sylvan2626
Topic Starter
A co-worker asked if I could help him with his family's home PC ( 4 people sharing 1 PC - OS is Win XP Home). His PC has been operating for a couple of years with no antivirus programs, no anti-spy programs, and the Windows XP system patches are woefully behind. IE6 is not up-to-date and the Jave run-time is outdated.
When I first booted up his PC, CPU usage went to 100%, there were popups galore, and IE crashed shortly after being opened each time. IE6 would get taken to a multiude of sites before crashing.
I've since installed Ad-aware, Spybot S&D, Norton Antivirus, Spysweeper (expired version used to control the browser hijacking), ATF Cleaner, CCleaner, HiJackThis, AVG Anti-Spyware, Vundo Removal Tool, and a few other programs. I've disabled the Windows firewall and intend to install ZoneAlarm Free as a firewall replacement. While I was fighting the malware, I removed many trojans with Norton AV and tons of spyware with the other software.
The PC is better, but not cured. I need your help to complete the spyware removal process. NAV reportedly removed Vundo, but there appear to be a few more lurking about. The HJT log is below and then the AVG Anti-Spyware Log uner it. I was unable to run the AVG program in SAFE mode (its service was disabled and I could not enable it) so I ran it in NORMAL mode.
I would greatly appreciate any help with this PC - I've been wrestling with it for a week now.
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 5:21:36 PM, on 6/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/vso/en-us/vso8/s…41&langid=1
O2 - BHO: (no name) - {06206072-4161-4467-B0E1-279BFD506515} - \
O2 - BHO: (no name) - {1DA97021-219A-4C3D-93DE-4DA6154CAA38} - \
O2 - BHO: (no name) - {28682BCE-2E3F-4D88-95FB-55A40C933C1C} - \
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {584818B2-3C05-4147-9B80-A0829CBC3C24} - \
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {826631EF-2E50-4989-B466-78D231B83194} - C:\WINDOWS\System32\lmkpfdhd.dll (file missing)
O2 - BHO: 0 - {9D08F951-2969-4DE4-8E8E-1CE58343CD57} - C:\Program Files\MSN\lavuka.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA0C3511-D2D8-DD21-D108-8AADDA922396} - C:\WINDOWS\System32\ytxitdmq.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\System32\gckfketm.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [{55-54-49-94-ZN}] C:\windows\system32\nkdsrego.exe CHD003
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [j1291636] rundll32 C:\WINDOWS\System32\j1291636.dll sook
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\System32\jqofxnig.dll",realset
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MARSHALL\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://mrsupergames.aavalue.com/toolbars/msg/msg-toolbar.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B964CC0E-7E0C-4B97-A4C4-B3B4C046314B}: NameServer = 85.255.114.39,85.255.112.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.39 85.255.112.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.39 85.255.112.11
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: StService (SServ) - Unknown owner - C:\Program Files\PCTurboPro_Free\AtlServ.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
AVG log:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 4:02:01 PM 6/9/2007
+ Scan result:
C:\WINDOWS\SYSTEM32\lmkpfdhd.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll -> Adware.Companion : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Application Data\Mіcrosoft\wυaclt.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ytxitdmq.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Downloads\AirportTycoon3Setup-dm[2].exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Local Settings\Temporary Internet Files\Content.IE5\VUS7FDOT\qwr67[1].exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\81EB01AJ\qwr67[1].exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\TTC.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINDOWS\qwr67.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\TICHD003.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\smpi1\lib67.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\Program Files\Fοnts\tracert.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\YazzleBundle-1281.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\WINDOWS\b103.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Local Settings\Temporary Internet Files\Content.IE5\KJDFMQFT\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Documents and Settings\LISA\Local Settings\Temporary Internet Files\Content.IE5\8CTPDEDI\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ENIDAH4R\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\func.js -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\WINDOWS\WpAJTrYf67HazytRD.exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[140] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[144] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[152] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[168] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[176] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[1804] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[212] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[220] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[236] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[252] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[312] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[340] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[400] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[416] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[468] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[516] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[536] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[896] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[944] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
C:\Program Files\MSN\lavuka.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\Documents and Settings\LISA\Local Settings\Temporary Internet Files\Content.IE5\AQU99L0A\WinAntiVirusPro2007FreeInstall[1].cab/UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\WinAntiVirusPro2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.u : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\tni1C3.tmp -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Cookies\jacob@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\LISA\Cookies\lisa@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\JACOB\Cookies\jacob@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\JACOB\Cookies\jacob@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\LISA\Cookies\lisa@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\MARSHALL\Local Settings\Temp\Cookies\marshall@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\RECYCLER\S-1-5-21-4196417710-2543008385-3922835211-1009\Dc2\UnInstall.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wnsinticomsv.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end
When I first booted up his PC, CPU usage went to 100%, there were popups galore, and IE crashed shortly after being opened each time. IE6 would get taken to a multiude of sites before crashing.
I've since installed Ad-aware, Spybot S&D, Norton Antivirus, Spysweeper (expired version used to control the browser hijacking), ATF Cleaner, CCleaner, HiJackThis, AVG Anti-Spyware, Vundo Removal Tool, and a few other programs. I've disabled the Windows firewall and intend to install ZoneAlarm Free as a firewall replacement. While I was fighting the malware, I removed many trojans with Norton AV and tons of spyware with the other software.
The PC is better, but not cured. I need your help to complete the spyware removal process. NAV reportedly removed Vundo, but there appear to be a few more lurking about. The HJT log is below and then the AVG Anti-Spyware Log uner it. I was unable to run the AVG program in SAFE mode (its service was disabled and I could not enable it) so I ran it in NORMAL mode.
I would greatly appreciate any help with this PC - I've been wrestling with it for a week now.
HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 5:21:36 PM, on 6/9/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
C:\Program Files\Roxio\GoBack\GBPoll.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Microsoft IntelliPoint\point32.exe
C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Dell AIO Printer A940\dlbabmon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Support.com\bin\tgcmd.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?rs=1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/vso/en-us/vso8/s…41&langid=1
O2 - BHO: (no name) - {06206072-4161-4467-B0E1-279BFD506515} - \
O2 - BHO: (no name) - {1DA97021-219A-4C3D-93DE-4DA6154CAA38} - \
O2 - BHO: (no name) - {28682BCE-2E3F-4D88-95FB-55A40C933C1C} - \
O2 - BHO: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {584818B2-3C05-4147-9B80-A0829CBC3C24} - \
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {826631EF-2E50-4989-B466-78D231B83194} - C:\WINDOWS\System32\lmkpfdhd.dll (file missing)
O2 - BHO: 0 - {9D08F951-2969-4DE4-8E8E-1CE58343CD57} - C:\Program Files\MSN\lavuka.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {CA0C3511-D2D8-DD21-D108-8AADDA922396} - C:\WINDOWS\System32\ytxitdmq.dll (file missing)
O2 - BHO: (no name) - {CD3447D4-CA39-4377-8084-30E86331D74C} - C:\WINDOWS\System32\gckfketm.dll (file missing)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O3 - Toolbar: BellSouth Toolbar - {4E7BD74F-2B8D-469E-8CBD-FD60BB9AAE2E} - C:\PROGRA~1\BLSTOO~1\BLSTOO~1.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A940] "C:\Program Files\Dell AIO Printer A940\dlbabmgr.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [Pure Networks Port Magic] "C:\PROGRA~1\PURENE~1\PORTMA~1\PortAOL.exe" -Run
O4 - HKLM\..\Run: [tgcmd] "C:\Program Files\Support.com\BellSouth\hcenter.exe" /starthidden /tgcmdwrapper
O4 - HKLM\..\Run: [BellSouthAlertManager.exe] C:\Program Files\BellSouth\Alert Manager\BellSouthAlertManager.exe
O4 - HKLM\..\Run: [{55-54-49-94-ZN}] C:\windows\system32\nkdsrego.exe CHD003
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [j1291636] rundll32 C:\WINDOWS\System32\j1291636.dll sook
O4 - HKLM\..\Run: [ApachInc] rundll32.exe "C:\WINDOWS\System32\jqofxnig.dll",realset
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartTrayApp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - C:\Program Files\AOL Toolbar\toolbar.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\MARSHALL\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyPoker.net\partypokernet.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} - http://mrsupergames.aavalue.com/toolbars/msg/msg-toolbar.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v5.cab
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{B964CC0E-7E0C-4B97-A4C4-B3B4C046314B}: NameServer = 85.255.114.39,85.255.112.11
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.39 85.255.112.11
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.39 85.255.112.11
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - Unknown owner - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe (file missing)
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GBPoll - Roxio, Inc. - C:\Program Files\Roxio\GoBack\GBPoll.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Ghost\GhostStartService.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: StService (SServ) - Unknown owner - C:\Program Files\PCTurboPro_Free\AtlServ.exe (file missing)
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
AVG log:
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 4:02:01 PM 6/9/2007
+ Scan result:
C:\WINDOWS\SYSTEM32\lmkpfdhd.dll -> Adware.BHO : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Companion Wizard\WapCHK.dll -> Adware.Companion : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Application Data\Mіcrosoft\wυaclt.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\ytxitdmq.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\Downloads\AirportTycoon3Setup-dm[2].exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Local Settings\Temporary Internet Files\Content.IE5\VUS7FDOT\qwr67[1].exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\81EB01AJ\qwr67[1].exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\TTC.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINDOWS\qwr67.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\TICHD003.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\smpi1\lib67.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\Program Files\Fοnts\tracert.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\YazzleBundle-1281.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe -> Downloader.PurityScan.eg : Cleaned with backup (quarantined).
C:\WINDOWS\b103.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Local Settings\Temporary Internet Files\Content.IE5\KJDFMQFT\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Documents and Settings\LISA\Local Settings\Temporary Internet Files\Content.IE5\8CTPDEDI\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\ENIDAH4R\WpAJTrYf67HazytRD[1].exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\Program Files\func.js -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\WINDOWS\WpAJTrYf67HazytRD.exe -> Hijacker.Small.jf : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[140] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[144] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[152] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[168] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[176] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[1804] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[212] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[220] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[236] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[252] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[312] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[340] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[400] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[416] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[468] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[516] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[536] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[896] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
[944] C:\WINDOWS\System32\j1291636.dll -> Hijacker.Small.mw : Cleaned with backup (quarantined).
C:\Program Files\MSN\lavuka.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\Documents and Settings\LISA\Local Settings\Temporary Internet Files\Content.IE5\AQU99L0A\WinAntiVirusPro2007FreeInstall[1].cab/UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UPCTP_0001_91M1101NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\WinAntiVirusPro2007FreeInstall.exe -> Not-A-Virus.Downloader.Win32.WinFixer.u : Cleaned with backup (quarantined).
C:\Documents and Settings\MARSHALL\Local Settings\Temp\tni1C3.tmp -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\Documents and Settings\JACOB\Cookies\jacob@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\LISA\Cookies\lisa@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\JACOB\Cookies\jacob@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\JACOB\Cookies\jacob@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\LISA\Cookies\lisa@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\MARSHALL\Local Settings\Temp\Cookies\marshall@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\LISA\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\MARSHALL\Cookies\marshall@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\JACOB\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\RECYCLER\S-1-5-21-4196417710-2543008385-3922835211-1009\Dc2\UnInstall.exe -> Trojan.Rond : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wnsinticomsv.exe -> Trojan.Small : Cleaned with backup (quarantined).
::Report end