This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed]Home Page Hijacked For A Few Seconds

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

During start up, the home page (i.e. background display) will be hijacked for a while until the Window desktop completes its icon arrangement and back to the normal home page. The log file is shown below:

Logfile of HijackThis v1.99.1
Scan saved at 2:17:36 PM, on 8/4/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ZipToA.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Winamp2\Winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Verizon Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.lib.berkeley.edu:7777/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://proxy.lib.berkeley.edu:7777/
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C6548A94-6C19-DD6F-1F26-B300B04EEE47} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O3 - Toolbar: (no name) - {2A82A7AA-87E3-CDE8-13FC-CCE37BB3D5CC} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp2\Winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1171074499735
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINNT\svchost.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\System32\ZipToA.exe
Hi! Welcome to the Tom Coyote forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

Please make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.
5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here in a reply.


Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt.
Download and Run ComboFix
  • Download this file from below:

    Here
  • Disconnect from the Internet, than disable your anti-virus and any real-time anti-spyware monitors that are running.
  • Then double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply with a new HijackThis log.
Note 1: Do not mouseclick combofix's window whilst it's running. That may cause it to stall
Note 2:Remember to re-enable your anti-virus and anti-spyware before reconnecting to the Internet.
Scotty, Thank you for your review for my case (SmokeyHJ). I have followed your instructions to make an uninstall list using HijackThis. I would like to add more details about my problem. First, the problem happened with my desktop background display. At the first time I encountered this problem, I went to check my Display setting (in Control Panel) and found there was the highjacker's insert in the setting list as "Internet Wallpaper". I reset the background Display to a normal one. In the next computer reboot, the undesired display still appears during Windows preparation. The hijack screen will sustain until all desktop icons arrangement completes. Below is the uninstall list as you requested: Ad-Aware SE Personal Adobe Acrobat 5.0 Adobe Acrobat Reader 5.0.5 Adobe Download Manager (Remove Only) Adobe Flash Player 9 ActiveX Adobe Photoshop 7.0 Adobe Reader 6.0 AFPL Ghostscript 7.04 AFPL Ghostscript Fonts Anfy AOL Instant Messenger Apple Software Update CDBurnerXP Pro 3 Chinese (Traditional) Language Support CS ChemDraw Std 5.0 DirectX 8 Hotfix - KB839643 DivX Codec Easy CD Creator 5 Platinum Eudora 5.1.3 Google Earth Google Toolbar for Internet Explorer GSview 4.3 Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for MDAC 2.53 (KB927779) HP DeskJet 610C Series (Remove only) Hummingbird HostExplorer V7.1 Image Transfer ImageMixer for Sony Kazaa Media Desktop 2.5 Leash32 2.1.2 for Windows Macromedia Dreamweaver 4 Macromedia Extension Manager Mathematica 4 MATLAB 6.1 MATLAB Family of Products Release 12 Microsoft Age of Empires II Microsoft Office XP Professional with FrontPage Microsoft PowerPoint Viewer 97 Microsoft Visual C++ 6.0 Introductory Edition Microsoft Word Viewer 97 MicroStaff WINASPI Mozilla Firefox (1.0) Origin 6.1 PaperPort 6.5 QuickTime RealOne Player SecureCRT 3.4.6 Security Update for Windows 2000 (KB904706) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 6.4 (KB925398) Shutterfly Plugin Sony USB Driver SoulSeek Client 146c SpywareBlaster v3.2 SSH Secure Shell Stuffit Standard Edition 7.5 TeXLive The Rosetta Stone Trimill TriLookup Version 2.2 TurboNote+ TurboTax Deluxe Deduction Maximizer 2006 TurboTax ItsDeductible 2006 Update Rollup 1 for Windows 2000 SP4 Verizon Online Viewpoint Manager (Remove Only) Viewpoint Media Player Visioneer 4400 Scanner WexTech AnswerWorks Winamp (remove only) Winamp3 (remove only) Windows 2000 Hotfix - KB842773 Windows 2000 Hotfix - KB867282 Windows 2000 Hotfix - KB893756 Windows 2000 Hotfix - KB896358 Windows 2000 Hotfix - KB896422 Windows 2000 Hotfix - KB896423 Windows 2000 Hotfix - KB896424 Windows 2000 Hotfix - KB899587 Windows 2000 Hotfix - KB899589 Windows 2000 Hotfix - KB900725 Windows 2000 Hotfix - KB901017 Windows 2000 Hotfix - KB901214 Windows 2000 Hotfix - KB905414 Windows 2000 Hotfix - KB905495 Windows 2000 Hotfix - KB905749 Windows 2000 Hotfix - KB908519 Windows 2000 Hotfix - KB908531 Windows 2000 Hotfix - KB911280 Windows 2000 Hotfix - KB912919 Windows 2000 Hotfix - KB913580 Windows 2000 Hotfix - KB914388 Windows 2000 Hotfix - KB914389 Windows 2000 Hotfix - KB917008 Windows 2000 Hotfix - KB917422 Windows 2000 Hotfix - KB917736 Windows 2000 Hotfix - KB917953 Windows 2000 Hotfix - KB918118 Windows 2000 Hotfix - KB920213 Windows 2000 Hotfix - KB920670 Windows 2000 Hotfix - KB920683 Windows 2000 Hotfix - KB920685 Windows 2000 Hotfix - KB920958 Windows 2000 Hotfix - KB921398 Windows 2000 Hotfix - KB922582 Windows 2000 Hotfix - KB923191 Windows 2000 Hotfix - KB923414 Windows 2000 Hotfix - KB923694 Windows 2000 Hotfix - KB923980 Windows 2000 Hotfix - KB924191 Windows 2000 Hotfix - KB924270 Windows 2000 Hotfix - KB924667 Windows 2000 Hotfix - KB925902 Windows 2000 Hotfix - KB926122 Windows 2000 Hotfix - KB926436 Windows 2000 Hotfix - KB927891 Windows 2000 Hotfix - KB928090 Windows 2000 Hotfix - KB928843 Windows 2000 Hotfix - KB929969 Windows 2000 Hotfix - KB930178 Windows 2000 Hotfix - KB931768 Windows 2000 Hotfix - KB931784 Windows 2000 Hotfix - KB932168 Windows 2000 Hotfix - KB933566 Windows 2000 Hotfix - KB935839 Windows 2000 Hotfix - KB935840 Windows 2000 Service Pack 4 Windows Installer 3.1 (KB893803) Windows Media Player Hotfix [See Q828026 for more information] WinRAR archiver WinZip 11.1 Yahoo! Install Manager
Scotty,

Below are the report and logs that you requested:

1. SDFix report <——————————————————————————————–

SDFix: Version 1.95

Run by [removed] on Sun 08/05/2007 at 9:17a

Microsoft Windows 2000 [Version 5.00.2195]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…


Normal Mode:
Checking Files:

Trojan Files Found:

C:\WINNT\system32\drivers\etc\hosts.bho - Deleted
C:\WINNT\system32\TFTP1380 - Deleted



Removing Temp Files…

ADS Check:

C:\WINNT
No streams found.

C:\WINNT\system32
No streams found.

C:\WINNT\system32\svchost.exe
No streams found.

C:\WINNT\system32\ntoskrnl.exe
No streams found.



Final Check:

Remaining Services:
——————



Remaining Files:
—————

Backups Folder: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL0003.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL0671.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL2675.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL3196.tmp
C:\Documents and Settings\Administrator\Application Data\Microsoft\Word\~WRL3457.tmp
C:\Documents and Settings\Administrator\My Documents\~WRL0004.tmp
C:\Documents and Settings\Administrator\My Documents\~WRL0005.tmp
C:\Documents and Settings\Administrator\My Documents\~WRL0006.tmp
C:\Documents and Settings\Administrator\My Documents\~WRL0974.tmp
C:\Documents and Settings\Administrator\My Documents\~WRL1210.tmp
C:\Peng\EXTRA\~WRL0047.tmp
C:\Peng\EXTRA\~WRL0068.tmp
C:\Peng\EXTRA\~WRL0096.tmp
C:\Peng\EXTRA\~WRL0126.tmp
C:\Peng\EXTRA\~WRL0144.tmp
C:\Peng\EXTRA\~WRL0145.tmp
C:\Peng\EXTRA\~WRL0149.tmp
C:\Peng\EXTRA\~WRL0153.tmp
C:\Peng\EXTRA\~WRL0171.tmp
C:\Peng\EXTRA\~WRL0177.tmp
C:\Peng\EXTRA\~WRL0186.tmp
C:\Peng\EXTRA\~WRL0198.tmp
C:\Peng\EXTRA\~WRL0216.tmp
C:\Peng\EXTRA\~WRL0226.tmp
C:\Peng\EXTRA\~WRL0236.tmp
C:\Peng\EXTRA\~WRL0266.tmp
C:\Peng\EXTRA\~WRL0283.tmp
C:\Peng\EXTRA\~WRL0294.tmp
C:\Peng\EXTRA\~WRL0309.tmp
C:\Peng\EXTRA\~WRL0353.tmp
C:\Peng\EXTRA\~WRL0382.tmp
C:\Peng\EXTRA\~WRL0394.tmp
C:\Peng\EXTRA\~WRL0396.tmp
C:\Peng\EXTRA\~WRL0418.tmp
C:\Peng\EXTRA\~WRL0450.tmp
C:\Peng\EXTRA\~WRL0472.tmp
C:\Peng\EXTRA\~WRL0473.tmp
C:\Peng\EXTRA\~WRL0490.tmp
C:\Peng\EXTRA\~WRL0512.tmp
C:\Peng\EXTRA\~WRL0527.tmp
C:\Peng\EXTRA\~WRL0561.tmp
C:\Peng\EXTRA\~WRL0610.tmp
C:\Peng\EXTRA\~WRL0646.tmp
C:\Peng\EXTRA\~WRL0660.tmp
C:\Peng\EXTRA\~WRL0664.tmp
C:\Peng\EXTRA\~WRL0687.tmp
C:\Peng\EXTRA\~WRL0695.tmp
C:\Peng\EXTRA\~WRL0713.tmp
C:\Peng\EXTRA\~WRL0720.tmp
C:\Peng\EXTRA\~WRL0731.tmp
C:\Peng\EXTRA\~WRL0732.tmp
C:\Peng\EXTRA\~WRL0763.tmp
C:\Peng\EXTRA\~WRL0765.tmp
C:\Peng\EXTRA\~WRL0778.tmp
C:\Peng\EXTRA\~WRL0787.tmp
C:\Peng\EXTRA\~WRL0790.tmp
C:\Peng\EXTRA\~WRL0812.tmp
C:\Peng\EXTRA\~WRL0831.tmp
C:\Peng\EXTRA\~WRL0845.tmp
C:\Peng\EXTRA\~WRL0859.tmp
C:\Peng\EXTRA\~WRL0860.tmp
C:\Peng\EXTRA\~WRL0861.tmp
C:\Peng\EXTRA\~WRL0863.tmp
C:\Peng\EXTRA\~WRL0864.tmp
C:\Peng\EXTRA\~WRL0920.tmp
C:\Peng\EXTRA\~WRL0922.tmp
C:\Peng\EXTRA\~WRL0965.tmp
C:\Peng\EXTRA\~WRL0967.tmp
C:\Peng\EXTRA\~WRL0984.tmp
C:\Peng\EXTRA\~WRL0991.tmp
C:\Peng\EXTRA\~WRL0998.tmp
C:\Peng\EXTRA\~WRL1001.tmp
C:\Peng\EXTRA\~WRL1013.tmp
C:\Peng\EXTRA\~WRL1019.tmp
C:\Peng\EXTRA\~WRL1040.tmp
C:\Peng\EXTRA\~WRL1050.tmp
C:\Peng\EXTRA\~WRL1070.tmp
C:\Peng\EXTRA\~WRL1071.tmp
C:\Peng\EXTRA\~WRL1079.tmp
C:\Peng\EXTRA\~WRL1080.tmp
C:\Peng\EXTRA\~WRL1086.tmp
C:\Peng\EXTRA\~WRL1089.tmp
C:\Peng\EXTRA\~WRL1104.tmp
C:\Peng\EXTRA\~WRL1115.tmp
C:\Peng\EXTRA\~WRL1118.tmp
C:\Peng\EXTRA\~WRL1121.tmp
C:\Peng\EXTRA\~WRL1123.tmp
C:\Peng\EXTRA\~WRL1125.tmp
C:\Peng\EXTRA\~WRL1135.tmp
C:\Peng\EXTRA\~WRL1152.tmp
C:\Peng\EXTRA\~WRL1153.tmp
C:\Peng\EXTRA\~WRL1188.tmp
C:\Peng\EXTRA\~WRL1199.tmp
C:\Peng\EXTRA\~WRL1236.tmp
C:\Peng\EXTRA\~WRL1238.tmp
C:\Peng\EXTRA\~WRL1240.tmp
C:\Peng\EXTRA\~WRL1247.tmp
C:\Peng\EXTRA\~WRL1277.tmp
C:\Peng\EXTRA\~WRL1282.tmp
C:\Peng\EXTRA\~WRL1287.tmp
C:\Peng\EXTRA\~WRL1307.tmp
C:\Peng\EXTRA\~WRL1311.tmp
C:\Peng\EXTRA\~WRL1320.tmp
C:\Peng\EXTRA\~WRL1340.tmp
C:\Peng\EXTRA\~WRL1359.tmp
C:\Peng\EXTRA\~WRL1385.tmp
C:\Peng\EXTRA\~WRL1387.tmp
C:\Peng\EXTRA\~WRL1391.tmp
C:\Peng\EXTRA\~WRL1392.tmp
C:\Peng\EXTRA\~WRL1396.tmp
C:\Peng\EXTRA\~WRL1457.tmp
C:\Peng\EXTRA\~WRL1482.tmp
C:\Peng\EXTRA\~WRL1490.tmp
C:\Peng\EXTRA\~WRL1515.tmp
C:\Peng\EXTRA\~WRL1532.tmp
C:\Peng\EXTRA\~WRL1541.tmp
C:\Peng\EXTRA\~WRL1551.tmp
C:\Peng\EXTRA\~WRL1554.tmp
C:\Peng\EXTRA\~WRL1564.tmp
C:\Peng\EXTRA\~WRL1578.tmp
C:\Peng\EXTRA\~WRL1611.tmp
C:\Peng\EXTRA\~WRL1617.tmp
C:\Peng\EXTRA\~WRL1625.tmp
C:\Peng\EXTRA\~WRL1629.tmp
C:\Peng\EXTRA\~WRL1631.tmp
C:\Peng\EXTRA\~WRL1639.tmp
C:\Peng\EXTRA\~WRL1646.tmp
C:\Peng\EXTRA\~WRL1653.tmp
C:\Peng\EXTRA\~WRL1661.tmp
C:\Peng\EXTRA\~WRL1672.tmp
C:\Peng\EXTRA\~WRL1690.tmp
C:\Peng\EXTRA\~WRL1697.tmp
C:\Peng\EXTRA\~WRL1700.tmp
C:\Peng\EXTRA\~WRL1750.tmp
C:\Peng\EXTRA\~WRL1823.tmp
C:\Peng\EXTRA\~WRL1835.tmp
C:\Peng\EXTRA\~WRL1837.tmp
C:\Peng\EXTRA\~WRL1854.tmp
C:\Peng\EXTRA\~WRL1873.tmp
C:\Peng\EXTRA\~WRL1887.tmp
C:\Peng\EXTRA\~WRL1888.tmp
C:\Peng\EXTRA\~WRL1906.tmp
C:\Peng\EXTRA\~WRL1909.tmp
C:\Peng\EXTRA\~WRL1910.tmp
C:\Peng\EXTRA\~WRL1912.tmp
C:\Peng\EXTRA\~WRL1922.tmp
C:\Peng\EXTRA\~WRL1964.tmp
C:\Peng\EXTRA\~WRL1980.tmp
C:\Peng\EXTRA\~WRL1982.tmp
C:\Peng\EXTRA\~WRL1994.tmp
C:\Peng\EXTRA\~WRL1996.tmp
C:\Peng\EXTRA\~WRL2021.tmp
C:\Peng\EXTRA\~WRL2033.tmp
C:\Peng\EXTRA\~WRL2043.tmp
C:\Peng\EXTRA\~WRL2059.tmp
C:\Peng\EXTRA\~WRL2066.tmp
C:\Peng\EXTRA\~WRL2077.tmp
C:\Peng\EXTRA\~WRL2081.tmp
C:\Peng\EXTRA\~WRL2094.tmp
C:\Peng\EXTRA\~WRL2104.tmp
C:\Peng\EXTRA\~WRL2117.tmp
C:\Peng\EXTRA\~WRL2119.tmp
C:\Peng\EXTRA\~WRL2190.tmp
C:\Peng\EXTRA\~WRL2192.tmp
C:\Peng\EXTRA\~WRL2194.tmp
C:\Peng\EXTRA\~WRL2206.tmp
C:\Peng\EXTRA\~WRL2215.tmp
C:\Peng\EXTRA\~WRL2218.tmp
C:\Peng\EXTRA\~WRL2223.tmp
C:\Peng\EXTRA\~WRL2235.tmp
C:\Peng\EXTRA\~WRL2251.tmp
C:\Peng\EXTRA\~WRL2285.tmp
C:\Peng\EXTRA\~WRL2293.tmp
C:\Peng\EXTRA\~WRL2326.tmp
C:\Peng\EXTRA\~WRL2328.tmp
C:\Peng\EXTRA\~WRL2329.tmp
C:\Peng\EXTRA\~WRL2372.tmp
C:\Peng\EXTRA\~WRL2374.tmp
C:\Peng\EXTRA\~WRL2382.tmp
C:\Peng\EXTRA\~WRL2385.tmp
C:\Peng\EXTRA\~WRL2389.tmp
C:\Peng\EXTRA\~WRL2426.tmp
C:\Peng\EXTRA\~WRL2431.tmp
C:\Peng\EXTRA\~WRL2441.tmp
C:\Peng\EXTRA\~WRL2446.tmp
C:\Peng\EXTRA\~WRL2450.tmp
C:\Peng\EXTRA\~WRL2453.tmp
C:\Peng\EXTRA\~WRL2470.tmp
C:\Peng\EXTRA\~WRL2484.tmp
C:\Peng\EXTRA\~WRL2485.tmp
C:\Peng\EXTRA\~WRL2531.tmp
C:\Peng\EXTRA\~WRL2537.tmp
C:\Peng\EXTRA\~WRL2596.tmp
C:\Peng\EXTRA\~WRL2613.tmp
C:\Peng\EXTRA\~WRL2618.tmp
C:\Peng\EXTRA\~WRL2634.tmp
C:\Peng\EXTRA\~WRL2650.tmp
C:\Peng\EXTRA\~WRL2653.tmp
C:\Peng\EXTRA\~WRL2679.tmp
C:\Peng\EXTRA\~WRL2680.tmp
C:\Peng\EXTRA\~WRL2685.tmp
C:\Peng\EXTRA\~WRL2692.tmp
C:\Peng\EXTRA\~WRL2710.tmp
C:\Peng\EXTRA\~WRL2723.tmp
C:\Peng\EXTRA\~WRL2752.tmp
C:\Peng\EXTRA\~WRL2759.tmp
C:\Peng\EXTRA\~WRL2775.tmp
C:\Peng\EXTRA\~WRL2800.tmp
C:\Peng\EXTRA\~WRL2813.tmp
C:\Peng\EXTRA\~WRL2834.tmp
C:\Peng\EXTRA\~WRL2837.tmp
C:\Peng\EXTRA\~WRL2878.tmp
C:\Peng\EXTRA\~WRL2879.tmp
C:\Peng\EXTRA\~WRL2891.tmp
C:\Peng\EXTRA\~WRL2896.tmp
C:\Peng\EXTRA\~WRL2909.tmp
C:\Peng\EXTRA\~WRL2910.tmp
C:\Peng\EXTRA\~WRL2911.tmp
C:\Peng\EXTRA\~WRL2914.tmp
C:\Peng\EXTRA\~WRL2922.tmp
C:\Peng\EXTRA\~WRL2923.tmp
C:\Peng\EXTRA\~WRL2941.tmp
C:\Peng\EXTRA\~WRL2942.tmp
C:\Peng\EXTRA\~WRL2959.tmp
C:\Peng\EXTRA\~WRL2986.tmp
C:\Peng\EXTRA\~WRL2998.tmp
C:\Peng\EXTRA\~WRL3022.tmp
C:\Peng\EXTRA\~WRL3045.tmp
C:\Peng\EXTRA\~WRL3078.tmp
C:\Peng\EXTRA\~WRL3096.tmp
C:\Peng\EXTRA\~WRL3105.tmp
C:\Peng\EXTRA\~WRL3107.tmp
C:\Peng\EXTRA\~WRL3108.tmp
C:\Peng\EXTRA\~WRL3110.tmp
C:\Peng\EXTRA\~WRL3117.tmp
C:\Peng\EXTRA\~WRL3118.tmp
C:\Peng\EXTRA\~WRL3119.tmp
C:\Peng\EXTRA\~WRL3125.tmp
C:\Peng\EXTRA\~WRL3134.tmp
C:\Peng\EXTRA\~WRL3153.tmp
C:\Peng\EXTRA\~WRL3181.tmp
C:\Peng\EXTRA\~WRL3185.tmp
C:\Peng\EXTRA\~WRL3195.tmp
C:\Peng\EXTRA\~WRL3197.tmp
C:\Peng\EXTRA\~WRL3249.tmp
C:\Peng\EXTRA\~WRL3257.tmp
C:\Peng\EXTRA\~WRL3273.tmp
C:\Peng\EXTRA\~WRL3274.tmp
C:\Peng\EXTRA\~WRL3276.tmp
C:\Peng\EXTRA\~WRL3279.tmp
C:\Peng\EXTRA\~WRL3294.tmp
C:\Peng\EXTRA\~WRL3355.tmp
C:\Peng\EXTRA\~WRL3370.tmp
C:\Peng\EXTRA\~WRL3383.tmp
C:\Peng\EXTRA\~WRL3394.tmp
C:\Peng\EXTRA\~WRL3424.tmp
C:\Peng\EXTRA\~WRL3428.tmp
C:\Peng\EXTRA\~WRL3431.tmp
C:\Peng\EXTRA\~WRL3453.tmp
C:\Peng\EXTRA\~WRL3461.tmp
C:\Peng\EXTRA\~WRL3473.tmp
C:\Peng\EXTRA\~WRL3478.tmp
C:\Peng\EXTRA\~WRL3479.tmp
C:\Peng\EXTRA\~WRL3513.tmp
C:\Peng\EXTRA\~WRL3539.tmp
C:\Peng\EXTRA\~WRL3544.tmp
C:\Peng\EXTRA\~WRL3590.tmp
C:\Peng\EXTRA\~WRL3621.tmp
C:\Peng\EXTRA\~WRL3651.tmp
C:\Peng\EXTRA\~WRL3657.tmp
C:\Peng\EXTRA\~WRL3664.tmp
C:\Peng\EXTRA\~WRL3668.tmp
C:\Peng\EXTRA\~WRL3674.tmp
C:\Peng\EXTRA\~WRL3687.tmp
C:\Peng\EXTRA\~WRL3693.tmp
C:\Peng\EXTRA\~WRL3705.tmp
C:\Peng\EXTRA\~WRL3718.tmp
C:\Peng\EXTRA\~WRL3720.tmp
C:\Peng\EXTRA\~WRL3754.tmp
C:\Peng\EXTRA\~WRL3774.tmp
C:\Peng\EXTRA\~WRL3775.tmp
C:\Peng\EXTRA\~WRL3791.tmp
C:\Peng\EXTRA\~WRL3793.tmp
C:\Peng\EXTRA\~WRL3807.tmp
C:\Peng\EXTRA\~WRL3821.tmp
C:\Peng\EXTRA\~WRL3841.tmp
C:\Peng\EXTRA\~WRL3852.tmp
C:\Peng\EXTRA\~WRL3858.tmp
C:\Peng\EXTRA\~WRL3880.tmp
C:\Peng\EXTRA\~WRL3887.tmp
C:\Peng\EXTRA\~WRL3893.tmp
C:\Peng\EXTRA\~WRL3900.tmp
C:\Peng\EXTRA\~WRL3925.tmp
C:\Peng\EXTRA\~WRL3937.tmp
C:\Peng\EXTRA\~WRL3954.tmp
C:\Peng\EXTRA\~WRL3967.tmp
C:\Peng\EXTRA\~WRL3994.tmp
C:\Peng\EXTRA\~WRL3998.tmp
C:\Peng\EXTRA\~WRL4018.tmp
C:\Peng\EXTRA\~WRL4019.tmp
C:\Peng\EXTRA\~WRL4020.tmp
C:\Peng\EXTRA\~WRL4022.tmp
C:\Peng\EXTRA\~WRL4027.tmp
C:\Peng\EXTRA\~WRL4038.tmp
C:\Peng\EXTRA\~WRL4057.tmp
C:\Peng\EXTRA\~WRL4071.tmp
C:\Peng\EXTRA\~WRL4077.tmp
C:\Peng\EXTRA\~WRL4078.tmp
C:\Peng\EXTRA\~WRL4100.tmp

Finished

2. ComboFix log: <———————————————————————————————-

ComboFix 07-08-05.4 - "Administrator" 08/05/2007 11:02:03.1 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.29 [GMT -4:00]


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINNT\NDNuninstall4_80.exe


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-05 11:02 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_29c.dat
2007-08-05 11:00 51,200 –a—— C:\WINNT\nircmd.exe
2007-08-05 09:16 d——– C:\WINNT\ERUNT


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

10/14/04 08:59a 226266 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\tvmknwrd.dll
10/06/92 07:56p 59586 –a–c— C:\Program Files\NRCOPY.EXE
10/04/92 12:18p 50719 –a–c— C:\Program Files\NRHELP.TXT
10/04/92 12:17p 60024 –a–c— C:\Program Files\NRHELP.COM
09/26/04 11:30p 24856 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
09/25/92 09:57p 41213 –a–c— C:\Program Files\NRF20OTH.AR
09/25/92 09:56p 155086 –a–c— C:\Program Files\NRF20REC.AR
09/25/92 09:56p 122105 –a–c— C:\Program Files\NRF20EXA.AR
09/25/92 09:09p 9590 –a–c— C:\Program Files\INSTALL.DAT
09/02/02 04:58p 2837 –a–c— C:\Program Files\INSTALL.LOG
09/02/02 04:25p 271 —h-c— C:\Program Files\desktop.ini
09/02/02 04:25p 21952 —h-c— C:\Program Files\folder.htt
06/26/04 10:23p 169504 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\shb.dat
05/10/92 10:34p 141068 –a–c— C:\Program Files\INSTALL.EXE
05/10/92 02:42p 48 –a–c— C:\Program Files\DISK.ID
03/16/03 12:54p 14848 –a–c— C:\Program Files\potdiff.xls
03/01/03 04:37p 110886 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\gykffmh.exe


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6548A94-6C19-DD6F-1F26-B300B04EEE47}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 03:05p C:\WINNT\system32\mobsync.exe]
"LoadQM"="loadqm.exe" [05/03/00 06:23p C:\WINNT\loadqm.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [01/11/01 05:00a]
"hpfsched"="C:\WINNT\hpfsched.exe" [03/03/99 05:39a]
"WinampAgent"="C:\Program Files\Winamp2\Winampa.exe" [03/20/02 03:15a]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/22/03 01:21p]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/06 07:58p]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [08/01/04 05:47p]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/24/07 08:20a]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [03/20/07 08:24p]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-23 21:00:53]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2003-11-29 23:44:47]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 11:10:00]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\Calvin_And_Hobbes_Dance.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\10]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\chamee.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\11]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\spiderman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\12]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\monkeybanana.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\13]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\dora15.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\14]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\penguin2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\moecharacter.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\kissin_susie.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman3.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\sunsunsun.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish3.gif
FriendlyName=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\PROGRA~1\Qualcomm\Eudora\EuShlExt.dll [04/04/02 02:00p 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 PrtSeqRd;PrtSeqRd;C:\WINNT\system32\drivers\PrtSeqRd.sys
R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R0 ultra66;ultra66;C:\WINNT\system32\DRIVERS\ultra66.sys
R1 cdudf;cdudf;C:\WINNT\system32\drivers\cdudf.sys
R1 pwd_2K;pwd_2K;C:\WINNT\system32\drivers\pwd_2K.sys
R1 UdfReadr;UdfReadr;C:\WINNT\system32\drivers\UdfReadr.sys
R2 HPFECP20;HPFECP20;C:\WINNT\system32\drivers\HPFECP20.SYS
R3 admjoy;Aureal Game Port Enumerator;C:\WINNT\system32\DRIVERS\admjoy.sys
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys
R3 mf;mf;C:\WINNT\system32\DRIVERS\mf.sys
R3 mmc_2K;mmc_2K;C:\WINNT\system32\drivers\mmc_2K.sys
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINNT\system32\drivers\adm8830.sys
R3 Winacpci;Winacpci;C:\WINNT\system32\DRIVERS\winacpci.sys
S2 .NET Connection Service;.NET Framework Service;C:\WINNT\svchost.exe
S3 dvd_2K;dvd_2K;C:\WINNT\system32\drivers\dvd_2K.sys
S3 MPE;BDA MPE Filter;C:\WINNT\system32\DRIVERS\MPE.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINNT\system32\DRIVERS\usbscan.sys
S3 USB_RNDIS_2K;Westell WireSpeed Dual Connect Modem;C:\WINNT\system32\DRIVERS\usb8023k.sys


Contents of the 'Scheduled Tasks' folder
2006-12-27 17:00:45 C:\WINNT\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 11:08:37
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 08/05/2007 11:10:01
C:\ComboFix-quarantined-files.txt … 08/05/07 11:09a

— E O F —


3. THe new HijackThis log after executing SDFix and ComboFix: <—————————————-

Logfile of HijackThis v1.99.1
Scan saved at 11:30:21 AM, on 8/5/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ZipToA.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Winamp2\Winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\WINNT\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINNT\system32\NOTEPAD.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.lib.berkeley.edu:7777/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://proxy.lib.berkeley.edu:7777/
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: (no name) - {C6548A94-6C19-DD6F-1F26-B300B04EEE47} - (no file)
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O3 - Toolbar: (no name) - {2A82A7AA-87E3-CDE8-13FC-CCE37BB3D5CC} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp2\Winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1171074499735
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINNT\svchost.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\System32\ZipToA.exe
Hi

Open Notepad and Copy/Paste the text in the codebox below into it:

File::
C:\DOCUME~1\ADMINI~1\APPLIC~1\tvmknwrd.dll
C:\DOCUME~1\ADMINI~1\APPLIC~1\gykffmh.exe

Folder::
C:\SDFix

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {C6548A94-6C19-DD6F-1F26-B300B04EEE47} - (no file)
O3 - Toolbar: (no name) - {2A82A7AA-87E3-CDE8-13FC-CCE37BB3D5CC} - (no file)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)



WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.


Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.
WeatherBug is a system tray icon that offers weather information and includes built-in ads. WeatherBug is controlled by AWS Convergence Technologies (weatherbugmedia.com). There is some controversy over whether WeatherBug should be targeted by anti-parasite software. AWS strongly deny their software is ‘spyware’, and by the definition used here, it is not, as it does not leak information back to its controlling servers. However, WeatherBug has in the past been silently installed by the FavoriteMan parasite and Freeze.com screensavers, and more recently has been bundled by software such as AIM and Blubster. This makes it ‘unsolicited’, and since it is installed to raise money for its creators through the built-in ads it is certainly ‘commercial’. So it does meet the definition for ‘parasite’: unsolicited commercial software. It is nonetheless listed as a borderline case because it is not overtly harmful and many people do install it deliberately. WeatherBug bundles the MySearch parasite in its standalone distribution and has in the past, installed Gator and SVAPlayer.

I recommend that you uninstall WeatherBugand choose one of these alternatives:
Weather Pulse
Weather Watcher
or
Get mozilla Firefox and then get FORECASTFOX!!!
or check the weather at these websites:
Weather Street: US Weather
Intellicast
To uninstall WeatherBug:
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight WeatherBug, click Remove.
  • Close the Add or Remove Programs and the Control Panel windows.
Post back with the log from the Combofix and a new HijackThis log, and let me know how the computer is behaving now. Also, looking at your last Combo log, are those pictures all downloaded by you?
Scotty,

After creating CFScript and dragging to ComboFix, a log is generated as below:

ComboFix 07-08-05.4 - "Administrator" 08/05/2007 14:06:10.2 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.29 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt

FILE::
C:\DOCUME~1\ADMINI~1\APPLIC~1\tvmknwrd.dll
C:\DOCUME~1\ADMINI~1\APPLIC~1\gykffmh.exe


((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\DOCUME~1\ADMINI~1\APPLIC~1\gykffmh.exe
C:\DOCUME~1\ADMINI~1\APPLIC~1\tvmknwrd.dll
C:\SDFix
C:\SDFix\apps\assosfix.reg
C:\SDFix\apps\cliptext.exe
C:\SDFix\apps\download.exe
C:\SDFix\apps\dummy.sys
C:\SDFix\apps\Enable_Command_Prompt.reg
C:\SDFix\apps\ERDNT.E_E
C:\SDFix\apps\ERDNTDOS.LOC
C:\SDFix\apps\ERDNTWIN.LOC
C:\SDFix\apps\ERUNT.EXE
C:\SDFix\apps\ERUNT.LOC
C:\SDFix\apps\fix.reg
C:\SDFix\apps\FixBH.reg
C:\SDFix\apps\FIXCU.reg
C:\SDFix\apps\FIXLM.reg
C:\SDFix\apps\FixPath.exe
C:\SDFix\apps\FixRedir.reg
C:\SDFix\apps\FixWebCheck.reg
C:\SDFix\apps\fixXP.reg
C:\SDFix\apps\FixXPsp2.reg
C:\SDFix\apps\HPFix.reg
C:\SDFix\apps\HPFix2.reg
C:\SDFix\apps\leg2.txt
C:\SDFix\apps\legacy.txt
C:\SDFix\apps\legacybk.txt
C:\SDFix\apps\locate.com
C:\SDFix\apps\LS.exe
C:\SDFix\apps\MD5File.exe
C:\SDFix\apps\moveex.exe
C:\SDFix\apps\MyGcpvFix.reg
C:\SDFix\apps\MyGkFix2.reg
C:\SDFix\apps\Process.exe
C:\SDFix\apps\RegDACL.exe
C:\SDFix\apps\Rem.txt
C:\SDFix\apps\Rem2.txt
C:\SDFix\apps\Replace\W2K.exe
C:\SDFix\apps\Replace\XP.exe
C:\SDFix\apps\Reset_AppInit_DLLs.reg
C:\SDFix\apps\RestartIt!.exe
C:\SDFix\apps\Restore_SecurityCenter.reg
C:\SDFix\apps\Restore_SharedAccess.reg
C:\SDFix\apps\sc.exe
C:\SDFix\apps\SF.exe
C:\SDFix\apps\shutdown.exe
C:\SDFix\apps\srv2.txt
C:\SDFix\apps\svc.txt
C:\SDFix\apps\svcbk.txt
C:\SDFix\apps\swreg.exe
C:\SDFix\apps\swsc.exe
C:\SDFix\apps\unzip.exe
C:\SDFix\apps\zip.exe
C:\SDFix\backups\attrib.exe
C:\SDFix\backups\backupreg.zip
C:\SDFix\backups\backups.zip
C:\SDFix\backups\find.exe
C:\SDFix\backups\findstr.exe
C:\SDFix\backups\HOSTS
C:\SDFix\backups\regedit.exe
C:\SDFix\catchme.exe
C:\SDFix\dummy.sys
C:\SDFix\Report.txt
C:\SDFix\RunThis.bat
C:\SDFix\SDFIX_ReadMe_Online.url


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-05 14:06 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_294.dat
2007-08-05 11:00 51,200 –a—— C:\WINNT\nircmd.exe
2007-08-05 09:16 d——– C:\WINNT\ERUNT


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

10/06/92 07:56p 59586 –a–c— C:\Program Files\NRCOPY.EXE
10/04/92 12:18p 50719 –a–c— C:\Program Files\NRHELP.TXT
10/04/92 12:17p 60024 –a–c— C:\Program Files\NRHELP.COM
09/26/04 11:30p 24856 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
09/25/92 09:57p 41213 –a–c— C:\Program Files\NRF20OTH.AR
09/25/92 09:56p 155086 –a–c— C:\Program Files\NRF20REC.AR
09/25/92 09:56p 122105 –a–c— C:\Program Files\NRF20EXA.AR
09/25/92 09:09p 9590 –a–c— C:\Program Files\INSTALL.DAT
09/02/02 04:58p 2837 –a–c— C:\Program Files\INSTALL.LOG
09/02/02 04:25p 271 —h-c— C:\Program Files\desktop.ini
09/02/02 04:25p 21952 —h-c— C:\Program Files\folder.htt
06/26/04 10:23p 169504 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\shb.dat
05/10/92 10:34p 141068 –a–c— C:\Program Files\INSTALL.EXE
05/10/92 02:42p 48 –a–c— C:\Program Files\DISK.ID
03/16/03 12:54p 14848 –a–c— C:\Program Files\potdiff.xls


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6548A94-6C19-DD6F-1F26-B300B04EEE47}]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 03:05p C:\WINNT\system32\mobsync.exe]
"LoadQM"="loadqm.exe" [05/03/00 06:23p C:\WINNT\loadqm.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [01/11/01 05:00a]
"hpfsched"="C:\WINNT\hpfsched.exe" [03/03/99 05:39a]
"WinampAgent"="C:\Program Files\Winamp2\Winampa.exe" [03/20/02 03:15a]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/22/03 01:21p]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/06 07:58p]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [08/01/04 05:47p]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/24/07 08:20a]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [03/20/07 08:24p]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-23 21:00:53]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2003-11-29 23:44:47]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 11:10:00]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\Calvin_And_Hobbes_Dance.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\10]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\chamee.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\11]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\spiderman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\12]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\monkeybanana.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\13]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\dora15.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\14]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\penguin2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\moecharacter.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\kissin_susie.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman3.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\sunsunsun.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish3.gif
FriendlyName=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\PROGRA~1\Qualcomm\Eudora\EuShlExt.dll [04/04/02 02:00p 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 PrtSeqRd;PrtSeqRd;C:\WINNT\system32\drivers\PrtSeqRd.sys
R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R0 ultra66;ultra66;C:\WINNT\system32\DRIVERS\ultra66.sys
R1 cdudf;cdudf;C:\WINNT\system32\drivers\cdudf.sys
R1 pwd_2K;pwd_2K;C:\WINNT\system32\drivers\pwd_2K.sys
R1 UdfReadr;UdfReadr;C:\WINNT\system32\drivers\UdfReadr.sys
R2 HPFECP20;HPFECP20;C:\WINNT\system32\drivers\HPFECP20.SYS
R3 admjoy;Aureal Game Port Enumerator;C:\WINNT\system32\DRIVERS\admjoy.sys
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys
R3 mf;mf;C:\WINNT\system32\DRIVERS\mf.sys
R3 mmc_2K;mmc_2K;C:\WINNT\system32\drivers\mmc_2K.sys
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINNT\system32\drivers\adm8830.sys
R3 Winacpci;Winacpci;C:\WINNT\system32\DRIVERS\winacpci.sys
S2 .NET Connection Service;.NET Framework Service;C:\WINNT\svchost.exe
S3 dvd_2K;dvd_2K;C:\WINNT\system32\drivers\dvd_2K.sys
S3 MPE;BDA MPE Filter;C:\WINNT\system32\DRIVERS\MPE.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINNT\system32\DRIVERS\usbscan.sys
S3 USB_RNDIS_2K;Westell WireSpeed Dual Connect Modem;C:\WINNT\system32\DRIVERS\usb8023k.sys

*Newly Created Service* - IPNAT
*Newly Created Service* - RASAUTO
*Newly Created Service* - SHAREDACCESS

Contents of the 'Scheduled Tasks' folder
2006-12-27 17:00:45 C:\WINNT\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 14:14:58
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 08/05/2007 14:16:30
C:\ComboFix-quarantined-files.txt … 08/05/07 02:15p
C:\ComboFix2.txt … 08/05/07 11:10a

— E O F —
<—————————————————————————————————————–>

After running HijackThis with Do A System Scan Only, I did find the four files were there. I then
checked these four files and run Fix Checked. Re-run HijackThis with scanning, a log is generated below:

Logfile of HijackThis v1.99.1
Scan saved at 2:44:48 PM, on 8/5/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\ZipToA.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Winamp2\Winampa.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\NetZero\exec.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINNT\explorer.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://proxy.lib.berkeley.edu:7777/proxy.pac
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http://proxy.lib.berkeley.edu:7777/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: ZeroBar - {F5735C15-1FB2-41FE-BA12-242757E69DDE} - C:\Program Files\NetZero\Toolbar.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [LoadQM] loadqm.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [hpfsched] C:\WINNT\hpfsched.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp2\Winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Image Transfer.lnk = C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\System32\Shdocvw.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/200212…meInstaller.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1171074499735
O20 - Winlogon Notify: NavLogon - C:\WINNT\System32\NavLogon.dll
O23 - Service: .NET Framework Service (.NET Connection Service) - Unknown owner - C:\WINNT\svchost.exe (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p1\webserver\bin\win32\matlabserver.exe
O23 - Service: ZipToA - Iomega Corporation - C:\WINNT\System32\ZipToA.exe

<—————————————————————————————————————->

It looks like the four O2 and O3's files are removed. I will reboot my computer to see if the hijack is still there.

Peng
Hi

One question. Is NetZero your ISP?

I suggest printing out, or copying to Notepad, the following instructions.

Download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates

Open Notepad and Copy/Paste the text in the codebox below into it:

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6548A94-6C19-DD6F-1F26-B300B04EEE47}]

Save this as "CFScript"

[external image: Posted Image]


Refering to the picture above, drag CFScript into ComboFix.exe
Then post the resultant log.

Reboot into SAFE MODEBy pressing the F8 key right when Windows starts, usually right after you hear your computer
beep when you reboot it (some versions of windows will display 'Starting Windows' with a grey progress bar)
you will be brought to a menu where you can choose to boot into safe mode.

If it does not work on the first try, reboot and try again, as you have to be quick when you press it.

I have found that during boot up, right after the computer displays the equipment , memory, etc
installed on your computer, if you start lightly tapping the F8 key, the system will usually display the menu.

Run a scan with AVG.
  • Click on Scanner
    • Click on the Settings tab, and set the following settings.
      • How to act
      • Click on Recommended actions, and set to Quarantine.
    • How to scan
      • Check all options.
    • Possibly unwanted software.
      • Check all options.
    • Reports
      • Check Do not automatically generate reports after every scan.
    • What to scan
      • Check Scan every file.
  • Click on the Scan tab.
    • Click on Complete System Scan and the scan will begin.
    • When the scan has finished
    • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
    • At the bottom of the window click on the Apply all Actions button.
Note: Don't save the report before you hit the Apply action button.

Close AVG Anti-Spyware.

AVG will save a report in the following location C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Then reboot back into Normal Mode and post back with the CFScript log and the AVG report.
Scotty,

My ISP is Verizon not NetZero.

Below is the new log from CFScript + ComboFix:

ComboFix 07-08-05.4 - "Administrator" 08/05/2007 15:41:22.3 - NTFSx86
Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.19 [GMT -4:00]
Command switches used :: C:\Documents and Settings\Administrator\Desktop\CFScript.txt


((((((((((((((((((((((((( Files Created from 2007-07-05 to 2007-08-05 )))))))))))))))))))))))))))))))


2007-08-05 15:41 16,384 –a—-t- C:\WINNT\system32\Perflib_Perfdata_290.dat
2007-08-05 15:31 10,872 –a—— C:\WINNT\system32\drivers\AvgAsCln.sys
2007-08-05 11:00 51,200 –a—— C:\WINNT\nircmd.exe
2007-08-05 09:16 d——– C:\WINNT\ERUNT


(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

10/06/92 07:56p 59586 –a–c— C:\Program Files\NRCOPY.EXE
10/04/92 12:18p 50719 –a–c— C:\Program Files\NRHELP.TXT
10/04/92 12:17p 60024 –a–c— C:\Program Files\NRHELP.COM
09/26/04 11:30p 24856 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\GDIPFONTCACHEV1.DAT
09/25/92 09:57p 41213 –a–c— C:\Program Files\NRF20OTH.AR
09/25/92 09:56p 155086 –a–c— C:\Program Files\NRF20REC.AR
09/25/92 09:56p 122105 –a–c— C:\Program Files\NRF20EXA.AR
09/25/92 09:09p 9590 –a–c— C:\Program Files\INSTALL.DAT
09/02/02 04:58p 2837 –a–c— C:\Program Files\INSTALL.LOG
09/02/02 04:25p 271 —h-c— C:\Program Files\desktop.ini
09/02/02 04:25p 21952 —h-c— C:\Program Files\folder.htt
06/26/04 10:23p 169504 –a–c— C:\DOCUME~1\ADMINI~1\APPLIC~1\shb.dat
05/10/92 10:34p 141068 –a–c— C:\Program Files\INSTALL.EXE
05/10/92 02:42p 48 –a–c— C:\Program Files\DISK.ID
03/16/03 12:54p 14848 –a–c— C:\Program Files\potdiff.xls


((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))


*Note* empty entries & legit default entries are not shown

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"="mobsync.exe" [06/19/03 03:05p C:\WINNT\system32\mobsync.exe]
"LoadQM"="loadqm.exe" [05/03/00 06:23p C:\WINNT\loadqm.exe]
"AdaptecDirectCD"="C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe" [01/11/01 05:00a]
"hpfsched"="C:\WINNT\hpfsched.exe" [03/03/99 05:39a]
"WinampAgent"="C:\Program Files\Winamp2\Winampa.exe" [03/20/02 03:15a]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [02/22/03 01:21p]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [10/25/06 07:58p]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [06/11/07 05:25a]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NetZero_uoltray"="C:\Program Files\NetZero\exec.exe" [08/01/04 05:47p]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [06/24/07 08:20a]
"RealPlayer"="C:\Program Files\Real\RealPlayer\realplay.exe" [03/20/07 08:24p]

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-03-23 21:00:53]
Image Transfer.lnk - C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe [2003-11-29 23:44:47]
WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2007-04-11 11:10:00]

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\Calvin_And_Hobbes_Dance.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\10]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\chamee.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\11]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\spiderman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\12]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\monkeybanana.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\13]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\dora15.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\14]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\penguin2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\moecharacter.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\kissin_susie.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\4]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\5]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\6]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickman3.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\7]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish2.gif
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\8]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\sunsunsun.jpg
FriendlyName=

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\9]
Source= C:\Documents and Settings\Administrator\My Documents\My Pictures\stickmanfish3.gif
FriendlyName=

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= C:\PROGRA~1\Qualcomm\Eudora\EuShlExt.dll [04/04/02 02:00p 77824]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sglfb.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\tga.sys]
@="Driver"

R0 PrtSeqRd;PrtSeqRd;C:\WINNT\system32\drivers\PrtSeqRd.sys
R0 SONYPVM1;Sony Memory Stick Driver(SONYPVM1);C:\WINNT\system32\DRIVERS\SONYPVM1.SYS
R0 ultra66;ultra66;C:\WINNT\system32\DRIVERS\ultra66.sys
R1 cdudf;cdudf;C:\WINNT\system32\drivers\cdudf.sys
R1 pwd_2K;pwd_2K;C:\WINNT\system32\drivers\pwd_2K.sys
R1 UdfReadr;UdfReadr;C:\WINNT\system32\drivers\UdfReadr.sys
R2 HPFECP20;HPFECP20;C:\WINNT\system32\drivers\HPFECP20.SYS
R3 admjoy;Aureal Game Port Enumerator;C:\WINNT\system32\DRIVERS\admjoy.sys
R3 EL90BC;3Com EtherLink XL B/C Adapter Driver;C:\WINNT\system32\DRIVERS\el90xbc5.sys
R3 mf;mf;C:\WINNT\system32\DRIVERS\mf.sys
R3 mmc_2K;mmc_2K;C:\WINNT\system32\drivers\mmc_2K.sys
R3 wdm_au8830;Aureal Vortex 8830 Audio Driver (WDM);C:\WINNT\system32\drivers\adm8830.sys
R3 Winacpci;Winacpci;C:\WINNT\system32\DRIVERS\winacpci.sys
S2 .NET Connection Service;.NET Framework Service;C:\WINNT\svchost.exe
S3 dvd_2K;dvd_2K;C:\WINNT\system32\drivers\dvd_2K.sys
S3 MPE;BDA MPE Filter;C:\WINNT\system32\DRIVERS\MPE.sys
S3 pmxscan;Visioneer USB Kernel;C:\WINNT\system32\DRIVERS\usbscan.sys
S3 USB_RNDIS_2K;Westell WireSpeed Dual Connect Modem;C:\WINNT\system32\DRIVERS\usb8023k.sys

*Newly Created Service* - AVG_ANTI-SPYWARE_DRIVER
*Newly Created Service* - AVG_ANTI-SPYWARE_GUARD

Contents of the 'Scheduled Tasks' folder
2006-12-27 17:00:45 C:\WINNT\Tasks\AppleSoftwareUpdate.job - C:\Program Files\Apple Software Update\SoftwareUpdate.exe

**************************************************************************

catchme 0.3.1061 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-08-05 15:51:06
Windows 5.0.2195 Service Pack 4 NTFS

scanning hidden processes …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************

Completion time: 08/05/2007 15:53:36
C:\ComboFix-quarantined-files.txt … 08/05/07 03:52p
C:\ComboFix2.txt … 08/05/07 02:16p
C:\ComboFix3.txt … 08/05/07 11:10a

— E O F —

<—————————————————————————————————————->

After executing AVG, the report is obtained as:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 5:07:31 PM 8/5/2007

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Ignored.
C:\WINNT\system32\chktrust.exe -> Adware.BargainBuddy : Ignored.
C:\WINNT\system32\javex80.vxd/C:/Program Files/NaviSearch/bin/nls.exe -> Adware.BargainBuddy : Ignored.
C:\WINNT\system32\javex80.vxd/C:/WINNT/System32/nvms.dll -> Adware.BargainBuddy : Ignored.
C:\WINNT\bsx32 -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ADBN3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ADTMI1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ADVC5.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ADVCTX2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIB9894.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIC29667.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASID12180.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIE17070.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIF29819.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIF4502.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIFA15376.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIFWH29233.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIG21943.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIGT10102.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIH21180.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIH7853.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASII21469.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIL18549.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASILS29399.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIM4381.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIM9740.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIOG19375.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIOT25456.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIPF1965.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIR21184.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIRE20082.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIS24110.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIS31590.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIT17011.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIT26116.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIW11211.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\ASIWS3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\AUTOS2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\BID1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\BingoRoom1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\CARD2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\CARS3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\DATE4.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\EECH1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\EML1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\FAST1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\FINC3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\FINC5.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\FLWR1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\FMND1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\HEBE3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\HERBS1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\HOGAR3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\INK1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\JOBS4.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\MORT5.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\MOVS2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\NEWS2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\SHOP2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\SPZ3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\TECH2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\TMP3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\TRVL6.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\UTONE2.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\VENUE1.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\WWW3.bsx -> Adware.BookedSpace : Ignored.
C:\WINNT\bsx32\XTFL2.bsx -> Adware.BookedSpace : Ignored.
C:\QooBox\Quarantine\C\DOCUME~1\ADMINI~1\APPLIC~1\gykffmh.exe.vir -> Adware.Casino : Ignored.
HKLM\SOFTWARE\DelFin -> Adware.Delfin : Ignored.
HKLM\SOFTWARE\DelFin\PromulGate -> Adware.Delfin : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\DelFin -> Adware.Delfin : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\DelFin\PromulGate -> Adware.Delfin : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\intexp -> Adware.IEPlugin : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\intexp\Config -> Adware.IEPlugin : Ignored.
HKU\S-1-5-21-1275210071-484763869-1708537768-500\Software\intexp\MyFileSystem2 -> Adware.IEPlugin : Ignored.
C:\QooBox\Quarantine\C\WINNT\NDNuninstall4_80.exe.vir -> Adware.NewDotNet : Ignored.
C:\WINNT\system32\SahAgent.exe_tobedeleted -> Adware.ShopAtHome : Ignored.
C:\WINNT\system32\SplWbr.dll -> Dropper.Small.abe : Ignored.
C:\WINNT\system32\thinInstOIT61MegaV2s.dll -> Dropper.Small.abe : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@247realmedia[1].txt -> TrackingCookie.247realmedia : Ignored.
:mozilla.292:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.293:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.294:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.295:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.296:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.297:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.298:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.299:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.300:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.301:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.302:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.303:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.304:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.305:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.306:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@adt.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@bizjournals.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@homestore.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@mathworks.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@meetupcom.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@microsoftgamestudio.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@adbrite[1].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Ignored.
:mozilla.147:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.150:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.378:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.84:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.85:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.93:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.364:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.365:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Adtech : Ignored.
:mozilla.309:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.310:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.311:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.312:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.313:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
:mozilla.307:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.385:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@bfast[1].txt -> TrackingCookie.Bfast : Ignored.
:mozilla.348:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Bluestreak : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Ignored.
:mozilla.24:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@burstnet[2].txt -> TrackingCookie.Burstnet : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.343:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Clickagents : Ignored.
:mozilla.344:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Clickagents : Ignored.
:mozilla.345:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Clickagents : Ignored.
:mozilla.346:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Clickagents : Ignored.
:mozilla.347:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Clickagents : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@clickbank[1].txt -> TrackingCookie.Clickbank : Ignored.
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\dodmc07z.slt\cookies.txt -> TrackingCookie.Clickzs : Ignored.
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\dodmc07z.slt\cookies.txt -> TrackingCookie.Clickzs : Ignored.
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Profiles\default\dodmc07z.slt\cookies.txt -> TrackingCookie.Clickzs : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Ignored.
:mozilla.94:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.95:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@com[2].txt -> TrackingCookie.Com : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Com : Ignored.
:mozilla.403:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
:mozilla.407:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : Ignored.
:mozilla.315:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.263:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Euniverseads : Ignored.
:mozilla.264:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Euniverseads : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@fortunecity[1].txt -> TrackingCookie.Fortunecity : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Hitslink : Ignored.
:mozilla.282:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
:mozilla.283:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Imrworldwide : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Information : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@linksynergy[2].txt -> TrackingCookie.Linksynergy : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Ignored.
:mozilla.308:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.314:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@mediaplex[2].txt -> TrackingCookie.Mediaplex : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Netflame : Ignored.
:mozilla.335:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.336:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.355:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@overture[1].txt -> TrackingCookie.Overture : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Overture : Ignored.
:mozilla.72:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Paypal : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Ignored.
:mozilla.324:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.325:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.326:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@questionmarket[1].txt -> TrackingCookie.Questionmarket : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Real : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@real[1].txt -> TrackingCookie.Real : Ignored.
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.20:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@realmedia[2].txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.239:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Revenue : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@revsci[1].txt -> TrackingCookie.Revsci : Ignored.
:mozilla.349:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@edge.ru4[1].txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.80:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.81:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.82:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.83:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@sexlist[1].txt -> TrackingCookie.Sexlist : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Sextracker : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@sextracker[1].txt -> TrackingCookie.Sextracker : Ignored.
:mozilla.182:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Sitestat : Ignored.
:mozilla.183:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Sitestat : Ignored.
:mozilla.438:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Sitestat : Ignored.
:mozilla.148:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.48:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.49:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.50:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@statcounter[2].txt -> TrackingCookie.Statcounter : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@tacoda[1].txt -> TrackingCookie.Tacoda : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Ignored.
C:\Documents and Settings\Administrator\Cookies\administrator@trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.319:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.320:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Valueclick : Ignored.
:mozilla.328:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.329:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.337:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.338:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Web-stat : Ignored.
:mozilla.339:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Web-stat : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Ignored.
:mozilla.434:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.435:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.440:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.441:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.234:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.235:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.56:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.57:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.58:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
C:\Documents and Settings\Administrator\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.108:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\wjnqcjds.default\cookies.txt -> TrackingCookie.Zedo : Ignored.


::Report end

<—————————————————————————————————————->

After installing AVG and rebooting PC with Normal mode, I still see the hijacked page.


Peng
Hi
  • Download GMER by GMER from here
  • Unzip it to a folder on your desktop
  • Double click on gmer.exe to launch GMER
  • If asked, allow the gmer.sys driver load
  • If it warns you about rootkit activity and asks if you want to run scan, click OK
  • If you don't get a warning then
    • Click the rootkit tab
    • Click Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerrk.txt
  • Click on the >>> tab
  • This will open up the rest of the tabs for you
  • Click on the Autostart tab
  • Click on Scan
  • Once the scan has finished, click copy
  • Paste the log into notepad using Ctrl+V
  • Save it to your desktop as gmerautos.txt
  • Copy and paste the contents of gmerautos.txt and gmerrk.txt as a reply to this topic
Scotty, I failed to get GMER report. When the SCAN was done, I clicked COPY and OK. The computer freezed. If I clicked CNTL+ALT+DEL, the hijacked page was shown. Please help. Peng
Hi Smokey

Try this instead.

Download F-Secure Blacklight (fsbl.exe) to the desktop from here.

Open it and click Accept Agreement.
Click Scan.
After the scan is complete, click Next, then Exit.
It will create a log on the desktop named fsbl-xxxxxxx.log (the xxxxxxx will be the date and time of the scan)
Save the log to your desktop. Paste the log in your next reply.
Scotty, Below is the log generated from fsbl scanning: 08/07/07 19:20:14 [Info]: BlackLight Engine 1.0.64 initialized 08/07/07 19:20:14 [Info]: OS: 5.0 build 2195 (Service Pack 4) 08/07/07 19:20:14 [Note]: 7019 4 08/07/07 19:20:14 [Note]: 7005 0 08/07/07 19:20:28 [Note]: 7006 0 08/07/07 19:20:28 [Note]: 7011 904 08/07/07 19:20:29 [Note]: 7026 0 08/07/07 19:20:29 [Note]: 7026 0 08/07/07 19:20:48 [Note]: FSRAW library version 1.7.1022 08/07/07 19:28:13 [Note]: 7007 0 Smokey

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI