/11/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\{D8146EBF-0958-1033-1202-030512200001}\Update.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O2 - BHO: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{38146EBF-0958-1033-1202-030512200001}\888.dll O3 - Toolbar: 888Bar - {C004DEC2-2623-438e-9CA2-C9043AB28508} - C:\Program Files\Common Files\{38146EBF-0958-1033-1202-030512200001}\888.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Sygate Personal Firewall (SmcService) - Unknown owner - C:\Program Files\Sygate\SPF\smc.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hello!
I go by FencerGirl. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.

Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Finally, please reply to this thread. Do not start a new topic.

It may take me a while to reply to you as all of my fixes are being checked by experts to ensure that you are getting a good fix. And remember, like you I have a real life, so I may not be at my computer when you are!

FencerGirl
Hello FencerGirl, I know that nothing has been suggested yet, but I looked at the Self Help post and went ahead and downloaded AVG's AntiSpyware and ran a scan on it. After almost an hour, here are the results of the scan… ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 2:27:33 PM 12/11/2006 + Scan result: C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\{2F93C55A-4040-42F6-B5A2-73569EE5C8DC}.exe -> Adware.Msnagent : Cleaned with backup (quarantined). C:\Program Files\Common Files\{38146EBF-0958-1033-1202-030512200001}\Activate.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\Program Files\Common Files\{38146EBF-0958-1033-1202-030512200001}\Uninstall.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\Program Files\Common Files\{D8146EBF-0958-1033-1202-030512200001}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\Program Files\Common Files\{D8146EBF-0958-1033-1202-030512200001}\system.dll -> Adware.Softomate : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038801.exe -> Adware.Softomate : Cleaned with backup (quarantined). [2752] C:\Program Files\Common Files\{D8146EBF-0958-1033-1202-030512200001}\Update.exe -> Adware.Softomate : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\MediaGatewayX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP440\A0034650.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP440\A0034666.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP445\A0035102.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP456\A0035626.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP460\A0035890.exe -> Downloader.Agent.awf : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{daa873d4-958c-453c-81ca-3fe6f3676a87} -> Downloader.Fugif : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32:quaa.dll -> Downloader.Small.azk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038782.exe -> Downloader.Small.cpt : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\this folder has odd files\lcqyxrwj.exe -> Downloader.Small.dam : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\this folder has odd files\wbdcjklg.exe -> Downloader.Small.dam : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\this folder has odd files\qqpnwpms.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Addcontrol : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@bfast[1].txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@centrport[1].txt -> TrackingCookie.Centrport : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@centrport[1].txt -> TrackingCookie.Centrport : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Onestat : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][1].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Popularix : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@yadro[2].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Temp Acct\Cookies\temp acct@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\SYSTEM32\this folder has odd files\zhopaizdupla.exe -> Trojan.Small : Cleaned with backup (quarantined). C:\Documents and Settings\System Administrator\My Documents\Software\(software) – MP3 Splitter[with crack]works for ablums too[awsome].zip/FUNNY.exe -> Worm.Blaxe : Cleaned with backup (quarantined). ::Report end
Hello Downshift,
You appear to be infected with Downloader.Agent.awf which overwrites legitimate files on your computer.
To help us find which files have been overwritten, please download noahdfear's FindAWF to your desktop and run it. The output will be saved to awf.txt.

If a DOS window does not stay open throughout the search (approx a minute) you need to change how the program runs. Heres how:

1. Locate the file
2. Right-click and select Properties
3. Select Compatibility and select Run this program in compatibility mode for: Windows 98/Windows ME and click OK.
4. The tool should now work.

Please post back with the contents of awf.txt and a new HijackThis log.

Thanks,
FencerGirl
Wow… This is NOT cool. This explains so much. Like for instance, why AVG first recognized TeaTimer and my old Sygate firewall as spyware. I never could figure that one out but now I understand it. Here's the results… 26450 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\QUICKT~1\BAK 04/23/2006 07:21 PM 155,648 qttask.exe 1 File(s) 155,648 bytes Directory of C:\PROGRA~1\SPYBOT~1\BAK 05/12/2004 01:03 AM 1,038,336 TeaTimer.exe 1 File(s) 1,038,336 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/04/2004 05:00 AM 15,360 ctfmon.exe 10/02/2003 01:19 PM 118,784 hkcmd.exe 2 File(s) 134,144 bytes Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK 09/07/2006 11:43 AM 369,664 avgcc.exe 1 File(s) 369,664 bytes Directory of C:\PROGRA~1\SYGATE\SPF\BAK 10/15/2004 07:40 PM 2,577,632 smc.exe 1 File(s) 2,577,632 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 282624 Dec 5 2006 "C:\Program Files\QuickTime\qttask.exe" 155648 Apr 23 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 1443992 Nov 24 2006 "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" 1038336 May 12 2004 "C:\Program Files\Spybot - Search & Destroy\bak\TeaTimer.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 118784 Oct 2 2003 "C:\DRIVERS\VIDEO\ONBOARD\HKCMD.EXE" 118784 Oct 2 2003 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 118784 Oct 2 2003 "C:\Documents and Settings\System Administrator\My Documents\DRIVERS\VIDEO\ONBOARD\HKCMD.EXE" 406016 Oct 19 2006 "C:\Program Files\Grisoft\AVG Free\avgcc.exe" 369664 Sep 7 2006 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe" 2577632 Oct 15 2004 "C:\Program Files\Sygate\SPF\bak\smc.exe" end of report ________________________________________________________________________________ Logfile of HijackThis v1.99.1 Scan saved at 12:15:04 PM, on 12/13/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi Downshift,
Could you please post the top part of your AWF log?
It should look something like this

Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~

25600 "C:\Documents and Settings\user\Local Settings\Temp\~WRS2976.tmp"


25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



26450 byte files found
~~~~~~~~~~~~~

Even if the top portion is blank, this will be of use in analyzing your log.
Thanks!
FencerGirl
Sorry, I had no idea I only copied part of it… Here's the whole log over again so I don't miss anything. Find AWF report by noahdfear ©2006 21504 byte files found ~~~~~~~~~~~~~ 21504 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 25600 byte files found ~~~~~~~~~~~~~ 25600 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ 26450 byte files found ~~~~~~~~~~~~~ 26450 byte files sorted with strings ~~~~~~~~~~~~~~~~~~~~~ bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\QUICKT~1\BAK 04/23/2006 07:21 PM 155,648 qttask.exe 1 File(s) 155,648 bytes Directory of C:\PROGRA~1\SPYBOT~1\BAK 05/12/2004 01:03 AM 1,038,336 TeaTimer.exe 1 File(s) 1,038,336 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/04/2004 05:00 AM 15,360 ctfmon.exe 10/02/2003 01:19 PM 118,784 hkcmd.exe 2 File(s) 134,144 bytes Directory of C:\PROGRA~1\GRISOFT\AVGFRE~1\BAK 09/07/2006 11:43 AM 369,664 avgcc.exe 1 File(s) 369,664 bytes Directory of C:\PROGRA~1\SYGATE\SPF\BAK 10/15/2004 07:40 PM 2,577,632 smc.exe 1 File(s) 2,577,632 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 282624 Dec 5 2006 "C:\Program Files\QuickTime\qttask.exe" 155648 Apr 23 2006 "C:\Program Files\QuickTime\bak\qttask.exe" 1443992 Nov 24 2006 "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" 1038336 May 12 2004 "C:\Program Files\Spybot - Search & Destroy\bak\TeaTimer.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 118784 Oct 2 2003 "C:\DRIVERS\VIDEO\ONBOARD\HKCMD.EXE" 118784 Oct 2 2003 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 118784 Oct 2 2003 "C:\Documents and Settings\System Administrator\My Documents\DRIVERS\VIDEO\ONBOARD\HKCMD.EXE" 406016 Oct 19 2006 "C:\Program Files\Grisoft\AVG Free\avgcc.exe" 369664 Sep 7 2006 "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe" 2577632 Oct 15 2004 "C:\Program Files\Sygate\SPF\bak\smc.exe" end of report
Hi Downshift,
You'll want to print out these instructions or save a copy to notepad as we will be in safe mode for a portion of this fix.

Copy the follwing code and paste it into a new notepad document.
@ECHO OFF

if exist "C:\Program Files\QuickTime\qttask.exe" del /q "C:\Program Files\QuickTime\qttask.exe"
copy "C:\Program Files\QuickTime\bak\qttask.exe" "C:\Program Files\QuickTime"

if exist "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" del /q "C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe"
copy "C:\Program Files\Spybot - Search & Destroy\bak\TeaTimer.exe" "C:\Program Files\Spybot - Search & Destroy"

if exist "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" copy "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" "C:\WINDOWS\SYSTEM32"

if exist "C:\Program Files\Grisoft\AVG Free\avgcc.exe" del /q "C:\Program Files\Grisoft\AVG Free\avgcc.exe"
copy "C:\Program Files\Grisoft\AVG Free\bak\avgcc.exe" "C:\Program Files\Grisoft\AVG Free"

if exist "C:\Program Files\Sygate\SPF\bak\smc.exe" copy "C:\Program Files\Sygate\SPF\bak\smc.exe" "C:\Program Files\Sygate\SPF"

Save it to your desktop as replace.bat. Save it as File Type All Files.

Boot into Safe Mode by restarting your computer, then contiunally tapping F8 until a menu appears. Use your up arrow key to highlight Safe Mode, then hit enter.

Once in SafeMode, double click replace.bat to run the batch file.

Now reboot back into safe mode and run AVG Anti-Spyware again to be sure we got everything.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

Once you're back in Normal Mode, please run these two files.
To execute these files: in Explorer - right-click the link
Select Install from the Menu.
Note: you will not see any onscreen action.
http://www.mvps.org/winhelp2002/DelDomains.inf
http://www.mvps.org/winhelp2002/ResetProtocolDefaults.reg

Please post back with your AVG Anti-Spyware log and a new HijackThis log.
As soon as I post this I'm going to turn off the System Restore and turn it back on so that the extra infected items are removed. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 12:38:46 PM 12/14/2006 + Scan result: C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038837.dll -> Adware.Aws : Ignored. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038838.exe -> Adware.Msnagent : Ignored. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038833.exe -> Adware.Softomate : Ignored. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038834.exe -> Adware.Softomate : Ignored. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038835.exe -> Adware.Softomate : Ignored. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038836.dll -> Adware.Softomate : Ignored. C:\WINDOWS\SYSTEM32:quaa.dll -> Downloader.Small.azk : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038829.exe -> Downloader.Small.dam : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038830.exe -> Downloader.Small.dam : Cleaned with backup (quarantined). C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038831.exe -> Downloader.Small.dkt : Cleaned with backup (quarantined). C:\Documents and Settings\System Administrator\Cookies\system administrator@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@com[2].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][2].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system administrator@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\System Administrator\Cookies\system [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP493\A0038832.exe -> Trojan.Small : Cleaned with backup (quarantined). ::Report end __________________________________________________________________________________ Logfile of HijackThis v1.99.1 Scan saved at 12:49:36 PM, on 12/14/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\hkcmd.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\svchost.exe C:\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} - O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Hi Downshift,
Your HijackThis log is looking better. There are still a few more things to do, though.

Open HijackThis and choose "Open the Misc Tools section" then choose "Open ADS Spy".
Tell it to Scan then Save Log.
Your log will be stored in your HijackThis folder. DO NOT remove anything yet.

There is evidence that you have run Spy-Bot's TeaTimer in the past. We need to clean out its system snapshots. This needs to be done while TeaTimer is off, so DO NOT re-enable it at this time.
Copy the following code and paste it into a new notepad document.
@echo off
::Edited 7:05 PM 9/15/2006
if [%OS%]==[Windows_NT] set path=%windir%;%SystemRoot%\system32

VER|find "Windows 2000">NUL
IF NOT ERRORLEVEL 1 GOTO NT

VER|find "Windows XP">NUL
IF NOT ERRORLEVEL 1 GOTO NT

VER|find "Windows 95">NUL
IF NOT ERRORLEVEL 1 GOTO win

VER|find "Windows 98">NUL
IF NOT ERRORLEVEL 1 GOTO win

VER|find "Windows Millennium">NUL
IF NOT ERRORLEVEL 1 GOTO winme

VER|find "Windows 2003">NUL
IF NOT ERRORLEVEL 1 GOTO NT

echo Unsupported Version
goto last

:NT
Echo.
Echo SpyBot and Tea Timer must be closed!! & pause
Echo.
CScript /?>nul 2>&1 && echo/Check OK>log1.txt || echo/Windows Script Host access is disabled on this machine. >log2.txt
if exist log1.txt goto continue

echo Post this in the forum please.>>log2.txt & start notepad log2.txt & exit 

:continue
if exist log1.txt del log1.txt

echo.Option Explicit>GetPaths.vbs
echo.>>GetPaths.vbs
echo Dim Shell>>GetPaths.vbs
echo Dim KeyPath>>GetPaths.vbs
echo Dim ObjFileSystem>>GetPaths.vbs
echo Dim ObjOutputFile>>GetPaths.vbs
echo Dim ObjRegExp>>GetPaths.vbs
echo Dim File>>GetPaths.vbs
echo Dim TmpVar>>GetPaths.vbs
echo Dim Var>>GetPaths.vbs
echo Dim Accent>>GetPaths.vbs

echo.>>GetPaths.vbs
echo KeyPath = "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo File = "SetPaths.bat">>GetPaths.vbs
echo.>>GetPaths.vbs
echo Set Shell = WScript.CreateObject("WScript.Shell")>>GetPaths.vbs
echo Set ObjFileSystem = CreateObject("Scripting.fileSystemObject")>>GetPaths.vbs
echo Set ObjOutputFile = ObjFileSystem.CreateTextFile(File, TRUE)>>GetPaths.vbs
echo Set ObjRegExp = New RegExp>>GetPaths.vbs
echo.>>GetPaths.vbs

echo Function ShortFileName(Path)>>GetPaths.vbs
echo Dim f>>GetPaths.vbs
echo Set f = ObjFileSystem.GetFolder(Path)>>GetPaths.vbs
echo ShortFileName = f.ShortPath>>GetPaths.vbs
echo End Function>>GetPaths.vbs

echo Function Accents(Str)>>GetPaths.vbs
echo ObjRegExp.Pattern = "[^a-zA-Z_0-9\\: ]">>GetPaths.vbs
echo ObjRegExp.IgnoreCase = True>>GetPaths.vbs
echo ObjRegExp.Global = True>>GetPaths.vbs
echo Accents = ObjRegExp.Replace(Str, "?")>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo.>>GetPaths.vbs

echo TmpVar = Shell.RegRead (KeyPath ^& "AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set AppData=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo KeyPath = "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath ^& "Common AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set CommonAppData=" ^& TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo ObjOutputFile.Close>>GetPaths.vbs
echo Set objFileSystem = Nothing>>GetPaths.vbs
echo Set Shell = Nothing>>GetPaths.vbs
echo Set ObjRegExp = nothing>>GetPaths.vbs
echo.>>GetPaths.vbs


cscript //I //nologo GetPaths.vbs
del GetPaths.vbs
Call SetPaths.bat
del SetPaths.bat


(@echo off
del /q %CommonAppData%\spybot~1\Snapshots\*.*
del /q %CommonAppData%\spybot~1\excludes\RegKeyWhite.sbe
del /q %CommonAppData%\spybot~1\excludes\RegKeyblack.sbe
del /q %CommonAppData%\spybot~1\excludes\ProcWhite.sbe
del /q %CommonAppData%\spybot~1\excludes\ProcBlack.sbe
del /q %CommonAppData%\spybot~1\excludes\UpdateDL.sbe
del /q %CommonAppData%\spybot~1\logs\resident.log
)>NUL 2>&1
Echo.
Echo Finished & pause & exit

:win
Echo.
Echo SpyBot and Tea Timer must be closed!! 
pause
echo.Option Explicit>GetPaths.vbs
echo.>>GetPaths.vbs
echo Dim Shell>>GetPaths.vbs
echo Dim KeyPath>>GetPaths.vbs
echo Dim ObjFileSystem>>GetPaths.vbs
echo Dim ObjOutputFile>>GetPaths.vbs
echo Dim ObjRegExp>>GetPaths.vbs
echo Dim File>>GetPaths.vbs
echo Dim TmpVar>>GetPaths.vbs
echo Dim Var>>GetPaths.vbs
echo Dim Accent>>GetPaths.vbs

echo.>>GetPaths.vbs
echo KeyPath = "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo File = "SetPaths.bat">>GetPaths.vbs
echo.>>GetPaths.vbs
echo Set Shell = WScript.CreateObject("WScript.Shell")>>GetPaths.vbs
echo Set ObjFileSystem = CreateObject("Scripting.fileSystemObject")>>GetPaths.vbs
echo Set ObjOutputFile = ObjFileSystem.CreateTextFile(File, TRUE)>>GetPaths.vbs
echo Set ObjRegExp = New RegExp>>GetPaths.vbs
echo.>>GetPaths.vbs

echo Function ShortFileName(Path)>>GetPaths.vbs
echo Dim f>>GetPaths.vbs
echo Set f = ObjFileSystem.GetFolder(Path)>>GetPaths.vbs
echo ShortFileName = f.ShortPath>>GetPaths.vbs
echo End Function>>GetPaths.vbs

echo Function Accents(Str)>>GetPaths.vbs
echo ObjRegExp.Pattern = "[^a-zA-Z_0-9\\: ]">>GetPaths.vbs
echo ObjRegExp.IgnoreCase = True>>GetPaths.vbs
echo ObjRegExp.Global = True>>GetPaths.vbs
echo Accents = ObjRegExp.Replace(Str, "?")>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo.>>GetPaths.vbs

echo TmpVar = Shell.RegRead (KeyPath & "AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set AppData=" & TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo KeyPath = "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath & "Common AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set CommonAppData=" & TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo ObjOutputFile.Close>>GetPaths.vbs
echo Set objFileSystem = Nothing>>GetPaths.vbs
echo Set Shell = Nothing>>GetPaths.vbs
echo Set ObjRegExp = nothing>>GetPaths.vbs
echo.>>GetPaths.vbs


cscript //I //nologo GetPaths.vbs
del GetPaths.vbs
Call SetPaths.bat
del SetPaths.bat




deltree /y %AppData%\spybot~1\snapshots\*.*
del %AppData%\spybot~1\logs\resident.log
del %AppData%\spybot~1\excludes\ProcBlack.sbe
del %AppData%\spybot~1\excludes\ProcWhite.sbe
del %AppData%\spybot~1\excludes\RegKeyWhite.sbe
del %AppData%\spybot~1\excludes\RegKeyBlack.sbe
del %AppData%\spybot~1\excludes\UpdateDL.sbe
cls
Echo.
Echo Finished
exit



:winme
Echo.
Echo SpyBot and Tea Timer must be closed!! 
pause
echo.Option Explicit>GetPaths.vbs
echo.>>GetPaths.vbs
echo Dim Shell>>GetPaths.vbs
echo Dim KeyPath>>GetPaths.vbs
echo Dim ObjFileSystem>>GetPaths.vbs
echo Dim ObjOutputFile>>GetPaths.vbs
echo Dim ObjRegExp>>GetPaths.vbs
echo Dim File>>GetPaths.vbs
echo Dim TmpVar>>GetPaths.vbs
echo Dim Var>>GetPaths.vbs
echo Dim Accent>>GetPaths.vbs

echo.>>GetPaths.vbs
echo KeyPath = "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo File = "SetPaths.bat">>GetPaths.vbs
echo.>>GetPaths.vbs
echo Set Shell = WScript.CreateObject("WScript.Shell")>>GetPaths.vbs
echo Set ObjFileSystem = CreateObject("Scripting.fileSystemObject")>>GetPaths.vbs
echo Set ObjOutputFile = ObjFileSystem.CreateTextFile(File, TRUE)>>GetPaths.vbs
echo Set ObjRegExp = New RegExp>>GetPaths.vbs
echo.>>GetPaths.vbs

echo Function ShortFileName(Path)>>GetPaths.vbs
echo Dim f>>GetPaths.vbs
echo Set f = ObjFileSystem.GetFolder(Path)>>GetPaths.vbs
echo ShortFileName = f.ShortPath>>GetPaths.vbs
echo End Function>>GetPaths.vbs

echo Function Accents(Str)>>GetPaths.vbs
echo ObjRegExp.Pattern = "[^a-zA-Z_0-9\\: ]">>GetPaths.vbs
echo ObjRegExp.IgnoreCase = True>>GetPaths.vbs
echo ObjRegExp.Global = True>>GetPaths.vbs
echo Accents = ObjRegExp.Replace(Str, "?")>>GetPaths.vbs
echo End Function>>GetPaths.vbs
echo.>>GetPaths.vbs

echo TmpVar = Shell.RegRead (KeyPath & "AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set AppData=" & TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo KeyPath = "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\">>GetPaths.vbs
echo TmpVar = Shell.RegRead (KeyPath & "Common AppData")>>GetPaths.vbs
echo TmpVar = ShortFileName(TmpVar)>>GetPaths.vbs
echo Var = "Set CommonAppData=" & TmpVar>>GetPaths.vbs
echo ObjOutputFile.WriteLine(Var)>>GetPaths.vbs
echo ObjOutputFile.Close>>GetPaths.vbs
echo Set objFileSystem = Nothing>>GetPaths.vbs
echo Set Shell = Nothing>>GetPaths.vbs
echo Set ObjRegExp = nothing>>GetPaths.vbs
echo.>>GetPaths.vbs


cscript //I //nologo GetPaths.vbs
del GetPaths.vbs
Call SetPaths.bat
del SetPaths.bat


del /y %CommonAppData%\spybot~1\snapshots\*.*
del %CommonAppData%\spybot~1\excludes\UpdateDL.sbe
del %CommonAppData%\spybot~1\excludes\RegKeyWhite.sbe
del %CommonAppData%\spybot~1\excludes\RegKeyblack.sbe
del %CommonAppData%\spybot~1\excludes\ProcWhite.sbe
del %CommonAppData%\spybot~1\excludes\ProcBlack.sbe
del %CommonAppData%\spybot~1\logs\resident.log
cls
Echo.
Echo Finished
exit

:last
echo Press any key to terminate,..
pause
exit
Save it to your desktop as CleanTea.bat. Save it as File Type All Files.
Double click CleanTea.bat to run the batch file.

Next, scan with HijackThis and check the following if present.

O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} -
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} -
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} -
O20 - AppInit_DLLs:

CLOSE ALL OTHER WINDOWS and select "Fixed Checked".

Finally, browse to C:\WINNT\Downloaded Program Files\ and delete the following files if present:

{166B1BCA-3F9C-11CF-8075-444553540000}
{4F1E5B1A-2A80-42CA-8532-2D05CB959537}
{B38870E4-7ECB-40DA-8C6A-595F0A5519FF}

Please post back with a new HijackThis log and the results of your ADS Spy scan.

Thanks!
FencerGirl
Due to inactivity, his topic is now closed If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI