This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Persistent Problems, Incl. Virtumonde, Who Knows What Else.

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer has problems that have resisted SpyBot and AdAware. By now, I'm not sure what all I have–except probably some conflicting anti-malware stuff as well as the nasty malware. I now have to shut down ZoneAlarm to be able to start up Firefox just to get here and post.

AVG keeps telling me about Virtumonde; I have AntiVir popping up on and off to tell me about Trojan goodness. Other symptoms are IE popping up (I've set ZoneAlarm to block its access, but it still tries) and a fake Win Antivirus Something ad opening itself in Firefox. And my computer is sluggish and about half the time it won't restart. Or shut down properly. At this point I am all "Help me Obi-wan Kenobi, you're my only hope."

As per the Before You Post instructions, here is an AVG log and the HijackThis log.

Thank you.

HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 7:09:42 PM, on 6/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\USB Storage RW\shwicon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ms101.mysearch.com/sa/srchlft.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R3 - Default URLSearchHook is missing
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://www.yahoo.com"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CPROGRA%7E1%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\prefs.js)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: (no name) - {9EAC0102-5E61-2312-BC2D-444C4C4F5552} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [KYE_Showicon] "C:\Program Files\USB Storage RW\shwicon.exe" -t"KYE\USB Storage RW"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AutoTBar] C:\hp\bin\autotbar.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBAudigy\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKLM\..\Run: [clfmon.exe] clfmon.exe
O4 - HKLM\..\Run: [defect08] Preliminary.exe
O4 - HKLM\..\Run: [trycrt] UserSp1.exe
O4 - HKLM\..\Run: [DNSCacheBoost] C:\WINDOWS\System32\dnsping.exe
O4 - HKLM\..\Run: [dmwkn.exe] C:\WINDOWS\System32\dmwkn.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [{ZN}] C:\WINDOWS\Temp\stdrun8.exe CHD001
O4 - HKLM\..\Run: [SBCSTray] C:\Program Files\Sunbelt Software\CounterSpy\SBCSTray.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [nmdllw] PrcIdle.exe
O4 - HKCU\..\Run: [Testimonials] qwe.exe
O4 - HKCU\..\Run: [prcmon] zantu.exe
O4 - HKCU\..\Run: [Xxwzc] C:\WINDOWS\System32\l?gonui.exe
O4 - HKCU\..\Run: [Iaes] "C:\WINDOWS\WNSXS~1\wuauboot.exe" -vt ndrv
O4 - HKCU\..\Run: [Lpved] "C:\Documents and Settings\Administrator\Application Data\?icrosoft.NET\d?xplore.exe"
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: TA_Start.lnk = C:\WINDOWS\Temp\stdrun8.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\BackWeb-137903.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O15 - Trusted IP range: 209.8.20.130
O15 - ProtocolDefaults: 'http' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in Trusted Zone, should be Internet Zone (HKLM)
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{14ABCAB4-831C-4E1B-87AB-EC855044B143}: NameServer = 69.50.166.94,69.31.80.244
O17 - HKLM\System\CCS\Services\Tcpip\..\{6671AA86-F0E9-45E8-BB11-53ACFE5249B1}: NameServer = 69.50.166.94,69.31.80.244
O17 - HKLM\System\CCS\Services\Tcpip\..\{9DE10CDA-670D-4D80-B618-5FA6AA895974}: NameServer = 69.50.166.94,69.31.80.244
O17 - HKLM\System\CS1\Services\Tcpip\..\{14ABCAB4-831C-4E1B-87AB-EC855044B143}: NameServer = 69.50.166.94,69.31.80.244
O20 - AppInit_DLLs: dvdplay.dll c:\windows\system32\ldcore.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sunbelt CounterSpy Antispyware (SBCSSvc) - Sunbelt Software - C:\Program Files\Sunbelt Software\CounterSpy\SBCSSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe


And the AVG log:

+ Created at: 6:30:00 PM 6/19/2007

+ Scan result:



HKLM\SOFTWARE\Classes\MTC2608.MTC2608 -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\MTC2608.MTC2608\CurVer -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WER4820.WER4820 -> Adware.PurityScan : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WER4820.WER4820\CurVer -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\vtuspnm.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
[252] C:\WINDOWS\system32\vtuspnm.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
[784] C:\WINDOWS\System32\vtuspnm.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temp\MSI397D.tmp -> Downloader.Murlo.fk : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temp\win.dll -> Downloader.Murlo.fk : Cleaned with backup (quarantined).
C:\WINDOWS\xftpvpuA.exe -> Downloader.VB.ang : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\ISKCDEFY\WinAntiVirusPro2007FreeInstall[1].cab/UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\.jpi_cache\file\1.0\java.class-42ed57a3-2c99a72f.class -> Not-A-Virus.Exploit.Java.Gimsh.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Administrator\Cookies\administrator@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
:mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.232:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.233:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\88iikv11.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.265:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.31:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.56:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.57:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\88iikv11.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Administrator\Local Settings\Temp\Cookies\administrator@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.22:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.23:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.24:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@navrcholu[2].txt -> TrackingCookie.Navrcholu : Cleaned.
:mozilla.176:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@real[2].txt -> TrackingCookie.Real : Cleaned.
:mozilla.184:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.235:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\88iikv11.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\88iikv11.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.38:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.39:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.41:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.42:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.43:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.44:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.45:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.46:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.51:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.52:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.53:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.54:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.55:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.199:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.200:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.201:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.202:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@toplist[1].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Administrator\Cookies\administrator@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.229:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.230:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.231:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\kgo9h4o4.slt\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end
Hello and welcome to the forum. Sorry about the delay in responding :( If you still need help, Scan again with HijackThis, and copy/paste" a new log file into this thread. Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI