This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Tr/crypt.xpack.gen Or Perfc000.dat

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi all, i have been searching google for the past few days trying to get rid of this thing but to no avail. I came across this site and read both thread about this particular malware or whatever it is and still couldn't find a solution.

i downloaded HJT and ran a scan
see below

i have ran safemode and tried another users method of changing the name and deleting the file on reboot, but it still appears

i would greatly appreciate any help on this.

Logfile of HijackThis v1.99.1
Scan saved at 6:09:32 PM, on 5/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Power DVD Player\PowerDVDPlayer.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [Power DVD Player] "C:\Program Files\Power DVD Player\PowerDVDPlayer.exe" hmw
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDVD4 Professional\MediaDetector.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.dat
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Welcome to the forum.

1. Please download The Avenger by Swandog46 to your Desktop.

* Click on Avenger.zip to open the file
* Extract avenger.exe to your desktop

2. Copy all the text contained in the code box below to your Clipboard by highlighting it, then right click on it and choose Copy [or by pressing (Ctrl+C)]:


Files to delete:
C:\WINDOWS\system32\perfc000.dat

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs


Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.

* Under "Script file to execute" choose "Input Script Manually".
* Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
* Right click in the new window and choose Paste or use (Ctrl+V). This will paste the text from the clipboard into the new window.
* Click Done
* Now click on the Green Light to begin execution of the script
* Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

* It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
* On reboot, it will briefly open a black command window on your desktop, this is normal.
* After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
* The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

———————–

Download combofix.exe from the link below:
http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Double click combofix.exe & follow the prompts.
A window will open with a warning.
Type "Y" (and Enter) to start the fix.
When the scan completes it will open a text window.
Please attach that log back here together with a fresh HJT log.
Caution - do not touch your mouse/keyboard until the scan has completed.
The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt

———————-

Please download and install the 30 day trial version of AVG Anti-Spyware 7.5 here:
http://www.ewido.net/en/download/

After it's installed…Check for updates:
Double click on the AVG-AS icon in the system tray or on the desktop> this will bring up the main program if it's not already up.

On the Main Page click the Update Tab and then Start Update.
Download and install any updates if available.

Select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine.
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found

Close ALL open Windows / Programs / Folders.
Open up AVG-AS
Now click the Scanner Icon on top
Click on Complete System Scan
Be patient - it takes a while to run.

IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?

Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply All Actions

Next select the Reports icon at the top.
Copy and paste the scan report in your next reply.

Close AVG-AS and Reboot in Normal Mode.

Post the log from AVG AS, ComboFix, Avenger and a fresh HJT log, MrC
ok i have done exactly what was asked..here are the logs.

AVG
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:01:30 PM 5/9/2007

+ Scan result:



C:\System Volume Information\_restore{6656275B-4F7F-48F0-AFA6-B2E1911E4D80}\RP401\A0060072.inf -> Adware.BetterInternet : Cleaned.
C:\System Volume Information\_restore{6656275B-4F7F-48F0-AFA6-B2E1911E4D80}\RP401\A0070252.dll -> Adware.Gator : Cleaned.
:mozilla.52:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.247realmedia : Error during cleaning.
:mozilla.53:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.247realmedia : Error during cleaning.
:mozilla.54:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.247realmedia : Error during cleaning.
:mozilla.64:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.65:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.66:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@network-ca.247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@oasc04.247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.150:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.159:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.32:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.34:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.35:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.36:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.37:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.38:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.39:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.39:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.40:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.40:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.41:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.41:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.42:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.42:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.43:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.43:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.44:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.44:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.45:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.45:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.46:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.48:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.82:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.2o7 : Error during cleaning.
:mozilla.91:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\user@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\user@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\user@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\user@partygaming.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\user\Cookies\user@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.11:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.13:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.14:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.15:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.16:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.28:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.29:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.30:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.31:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.
:mozilla.32:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Advertising : Error during cleaning.
C:\Documents and Settings\user\Cookies\user@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Advertisingcom.zip/user@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.29:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.46:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Atdmt : Error during cleaning.
C:\Documents and Settings\user\Cookies\user@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\AvenueAInc.zip/user@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.185:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Belstat : Error during cleaning.
:mozilla.186:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Belstat : Error during cleaning.
:mozilla.194:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Belstat : Cleaned.
:mozilla.195:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Belstat : Cleaned.
:mozilla.106:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.97:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Bluestreak : Error during cleaning.
C:\Documents and Settings\user\Cookies\user@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.10:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.17:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.18:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.19:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.47:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.48:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.49:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.50:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.51:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Casalemedia : Error during cleaning.
:mozilla.8:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.9:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.162:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Centrport : Error during cleaning.
:mozilla.171:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\user\Cookies\user@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\user\Cookies\user@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\user\Cookies\user@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.121:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Dealtime : Error during cleaning.
:mozilla.130:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.24:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Doubleclick : Error during cleaning.
:mozilla.31:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\user\Cookies\user@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\DoubleClick.zip/user@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\user\Cookies\user@estat[1].txt -> TrackingCookie.Estat : Cleaned.
:mozilla.81:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Euroclick : Error during cleaning.
:mozilla.90:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.65:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Fastclick : Error during cleaning.
:mozilla.74:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\FastClick.zip/user@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.167:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Findwhat : Error during cleaning.
:mozilla.176:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Findwhat : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox.zip/user@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox1.zip/[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitBox2.zip/[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\HitsLink.zip/[removed][1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\user\Cookies\user@idot[1].txt -> TrackingCookie.Idot : Cleaned.
C:\Documents and Settings\user\Cookies\user@info[2].txt -> TrackingCookie.Info : Cleaned.
:mozilla.204:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Information : Error during cleaning.
:mozilla.213:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\user\Cookies\user@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\user\Cookies\user@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned.
C:\Documents and Settings\user\Cookies\user@komtrack[2].txt -> TrackingCookie.Komtrack : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][2].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.21:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Mediaplex : Error during cleaning.
:mozilla.22:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Mediaplex : Error during cleaning.
:mozilla.54:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.55:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\user\Cookies\user@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\MediaPlex.zip/user@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][2].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.111:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Onestat : Error during cleaning.
:mozilla.112:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Onestat : Error during cleaning.
:mozilla.120:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.121:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.152:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Overture : Error during cleaning.
:mozilla.161:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\user\Cookies\user@overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.151:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Paycounter : Error during cleaning.
:mozilla.160:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.188:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Paypal : Error during cleaning.
:mozilla.197:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.123:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.124:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.125:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.126:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Pointroll : Error during cleaning.
:mozilla.132:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.133:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.134:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.135:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.114:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.
:mozilla.115:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Qksrv : Error during cleaning.
:mozilla.123:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.124:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Quarterserver : Cleaned.
:mozilla.58:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Questionmarket : Error during cleaning.
:mozilla.59:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Questionmarket : Error during cleaning.
:mozilla.67:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.68:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\user\Cookies\user@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][2].txt -> TrackingCookie.Real : Cleaned.
:mozilla.60:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Realmedia : Error during cleaning.
:mozilla.61:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Realmedia : Error during cleaning.
:mozilla.69:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.70:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\user\Cookies\user@www.res99[1].txt -> TrackingCookie.Res99 : Cleaned.
:mozilla.203:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Revenue : Error during cleaning.
:mozilla.212:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.87:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Ru4 : Error during cleaning.
:mozilla.96:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.156:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.157:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.158:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.159:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.160:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.161:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Serving-sys : Error during cleaning.
:mozilla.165:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.166:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.167:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.168:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.169:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.170:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.163:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Sexcounter : Error during cleaning.
:mozilla.164:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Sexcounter : Error during cleaning.
:mozilla.172:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.173:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.100:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.101:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.102:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.103:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.105:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.106:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.107:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.108:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.108:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.109:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.109:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.110:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.110:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
:mozilla.111:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.112:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.114:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.115:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.116:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.117:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.118:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.119:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.99:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Statcounter : Error during cleaning.
C:\Documents and Settings\user\Cookies\user@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\user\Cookies\user@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.215:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Targetnet : Error during cleaning.
:mozilla.224:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.28:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.57:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Tribalfusion : Error during cleaning.
C:\Documents and Settings\user\Cookies\user@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.56:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.57:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.58:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.59:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.60:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.61:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\user\Cookies\user@vegasred[1].txt -> TrackingCookie.Vegasred : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Vegasred : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.15:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.22:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.23:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.24:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.25:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.26:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.27:C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.6:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.7:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.8:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
:mozilla.9:C:\Program Files\Spybot - Search & Destroy 1.1\Recovery\Mozilla2.zip/cookies.txt -> TrackingCookie.Yieldmanager : Error during cleaning.
C:\Documents and Settings\user\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end


Combofix
"user" - 2007-05-09 18:07:22 Service Pack 2
ComboFix 07-05.09.V - Running from: "C:\Documents and Settings\user\Desktop\"


(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\Packet.dll
C:\WINDOWS\system32\pthreadVC.dll
C:\WINDOWS\system32\WanPacket.dll
C:\WINDOWS\system32\wpcap.dll
C:\DOCUME~1\user\Desktop\internet.lnk
C:\WINDOWS\system32\drivers\npf.sys


((((((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))


——-\LEGACY_NPF
——-\NPF


((((((((((((((((((((((((((((((( Files Created from 2007-04-09 to 2007-05-09 ))))))))))))))))))))))))))))))))))


2007-05-09 18:05 d——– C:\avenger
2007-05-05 15:23 d–hs—- C:\WINDOWS\CSC
2007-05-01 19:30 d——– C:\Program Files\BlazeVideo
2007-04-30 22:14 d——– C:\DOCUME~1\user\APPLIC~1\BitTyrant
2007-04-30 22:13 d——– C:\Program Files\BitTyrant
2007-04-29 23:43 d——– C:\DOCUME~1\user\APPLIC~1\uTorrent
2007-04-27 22:29 4,718,592 –a—— C:\DOCUME~1\user\ntuser.dat
2007-04-19 23:07 43,584 –a—— C:\WINDOWS\system32\drivers\avipbb.sys
2007-04-19 23:07 28,352 –a—— C:\WINDOWS\system32\drivers\ssmdrv.sys
2007-04-15 14:32 73,216 –a—— C:\WINDOWS\ST6UNST.EXE
2007-04-15 14:32 249,856 ——— C:\WINDOWS\Setup1.exe
2007-04-15 14:32 d——– C:\Program Files\CodecInstaller
2007-04-15 14:31 36 –a—— C:\WINDOWS\system32\ddp.dat
2007-04-15 14:31 d——– C:\Program Files\Power DVD Player


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-04-30 04:13:17 ——– d—–w C:\Program Files\Spyware Doctor
2007-04-30 03:47:58 ——– d—–w C:\Program Files\Spybot - Search & Destroy 1.1
2007-04-27 01:57:59 ——– d—–w C:\DOCUME~1\user\APPLIC~1\TransRender
2007-04-14 02:33:21 ——– d—–w C:\Program Files\Tiger Gaming
2007-03-28 03:11:22 ——– d—–w C:\Program Files\AC3Filter
2007-03-28 03:04:30 ——– d—–w C:\DOCUME~1\user\APPLIC~1\DivX
2007-03-28 03:04:09 ——– d—–w C:\Program Files\DivX
2007-03-17 13:43:01 292,864 —-a-w C:\WINDOWS\system32\winsrv.dll
2007-03-08 15:36:28 577,536 —-a-w C:\WINDOWS\system32\user32.dll
2007-03-08 15:36:28 40,960 —-a-w C:\WINDOWS\system32\mf3216.dll
2007-03-08 15:36:28 281,600 —-a-w C:\WINDOWS\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 —-a-w C:\WINDOWS\system32\win32k.sys
2007-02-23 04:29:58 524,288 —-a-w C:\WINDOWS\system32\DivXsm.exe
2007-02-23 04:29:56 3,596,288 —-a-w C:\WINDOWS\system32\qt-dx331.dll
2007-02-23 04:29:52 129,784 ——w C:\WINDOWS\system32\pxafs.dll
2007-02-23 04:29:52 118,520 ——w C:\WINDOWS\system32\pxinsi64.exe
2007-02-23 04:29:52 116,472 ——w C:\WINDOWS\system32\pxcpyi64.exe
2007-02-23 04:29:49 200,704 —-a-w C:\WINDOWS\system32\ssldivx.dll
2007-02-23 04:29:49 1,044,480 —-a-w C:\WINDOWS\system32\libdivx.dll
2007-02-23 04:25:24 73,728 —-a-w C:\WINDOWS\system32\dpl100.dll
2007-02-23 04:25:24 196,608 —-a-w C:\WINDOWS\system32\dtu100.dll
2007-02-23 04:25:23 53,248 —-a-w C:\WINDOWS\system32\dpuGUI10.dll
2007-02-23 04:25:22 593,920 —-a-w C:\WINDOWS\system32\dpuGUI11.dll
2007-02-23 04:25:22 57,344 —-a-w C:\WINDOWS\system32\dpv11.dll
2007-02-23 04:25:22 344,064 —-a-w C:\WINDOWS\system32\dpus11.dll
2007-02-23 04:25:22 294,912 —-a-w C:\WINDOWS\system32\dpu11.dll
2007-02-23 04:25:22 294,912 —-a-w C:\WINDOWS\system32\dpu10.dll
2007-02-23 04:25:19 823,296 —-a-w C:\WINDOWS\system32\divx_xx0c.dll
2007-02-23 04:25:19 823,296 —-a-w C:\WINDOWS\system32\divx_xx07.dll
2007-02-23 04:25:19 802,816 —-a-w C:\WINDOWS\system32\divx_xx11.dll
2007-02-23 04:25:19 639,066 —-a-w C:\WINDOWS\system32\DivX.dll
2007-02-17 23:08:23 737,280 —-a-w C:\WINDOWS\iun6002.exe
2007-02-16 01:40:35 124,472 —-a-w C:\WINDOWS\system32\DivXCodecUpdateChecker.exe


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
"{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}"="C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx"
"{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB}"="C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll"
"{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}"="C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll"
"{AA58ED58-01DD-4d91-8333-CF10577473F7}"="c:\program files\google\googletoolbar1.dll"
"{B56A7D7D-6927-48C8-A975-17DF180C71AC}"="C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Logitech Utility"="Logi_MwX.Exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"avgnt"="\"C:\\Program Files\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"Athan"="C:\\Program Files\\Athan\\Athan.exe"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"PcSync"="C:\\Program Files\\Nokia\\Nokia PC Suite 6\\PcSync2.exe /NoDialog"
"WeatherEye"="C:\\Program Files\\TheWeatherNetwork\\WeatherEye\\WeatherEye"
"Power DVD Player"="\"C:\\Program Files\\Power DVD Player\\PowerDVDPlayer.exe\" hmw"
"BlazeServoTool"="\"C:\\Program Files\\BlazeVideo\\BlazeDVD4 Professional\\MediaDetector.exe\""


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages msv1_0\
Security Packages kerberosmsv1_0schannelwdigest\
Notification Packages scecli\

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^microsoft office.lnk
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE -b -l

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\c:^documents and settings^all users^start menu^programs^startup^utility tray.lnk
C:\WINDOWS\system32\sistray.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\asus probe
C:\Program Files\ASUS\Probe\AsusProb.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\atipta
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msmsgs
"C:\Program Files\Messenger\msmsgs.exe" /background

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nerofiltercheck
C:\WINDOWS\system32\NeroCheck.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sis windows keyhook
C:\WINDOWS\System32\keyhook.exe

HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\sisusbrg
C:\WINDOWS\SiSUSBrg.exe


[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService AlerterWebClientLmHostsRemoteRegistryupnphostSSDPSRV\
NetworkService DnsCache\
rpcss RpcSs\
imgsvc StiSvc\
termsvcs TermService\
HTTPFilter HTTPFilter\
DcomLaunch DcomLaunchTermService\
WudfServiceGroup WUDFSvc\

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\Symantec NetDetect.job

********************************************************************

catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-09 18:11:37
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


********************************************************************

Completion time: 2007-05-09 18:12:42 - machine was rebooted
C:\ComboFix-quarantined-files.txt … 2007-05-09 18:12


Avenger log

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\bnfvluop

*******************

Script file located at: \??\C:\Program Files\obwwbvcy.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\perfc000.dat not found!
Deletion of file C:\WINDOWS\system32\perfc000.dat failed!

Could not process line:
C:\WINDOWS\system32\perfc000.dat
Status: 0xc0000034

Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.


NEW HJT log

Logfile of HijackThis v1.99.1
Scan saved at 8:04:02 PM, on 5/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Power DVD Player\PowerDVDPlayer.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [Power DVD Player] "C:\Program Files\Power DVD Player\PowerDVDPlayer.exe" hmw
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDVD4 Professional\MediaDetector.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe



I will reboot and post a new HJT to see if 020 is actually gone…
btw i would like to add…MrCharlie, you have been a great help so far…the world needs more people like you. !!!…i'm currently at work now..but i will post a HJT once i get home. does it look good so far?
so far the PC has been running normally..nothing is poping up
new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 5:34:27 PM, on 5/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Athan\Athan.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye.exe
C:\Program Files\Power DVD Player\PowerDVDPlayer.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\user\Application Data\Mozilla\Profiles\default\3g0ee940.slt\prefs.js)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Athan] C:\Program Files\Athan\Athan.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [WeatherEye] C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye
O4 - HKCU\..\Run: [Power DVD Player] "C:\Program Files\Power DVD Player\PowerDVDPlayer.exe" hmw
O4 - HKCU\..\Run: [BlazeServoTool] "C:\Program Files\BlazeVideo\BlazeDVD4 Professional\MediaDetector.exe"
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyPoker\PartyPoker.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by22fd.bay22.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Looks OK

The first time we dealt with this infection it wasn't this easy!

If you have any questions - please post back

I'll leave you with……..

Some Preventive Maintenance:

Some of the programs you may have run create backups of what was deleted - you can safely delete them now: (delete folders in blue) You can also delete/uninstall the programs themselves.

C:\!KillBox (KillBox)
C:\VundoFix Backups (VundoFix)
C:\QooBox (ComboFix)
C:\SDFix\backups\backups.zip (SDFix)
C:\avenger\backup.zip (Avenger)


AVG Anti-Spyware will provide 30 days of real time protection and then after that you can use it to scan for malware - you'll have to manually update it first.


——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:

Note: This will remove all previous Restore Points!

1. Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer,

2. Turn on System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UnCheck Turn off System Restore.
Click Apply, and then click OK.

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File
Direct Download - MVPS HOSTS <==> MVPS HOSTS Tutorial

Need a free anti virus?
AVG*free
Avast free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
Windows firewall is not suffient…install a better one.
Comodo Free Firewall
ZoneAlarm*free
Other free firewalls

Keep those temp files off your system use
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected"
or
CCleaner
Uncheck "Cookies" under "Internet Explorer".
That will clear out all the temp files on the system.

IMPORTANT!!
Keep your Sun Java up-to-date JRE Version 6 Update 1<–newest version
Delete ALL old versions from add/remove programs if listed first!
http://forums.tomcoyote.org/index.php?showtopic=68632

Keep the registry backed up - use ERUNT
Print this out and save it
ERUNT Tutorial

Starter Manage you startup programs and services.

———-Free malware removal programs:———-

AVG Anti-Spyware<—VERY GOOD! (XP and 2K only)
SUPERAntiSpyware (free edition)<—Excellent!
SpyBot
AD-Aware
CW-Shredder

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable "Windows Messenger Service" XP - 2K (stops pop-up ads -etc):
Shoot The Messenger

Anti-Rootkit Software - Detection, Removal & Protection

Don't open e-mail attachments without first scanning them with an up-to-date anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Don't believe e-mails from your bank, financial institution, etc asking for personal informations - they're most likely fraudulent no matter how authentic they look.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI