This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Please inspect

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Recently I was blind-linked to DriveCleaner's insidious site, where my browser either froze, or was highjacked. I rebooted to escape, rather than click on any of the (phony?) buttons. Was this the right way to escape their clutches? I don't think anything was installed, and I'm not getting DriveCleaner popups (yet) but a lot of popups for other products have been getting under the radar. Also, my browser periodically won't open, and R-click options frequently don't work. Please check this log for threats, and advise me what to do, if anything. Thank you !

Logfile of HijackThis v1.99.1
Scan saved at 8:35:02 AM, on 3/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6028\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Russ\Desktop\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\PROGRA~1\mcafee\VIRUSS~1\scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6028\SiteAdv.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6028\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6028\SAService.exe
Cygnus :D

Welcome to Tom Coyote .

It looks like you did the right thing and were spared, but to make sure, run this quick scan and post the report.

Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Thank you Ken. Here's the scan result. SmitFraudFix v2.161 Scan done at 2:37:43.96, Fri 03/30/2007 Run from C:\Documents and Settings\Russ\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is FAT32 Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\AGRSMMSG.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\system32\hkcmd.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\Program Files\Microsoft IntelliPoint\ipoint.exe C:\Program Files\SiteAdvisor\6028\SiteAdv.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\QuickTime\qttask.exe C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\SiteAdvisor\6028\SAService.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe C:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Russ »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Russ\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\RUSS\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Intel® PRO/Wireless 2200BG Network Connection - Packet Scheduler Miniport DNS Server Search Order: 10.61.32.1 DNS Server Search Order: 1.1.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{20D2E6B0-3300-4041-A6E0-EEADCD51BFF9}: DhcpNameServer=10.61.32.1 1.1.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{20D2E6B0-3300-4041-A6E0-EEADCD51BFF9}: DhcpNameServer=10.61.32.1 1.1.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{20D2E6B0-3300-4041-A6E0-EEADCD51BFF9}: DhcpNameServer=10.61.32.1 1.1.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=10.61.32.1 1.1.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=10.61.32.1 1.1.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=10.61.32.1 1.1.1.1 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
It looks like you never picked up the Drive Cleaner infection that is part of the Smitfraud family of trojans. :thumbup: How is you system running? Let me know if things are ok and I will post some free programs for you to install to help keep you more secure on the internet.
Hi Ken. Windows is acting screwy and seems unstable, but I can't really put my finger on it yet. Right click still disables after a few hours of browsing with IE… links unresponsive… files/folders behaving strangely etc. I'll need more time to evaluate these irregular glitches. Meanwhile, please post anything you feel may be helpful with regard to browser security. I possess little computer knowledge and even less defenses against attack. Thanks for your time and assistance. :)
Cygnus :D

Before I send you to our other forum for windows issues, run the trial of AVG Anti Spyware, if something bad is on your system and not showing up on your HJT log this program will root it out. Keep in mind that if you don't post the report for me to see, I won't be able to proceed any further so read the instructions and follow them best you can.

Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
Okay Ken, I followed your instructions and ran the AVG scan in safe mode. A number of tracking cookies were detected and cleaned, but no report was shown listing any other threats. However, I did see something about a 'trace' being detected somewhere in documents and settings. Could this be caused by me visiting sites to check my connectivity speed, or should I be worried about a more serious threat? :( Nothing about this trace is shown in the report, only a long list of the cookies, which I doubt you want me to post. Thanks again.

I did see something about a 'trace' being detected somewhere in documents and settings.


Keep in mind that if you don't post the report for me to see, I won't be able to proceed any further so read the instructions and follow them best you can.


This is why I asked to see the log, without me seeing it my hands are tied behind my back.
Sorry Ken.. I may have misunderstood all of this. First off, there was no threat warning in the AVG results report window, so I thought those were the only results you wanted me to post. Secondly, the 'trace' indicated in the scan seemed vague and didn't provide any further explanation or advisory, and I saw no evidence of it in the report, only the cookies. Lastly, I'm having major connectivity problems with my provider… often I'm offline or running at around 5 kbps :rant2: Ok, well here's the report (despite the embarrassment of exposing my sexxxcounter cookies) :rofl: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 3:59:15 PM 4/7/2007 + Scan result: :mozilla.13:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.481:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.36:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.37:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.601:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.602:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.736:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Adobe : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.739:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.91:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Russ\Cookies\[removed][2].txt -> TrackingCookie.Com : Cleaned. :mozilla.115:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Custom-click : Cleaned. :mozilla.116:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Custom-click : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Russ\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.221:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@hotlog[2].txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.635:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.636:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.637:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.638:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.225:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.716:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Ne : Cleaned. :mozilla.717:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Ne : Cleaned. :mozilla.523:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.40:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.41:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.42:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.43:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.567:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.568:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.722:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.592:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.593:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.594:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.595:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.824:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@revsci[2].txt -> TrackingCookie.Revsci : Cleaned. :mozilla.650:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.651:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.652:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.653:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.654:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.74:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.100:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.101:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.102:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.103:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.104:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.105:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.106:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.107:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.108:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.109:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.110:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.111:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.112:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.113:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.114:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.95:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.96:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.97:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.98:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.99:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.674:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.675:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.676:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.677:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.57:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.684:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.685:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.686:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.33:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Texttbnru : Cleaned. :mozilla.695:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Toplist : Cleaned. :mozilla.705:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.706:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.707:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.803:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Xxxcounter : Cleaned. :mozilla.804:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Xxxcounter : Cleaned. :mozilla.805:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Xxxcounter : Cleaned. :mozilla.806:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Xxxcounter : Cleaned. :mozilla.807:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Russ\Cookies\russ@yadro[1].txt -> TrackingCookie.Yadro : Cleaned. :mozilla.822:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.823:C:\Documents and Settings\Russ\Application Data\Mozilla\Firefox\Profiles\h1q4xf6i.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Russ\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. ::Report end
Cygnus :D

I know that this stuff seems overwhelming at times but we look at the logs for nasty stuff that could be hidding even though to the average home user the log makes no sense. Your HJT log is clean and all AVG found were cookies and that trace is not related to your ISP or connectivity problems. If all or parts of Drive Cleaner were present it would have showed up in both AVG and the Smitfraud log.

I would call your ISP as it may be on there end or some problem with your hardware.


Here is some reading for you and also some windows support sites that deal with issues like that.

It's Not Always MalwareSpeedup Windows Windows Tips
Windows Tech Support Forums
How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI