Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93081 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

baseline


  • Please log in to reply
7 replies to this topic

#1 Metrix

Metrix

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 10 October 2007 - 11:28 AM

Thanks for looking

I've got three icons appeared on desktop, error cleaner, privacy protector, spyware protection
really slow computer
browser trying to connect to safeweb search
warnings about w32 looksky

I have windows xp home
internet explorer 7
Norton internet security (up to date but still let this rubbish in)

I have done a "hijack this log" and "smitfraud log"

THANKS FOR ANY HELP

Logfile of HijackThis v1.99.1
Scan saved at 16:50:52, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\Program Files\KService\KService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Startup Mechanic\StartupMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\home.7E5AAE5DA7AF432\Desktop\New Folder\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarerefer...=...6Ojg5&lid=2
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:\WINDOWS\bndsrdkq.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:\WINDOWS\netadv.dll
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Program Files\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [WUSB54Gv4] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: DTV Remote Control.lnk = C:\Program Files\V-Stream Multimedia\DVBT USB Utilities\DVBTRCtl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZCxdm491LDGB
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....rl/LSSupCtl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.mess.../Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager...unttracking.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/...h2.1.0.0.55.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163807485593
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoe...ggPublisher.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....rl/SymAData.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/...sh.1.0.0.89.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zon...er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {FFC0A381-8145-4CFD-A768-A2259776C179} (PTV xVectorMap Plugin 3.1) - http://xvectormap.pt...VectorMap31.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: sysdx - {4385E564-E6EA-41E4-8DBE-BFB97820F90D} - C:\WINDOWS\sysdx.dll
O21 - SSODL: msvb - {7923C99B-79F5-4215-BE3B-714714702C38} - C:\WINDOWS\msvb.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

Smitfraud log

SmitFraudFix v2.221

Scan done at 17:28:34.31, 10/10/2007
Run from C:\Documents and Settings\home.7E5AAE5DA7AF432\Desktop\New Folder\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Startup Mechanic\StartupMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\windows\system32\bonypdmss.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\cmd.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\privacy_danger FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\home.7E5AAE5DA7AF432


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\HOME~1.7E5\FAVORI~1

C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Online Security Test.url FOUND !
C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Error Cleaner.url FOUND !
C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Privacy Protector.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\HOME~1.7E5\Desktop\Error Cleaner.url FOUND !
C:\DOCUME~1\HOME~1.7E5\Desktop\Privacy Protector.url FOUND !
C:\DOCUME~1\HOME~1.7E5\Desktop\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: VIA Compatable Fast Ethernet Adapter - Packet Scheduler Miniport
DNS Server Search Order: 194.168.4.100
DNS Server Search Order: 194.168.8.100

HKLM\SYSTEM\CCS\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CCS\Services\Tcpip\..\{43CA6798-90D7-4B38-8E5C-F04E6FA98100}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{43CA6798-90D7-4B38-8E5C-F04E6FA98100}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=194.168.4.100 194.168.8.100


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

    Advertisements

Register to Remove


#2 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 10 October 2007 - 01:52 PM

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then <ENTER> to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted - if this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete...
Under Temporary Internet Files, click Delete files...

6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

7) Empty the Recycle Bin.

8) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

9) Reboot into Normal Mode.

10) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

Death to the salad eaters!

#3 Metrix

Metrix

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 11 October 2007 - 02:33 PM

Thanks again for your help

Everything went through as asked except the web tab in
start>control panel>display>desktop>customize desktop>web
There were no web pages and no security info
I had to run smitfraud as it was, as i couldn't update. The pc was impossible
to behave on the internet. (AVG updated remotely)

The pc is running alot better. problem icons gone, no pop-ups
Internet connects to what i want and seems stable.

Here are my logs
HJT
AVG
rapport
uninstall list
Logfile of HijackThis v1.99.1
Scan saved at 19:26:31, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\ntl\ntl Netguard\fws.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Startup Mechanic\StartupMonitor.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hyjack\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: MSVPS System - {3ADCBC16-19FA-4C59-9C22-E17C71B5FD7A} - C:\WINDOWS\bndsrdkq.dll
O2 - BHO: PopKill Class - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\ntl\ntl Netguard\pkR.dll
O2 - BHO: ZKBho Class - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\ntl\ntl Netguard\FBHR.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: The netadv - {ABF529BE-6245-465A-BBD4-238C4EAB0F0A} - C:\WINDOWS\netadv.dll
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [Startup Manager Scanner] C:\Program Files\Startup Mechanic\StartupMonitor.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [WUSB54Gv4] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Watch.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: DTV Remote Control.lnk = C:\Program Files\V-Stream Multimedia\DVBT USB Utilities\DVBTRCtl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZCxdm491LDGB
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....rl/LSSupCtl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.mess.../Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager...unttracking.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/...h2.1.0.0.55.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163807485593
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://javadl-esd.su...ows-i586-jc.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoe...ggPublisher.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....rl/SymAData.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/...sh.1.0.0.89.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zon...er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {FFC0A381-8145-4CFD-A768-A2259776C179} (PTV xVectorMap Plugin 3.1) - http://xvectormap.pt...VectorMap31.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: sysdx - {21743213-E074-4803-8B78-592174F53E1E} - C:\WINDOWS\sysdx.dll
O21 - SSODL: msvb - {FA6BBAA5-3895-4FB1-9B69-2162B9431ECB} - C:\WINDOWS\msvb.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Radialpoint Service (FWS) - Radialpoint Inc. - C:\Program Files\ntl\ntl Netguard\fws.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 19:19:37 11/10/2007

+ Scan result:



:mozilla.102:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.80:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.81:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.82:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.83:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.84:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.85:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.904:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.919:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.293:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.294:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.340:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.341:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.926:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.941:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.577:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.578:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.579:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.580:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.581:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.582:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.584:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.585:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.586:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.587:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.588:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.589:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.620:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.621:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.627:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.628:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.623:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.626:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.629:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.633:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.63:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.640:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.64:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.78:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.641:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.68:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.784:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.785:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.799:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.800:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\home.52743FDCA17E428\Cookies\home@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.593:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.595:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.597:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.599:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.600:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.602:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.604:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.606:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.522:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.523:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.527:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.528:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.532:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.533:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.537:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.538:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.759:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.774:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\home.52743FDCA17E428\Cookies\home@connextra[1].txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.105:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.62:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.757:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.772:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.652:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.653:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.653:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.654:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Goclick : Cleaned.
:mozilla.156:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.341:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.381:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.100:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.576:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.583:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.86:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.87:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.88:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.89:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.97:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.98:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.99:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.718:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.731:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.744:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.745:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.759:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.760:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.394:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.429:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.105:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.6:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\home.52743FDCA17E428\Cookies\home@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.437:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.463:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.710:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.717:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.430:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.456:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.701:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.701:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.702:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.702:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.889:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.890:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.891:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.892:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.893:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.904:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.905:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.906:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.907:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.908:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.634:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.635:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.636:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.637:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.637:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.638:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.638:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.639:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.639:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.640:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.641:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.642:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.491:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.492:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.493:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.494:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.495:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.496:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.497:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.498:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.499:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.500:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.501:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.501:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.502:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.502:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.503:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.503:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.504:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.504:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.505:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.505:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.506:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.506:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.507:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.507:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.508:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.508:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.509:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.509:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.510:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.510:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.511:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.511:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.512:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.512:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.513:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.513:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.514:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.514:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.515:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.516:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.517:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.518:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.519:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.520:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.521:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.522:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.523:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.524:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.125:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.212:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.713:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.714:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.715:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.720:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.721:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.722:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.307:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.308:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.309:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.310:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.311:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.312:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.313:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.353:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.354:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.355:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.356:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.357:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.358:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.359:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.583:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.584:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.585:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.590:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.591:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.592:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.137:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.138:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.139:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.71:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.72:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.73:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.74:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.917:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.932:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.594:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.596:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.598:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.601:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.603:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.605:C:\Documents and Settings\home.7E5AAE5DA7AF432\Application Data\Mozilla\Firefox\Profiles\p7tuwvvk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{212A818A-2C98-4646-B924-D66757ED93A8}\RP575\A0102723.exe -> Trojan.Obfuscated.en : Cleaned.

::Report end



SmitFraudFix v2.221

Scan done at 17:36:16.29, 11/10/2007
Run from C:\smit\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\privacy_danger\ Deleted
C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url Deleted
C:\DOCUME~1\HOME~1.7E5\Desktop\Error Cleaner.url Deleted
C:\DOCUME~1\HOME~1.7E5\Desktop\Privacy Protector.url Deleted
C:\DOCUME~1\HOME~1.7E5\Desktop\Spyware?Malware Protection.url Deleted
C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Online Security Test.url Deleted
C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Error Cleaner.url Deleted
C:\DOCUME~1\HOME~1.7E5\FAVORI~1\Privacy Protector.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CCS\Services\Tcpip\..\{43CA6798-90D7-4B38-8E5C-F04E6FA98100}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{43CA6798-90D7-4B38-8E5C-F04E6FA98100}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» End


uninstall list

µTorrent
ABBYY FineReader 6.0 Sprint
Ad-Aware SE Professional
Adobe Anchor Service CS3
Adobe Asset Services CS3
Adobe Bridge CS3
Adobe Bridge Start Meeting
Adobe Camera Raw 4.0
Adobe CMaps
Adobe Color - Photoshop Specific
Adobe Color Common Settings
Adobe Color Common Settings
Adobe Color EU Extra Settings
Adobe Color JA Extra Settings
Adobe Color NA Recommended Settings
Adobe Default Language CS3
Adobe Device Central CS3
Adobe Download Manager 2.0 (Remove Only)
Adobe ExtendScript Toolkit 2
Adobe ExtendScript Toolkit 2
Adobe Flash Player ActiveX
Adobe Fonts All
Adobe Help Viewer CS3
Adobe Linguistics CS3
Adobe PDF Library Files
Adobe Photoshop CS3
Adobe Photoshop CS3
Adobe Reader 7.0.7
Adobe Setup
Adobe Setup
Adobe Setup
Adobe Stock Photos CS3
Adobe Type Support
Adobe Update Manager CS3
Adobe Version Cue CS3 Client
Adobe WinSoft Linguistics Plugin
Adobe XMP Panels CS3
Adobe® Photoshop® Album Starter Edition 3.0
AppCore
Apple Mobile Device Support
Apple Software Update
ASIO4ALL
AsusUpdate
Athlon 64 Processor Driver
ATI Display Driver
AV
AVG Anti-Spyware 7.5
BankshotBilliards
Bejeweled
Big Fish Games Client
Bluetooth Stack for Windows by Toshiba
Bricks of Egypt
broadband medic
Browser Protection Volume
ccCommon
Collab
Diner Dash
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DTVR
Fish Tycoon
FL Studio 7
FM Modifier 2.12
Football Manager 2007_2 (C:\Program Files\Sports Interactive\Fo
Google Earth
Google Toolbar for Firefox
Google Toolbar for Internet Explorer
Gutterball
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
IL Download Manager
InterActual Player
Internet Explorer Secure Plug-in
InternetGameBox
iTunes
J2SE Runtime Environment 5.0 Update 3
Java™ SE Runtime Environment 6 Update 1
Jimmy Neutron Boy Genius
Lexmark 4300 Series
Lexmark Fax Solutions
LimeWire 4.14.10
LiveUpdate 3.1 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
LogViewer
Macromedia Shockwave Player
MediaShow 3.0
Messenger Plus! 3 & Sponsor
Messenger Plus! Live & Sponsor (CiD)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional with FrontPage
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft Works
Movavi VideoSuite 4.5
Mozilla Firefox (2.0.0.4)
MSN
MSN Search Toolbar
MSRedist
MSXML 4.0 SP2 (KB925672)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Norton AntiVirus
Norton Confidential Browser Component
Norton Confidential Web Protection Component
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security
Norton Internet Security (Symantec Corporation)
Norton Protection Center
ntl Netguard Security
Online Video Add-on
Panda ActiveScan
PDF Settings
PFConfig 1.0.127
PhotoNow! 1.0
Picasa 2
Power2Go 4.0
PowerBackup 1.0
PowerCinema 4.0
PowerDirector Express
PowerDVD
PowerDVD Copy 1.0
PowerProducer
PowerStarter
QuickTime
Realtek AC'97 Audio
RocketBowl
Saints & Sinners Bowling
Security Messenger
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB938829)
Shockwave
Sky Anytime
SmartCamera Ver 2.1
SPBBC 32bit
Startup Mechanic 2.0.1
Switch
Symantec Technical Support Web Controls
SymNet
Theme Park World
Theme Park World Fix
Turbo Pizza
Uninstall JL2005A Toy Camera
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB938828)
USB PC Cam Plus
VIA Platform Device Manager
VIA Rhine-Family Fast Ethernet Adapter
VideoEgg Publisher
Virgin Broadband advisor 1.5.10
V-Stream DVBT USB Drivers
V-Stream DVBT USB Utilities
WavePad Uninstall
WinAce Archiver
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Sign-in Assistant
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
WinRAR archiver
Zuma Deluxe

#4 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 11 October 2007 - 02:43 PM

You may need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O21 - SSODL: sysdx - {21743213-E074-4803-8B78-592174F53E1E} - C:\WINDOWS\sysdx.dll
O21 - SSODL: msvb - {FA6BBAA5-3895-4FB1-9B69-2162B9431ECB} - C:\WINDOWS\msvb.dll


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Remove any/all of the following files/folders that you can find:

Files

C:\WINDOWS\sysdx.dll
C:\WINDOWS\msvb.dll


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


Should any of these files fail to delete, reboot the PC and try again. If they still don't go, try Safe Mode and then give up and let me know.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You are running an old version of Sun Java which needs updating:
  • Go here and click on the Download button to the right of Java Runtime Environment (JRE) 6u3.
  • Accept the license agreement by clicking the appropriate radio button and then continue.
  • Under Windows Platform - Java™ SE Runtime Environment 6 Update 3, click the Windows Offline Installation, Multi-language link.
  • Go to Add/Remove Programs and remove any entries that refer to Java 2 Runtime Environment and then reboot your PC.
  • Navigate to and delete the following folder, if it exists: C:\Program Files\Java.
  • Finally double click the installation file that you downloaded earlier.
You'll also need to update Adobe Reader - available here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

As long as the above goes OK, I want you to run your PC as normal for a few days. When you are happy that everything is fine, do the following:

Disable System Restore,
Reboot your PC,
Re-enable System Restore,
Create a Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.

If you have the time, pay a vist to Malware Complaints and register a complaint about the malware that has infected you - in your case it was a Smitfraud infection. If enough people take the time, it could make a difference.
Death to the salad eaters!

#5 Metrix

Metrix

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 13 October 2007 - 08:44 AM

As I said all looked well. I had had the pc on for some time ok. I connected to the internet for a while ok. I left it on google for 1/2 hour
then only went on known sites, eg virgin media.
Looked at previous post to see what actions next to take. Started my mates pc again and the three icons had re-appeared
and pop-ups, slow down etc.
Safe mode, Re ran smitfraud clean, Re-ran avg (nothing found)
Restarted normal mode, ran smitfraud and updated online.
Safe mode again re-ran smitfraud clean (post below)
Carried out requested actions, the two 021 items in hyjack this returned
Deleted two files sysdx.dll, msvb.dll , needed to be in safe mode
The two 021 items cleared
Updated java ok
The ad-aware program kept popping up and freezing, (this was doing this before your help.)
Removed this and installed spybot 1.5
This found about 20 items including two references to smitfraud on its first scan but has been clear since.
The only thing that comes up on spybot is that windows security service is dis-abled. It seems to fix but on restart is off again.
So otherwise seem to be good again, been on internet and have been restarting pc constantly. Runs ok and is not slow
Thanks again for your time and patience


Logfile of HijackThis v1.99.1
Scan saved at 09:20:00, on 13/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\CyberLink\PowerCinema\PCMService.exe
C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Lexmark 4300 Series\ezprint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\Program Files\ntl\broadband medic\bin\mpbtn.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\hyjack\hijackthis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0...S01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1;*.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: MSN Search Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: MSN Search Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [{1290A33C-85F5-4164-A1BE-7DD299D4986A}] "C:\Program Files\CyberLink\PowerBackup\PBKScheduler.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\CyberLink\PowerCinema\PCMService.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\ntl\BROADB~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 4300 Series\ezprint.exe"
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [WUSB54Gv4] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: broadband medic.lnk = C:\Program Files\ntl\broadband medic\bin\matcli.exe
O4 - Global Startup: DTV Remote Control.lnk = C:\Program Files\V-Stream Multimedia\DVBT USB Utilities\DVBTRCtl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar3.dll/cmsearch.html
O8 - Extra context menu item: &MSN Search - res://C:\Program Files\MSN Toolbar Suite\TB2.05.0000.1082\en-gb\msntb.dll/search.htm
O8 - Extra context menu item: &Search - ?p=ZCxdm491LDGB
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar3.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar3.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar3.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar3.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar3.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zon...kr.cab31267.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec....trl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec....trl/tgctlsr.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec....rl/LSSupCtl.cab
O16 - DPF: {2250C29C-C5E9-4F55-BE4E-01E45A40FCF1} (CMediaMix Object) - http://musicmix.mess.../Medialogic.CAB
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zon...er.cab31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.syma...bin/AvSniff.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager...unttracking.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zon...1/GAME_UNO1.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/...h2.1.0.0.55.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.micros...b?1163807485593
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zon...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoft...free/asinst.cab
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoe...ggPublisher.exe
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn...pDownloader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn...ro.cab34246.cab
O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zon...ot.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zon...nt.cab56907.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec....rl/SymAData.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/...sh.1.0.0.89.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zon...er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zon...wn.cab31267.cab
O16 - DPF: {FFC0A381-8145-4CFD-A768-A2259776C179} (PTV xVectorMap Plugin 3.1) - http://xvectormap.pt...VectorMap31.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\CyberLink\PowerCinema\Kernel\TV\CLSched.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: KService - Kontiki Inc. - C:\Program Files\KService\KService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: lxce_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxcecoms.exe
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 19:04:58 12/10/2007

+ Scan result:



Nothing found.



::Report end



SmitFraudFix v2.240

Scan done at 19:43:24.59, 12/10/2007
Run from C:\smit\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\netadv.dll Deleted
C:\WINDOWS\wsremover.exe Deleted
C:\Program Files\Online Video Add-on\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100
HKLM\SYSTEM\CS1\Services\Tcpip\..\{4276AC15-8504-4865-96CB-1624E8737CEA}: DhcpNameServer=194.168.4.100 194.168.8.100


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

#6 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 13 October 2007 - 01:47 PM

Did you uninstall all the old versions of Sun Java? It was thought that this may have been an exploit that the Smitfraud writers were using at one time?
Death to the salad eaters!

#7 Metrix

Metrix

    New Member

  • Authentic Member
  • Pip
  • 14 posts

Posted 14 October 2007 - 08:56 AM

Yes I uninstalled it in add-remove programs It knew i had uninstalled it, and an icon in system tray gave me the chance to re-install latest one online. But I used the downloaded one from link. PC Still running ok today so thank you and fingers crossed

#8 Noviciate

Noviciate

    Retired WTT Teacher

  • Visiting Fellow
  • PipPipPipPipPip
  • 2,907 posts

Posted 14 October 2007 - 01:49 PM

Give it a workout for a couple of days and then let me know how it's performing. I'd say the infection was a new one, rather than the old one resurrecting itself, but i'm not sure - it is a little soon for my liking!
Death to the salad eaters!

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users