This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help me get rid of adware.agent.BN

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have McAfee, Spyware Doctor, and Norton's Security, and none of them can get rid of this! I don't have System Restore - it was disabled. Can anyone help me? I can't reformat this computer yet - I'd like that to be the very last possible option! So far, I only get annoying popups that link to false spyware removal sites, and the default home page of my internet explorer keeps changing (this isn't too much of a problem since my default browser is not internet explorer, but it's still really annoying). And an annoying desktop item pops up a lot that says 'your privacy is in danger' or something.

Here is my Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:00:36 PM, on 10/27/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O1 - Hosts: 216.93.248.82 www.sleepywood.net
O1 - Hosts: 216.93.248.82 sleepywood.net
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSVPS System - {90CF5384-7C70-4CD6-A30D-B2F14537B5C3} - C:\WINDOWS\movctrlwxq.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: The nssfrch - {7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC} - C:\WINDOWS\nssfrch.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix\registrycleanfix.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {2CD6A50D-0FE6-4A51-A9D6-AAEFED8DE88F} (Nexon Package Manager Control (T)) - http://s.nx.com/activex/public_new/nxpmt.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.playfirst.com/play/game/dinerda…h2.1.0.0.67.cab
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.playfirst.com/play/game/dinerda…tg.1.0.0.32.cab
O16 - DPF: {BC5E698E-77CF-45EF-80A3-090A4B6AAF83} (HGPlugin8USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin8USA.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin10USA.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O21 - SSODL: bxsbang - {DCB4631A-57DF-4AD4-9563-85249614E9DF} - C:\WINDOWS\bxsbang.dll
O21 - SSODL: ocgrep - {A22B6C08-8412-4B9E-9EEC-BAD32BAE9349} - C:\WINDOWS\ocgrep.dll
O23 - Service: McAfee Application Installer Cleanup (0283001193505557) (0283001193505557mcinstcleanup) - Unknown owner - C:\DOCUME~1\SARAHK~1\LOCALS~1\Temp28300~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O24 - Desktop Component 0: (no name) - file:///C:/WINDOWS/privacy_danger/images/spacer.gif
O24 - Desktop Component 1: Privacy Protection - file:///C:\WINDOWS\privacy_danger\index.htm

–
End of file - 12924 bytes
  • Hello, and welcome to the forum.

    My name is Simon V., and I'll be glad to help you with your computer problems.

    HijackThis logs can take some time to research, so please be patient with me. I know that you need your computer working as quickly as possible, and I will work hard to help see that happens.

    I'd be grateful if you would note the following:
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.

    I'll get back to you as soon as possible.
  • Hi :)

    If your System Restore is still disabled, please re-enable it:

    Re-Enable System Restore
  • On the desktop, right-click My Computer.
    • Click Properties.
    • Click the System Restore tab.
    • Uncheck Turn off System Restore.
    • Click Apply, and then click OK.
    SmitfraudFix
  • Please download SmitfraudFix (By S!ri).
    • Double-click on SmitfraudFix.exe. A screen will pop up. Select Option 1 (Search) by typing 1 and hit enter. A text file will appear, which will list the infected files. Save it to a convenient location.
    • The log will also be saved here: C:\rapport.txt
    • Note: process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
    Make an Uninstall List
  • To access the Uninstall Manager you would do the following:

    1. Start HijackThis
    2. Click on the Config button
    3. Click on the Misc Tools button
    4. Click on the Open Uninstall Manager button.
    5. Click on the Save list… button and save the file to a convenient location. When you press Save, Notepad will open with the contents of that file.

    Report Back
  • Please post the report from SmitfraudFix and the Uninstall List, along with a new HijackThis log in your next reply.
Okay, thank you.

The Rapport report:

SmitFraudFix v2.242

Scan done at 9:17:50.71, Sun 10/28/2007
Run from C:\Program Files\Mozilla Firefox\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\System32\svchost.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe
C:\WINDOWS\system32\cmd.exe
c:\PROGRA~1\mcafee\VIRUSS~1\mcvsmap.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\bxsbang.dll FOUND !
C:\WINDOWS\kthemup.exe FOUND !
C:\WINDOWS\nssfrch.dll FOUND !
C:\WINDOWS\ocgrep.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Sarah Kwak


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Sarah Kwak\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\SARAHK~1\FAVORI~1

C:\DOCUME~1\SARAHK~1\FAVORI~1\Error Cleaner.url FOUND !
C:\DOCUME~1\SARAHK~1\FAVORI~1\Privacy Protector.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\SARAHK~1\Desktop\Error Cleaner.url FOUND !
C:\DOCUME~1\SARAHK~1\Desktop\Privacy Protector.url FOUND !
C:\DOCUME~1\SARAHK~1\Desktop\Spyware?Malware Protection.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components]
"Source"="file:///C:/WINDOWS/privacy_danger/images/spacer.gif"
"SubscribedURL"="file:///C:/WINDOWS/privacy_danger/images/spacer.gif"
"FriendlyName"=""

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Intel® PRO/100 VE Network Connection - Packet Scheduler Miniport
DNS Server Search Order: 192.168.2.1

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3D4DF90D-922D-477B-9A51-8528E5085C46}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3D4DF90D-922D-477B-9A51-8528E5085C46}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



Uninstall List:

Ad-Aware 2007
Adobe Common File Installer
Adobe Flash Player 9 ActiveX
Adobe Help Center 1.0
Adobe Photoshop CS2
Adobe Reader 7.0.7
Adobe Stock Photos 1.0
ALUpdate
ALZip
AOL Instant Messenger
Apple Mobile Device Support
Apple Software Update
BannedStory
Dell Digital Jukebox Driver
Dell Driver Reset Tool
Digital Content Portal
DivX Web Player
Fraps
GOM Player
Google
Google Talk (remove only)
Google Updater
GTK+ Runtime 2.6.9 rev a (remove only)
Gunbound Revolution
High Definition Audio Driver Package - KB835221
HijackThis 2.0.2
Hotfix for Windows Media Format SDK (KB902344)
Hotfix for Windows XP (KB896344)
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Drivers
Intel® PROSet for Wired Connections
iPod for Windows 2006-06-28
iTunes
Last.fm [removed]
LimeWire 4.14.8
Macromedia Flash Player
Macromedia Shockwave Player
MapleStory
McAfee SecurityCenter
MCU
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Office Professional Edition 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
Mozilla Firefox (2.0.0.8)
MSN
MSXML 4.0 SP2 (KB936181)
Norton Security Scan
ObjectDock
Qualxserve Service Agreement
QuickBooks Simple Start Special Edition
QuickTime
Security Update for CAPICOM (KB931906)
Security Update for CAPICOM (KB931906)
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Sonic Activation Module
Sony Media Manager 2.2
Spyware Doctor 5.1
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB900930)
Update for Windows XP (KB904942)
Update for Windows XP (KB910437)
Update for Windows XP (KB912945)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
URL Assistant
Viewpoint Toolbar
WebCyberCoach 3.2 Dell
WebVideo Support
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Media Connect
Windows Media Format Runtime
Windows Media Player 10
Windows Media Player 10
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB887797
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
WinRAR archiver





The new Hijackthis Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:22:32 AM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\FRAPS\FRAPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Sarah Kwak\Desktop\HiJackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=…6Ojg5&lid=2
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
O1 - Hosts: 216.93.248.82 www.sleepywood.net
O1 - Hosts: 216.93.248.82 sleepywood.net
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSVPS System - {90CF5384-7C70-4CD6-A30D-B2F14537B5C3} - C:\WINDOWS\movctrlwxq.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: The nssfrch - {7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC} - C:\WINDOWS\nssfrch.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix\registrycleanfix.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {2CD6A50D-0FE6-4A51-A9D6-AAEFED8DE88F} (Nexon Package Manager Control (T)) - http://s.nx.com/activex/public_new/nxpmt.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.playfirst.com/play/game/dinerda…h2.1.0.0.67.cab
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.playfirst.com/play/game/dinerda…tg.1.0.0.32.cab
O16 - DPF: {BC5E698E-77CF-45EF-80A3-090A4B6AAF83} (HGPlugin8USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin8USA.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin10USA.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O21 - SSODL: bxsbang - {DCB4631A-57DF-4AD4-9563-85249614E9DF} - C:\WINDOWS\bxsbang.dll
O21 - SSODL: ocgrep - {A22B6C08-8412-4B9E-9EEC-BAD32BAE9349} - C:\WINDOWS\ocgrep.dll
O23 - Service: McAfee Application Installer Cleanup (0283001193505557) (0283001193505557mcinstcleanup) - Unknown owner - C:\DOCUME~1\SARAHK~1\LOCALS~1\Temp28300~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe
O24 - Desktop Component 0: (no name) - file:///C:/WINDOWS/privacy_danger/images/spacer.gif

–
End of file - 12915 bytes
  • Hi :)

    P2P Warning
  • I understand that downloading music and other files may be important to you; however, the P2P programs that you are using to do that, even if they are not infected with malware, will bring malware into your system. Therefore, the chances of you becoming infected again are very high. This obviously can result in disabling your computer and could even lead to someone stealing sensitive personal data from your computer. Beyond the inconvenience this causes you, these programs also tend to use your computer as a server to spread more infection all over the internet, so your computer becomes a part of the malware problem.

    Remember that no matter how clean the program you're using for Peer-to-Peer filesharing may be, it offers no guarantees regarding the cleanliness of files you may choose to download. All files available via P2P filesharing carry a high risk, particularly those that offer you illegitimate methods of using legitimate software programs without paying for them. Any program or file that offers you the ability to access non-freeware programs at no cost, e.g., pirated software and/or cracks/key generators for gaining access to legitimate software, is 100% guaranteed to contain malware.

    Here is some information that looks at the rates of infection:

    http://www.benedelman.org/spyware/p2p/

    With that being said, I recommend that you remove the following P2P program(s):

    LimeWire 4.14.8

    AVG Anti-Spyware
  • Please download and install AVG Anti-Spyware.

    After the installation, open AVG Anti-Spyware and do the following:
  • Under 'Status', click on Change state, next to 'Resident shield' (this will change from Active to Inactive)
  • Under the 'Update' tab, click on 'Start update'.
  • Under 'Scanner', click on the 'Settings' tab:
  • Under 'How to act?', click on 'Recommended actions', and select Quarantine.
  • Under 'Reports', select 'Do not automatically generate reports'.
Close AVG Anti-Spyware. Do not let it scan yet.

ATF Cleaner

[*]Please download ATF Cleaner.


Double-click on ATF-Cleaner.exe to start the program.
Under the Main tab, put a check next to 'Select All'.
Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')

If you use the Firefox browser:
Click on Firefox at the top and put a check next to 'Select All'.
If you would like to keep your saved passwords, click No at the prompt.
Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies').

If you use the Opera browser:
Click on Opera at the top and put a check next to 'Select All'.
If you would like to keep your saved passwords, click No at the prompt.
Click the 'Empty Selected' button. (Note: if you select cookies, automated login at forums and sites will be disabled. If you do not want this, uncheck 'Cookies')

Safe Mode

[*]Print these instructions or copy them to Notepad and save it to your desktop, as you won't be able to access internet in Safe Mode.


[*]Please reboot into Safe Mode. To do this, go to Start > Turn off Computer, and select Restart. Rapidly tap F8 just before Windows starts to load. In the menu that appears, select Safe Mode (Without Networking)


SmitfraudFix

[*]Double-click on Smifraudfix.exe.
  • A screen will pop up. Select Option 2 (Clean) by typing 2 and hit Enter.
  • You will be prompted: 'Registry Cleaning - Do you want to clean the registry?' Answer Yes by typing Y and press Enter in order to clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file; answer Yes by typing Y and hit Enter.
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart Windows into Normal Mode.
  • A text file will appear onscreen, with results from the cleaning process; please copy the content of that report and paste it in your next reply. The report can also be found at C:\rapport.txt.

[*]Warning: running option #2 on a non infected computer will remove your desktop background.


AVG Anti-Spyware

[*]Please open AVG Anti-Spyware.
  • Click on the 'Scan' tab.
  • Click on 'Complete System Scan' to start the scan process.
  • After the scan, do the following:Important: Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not, click on the link and select 'Quarantine' from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button. (3)
  • When done, click the 'Save Report' (4) button, and save the file to your desktop.

[external image: Posted Image].

[*]Reboot your computer in Normal Mode.


Run a .bat File

[*]Please copy and paste the text in the code box into Notepad (Go to Start > Run, type Notepad and hit Enter)


@echo off

if exist C:\export.txt del /q C:\export.txt
regedit /a C:\export.txt "HKEY_CURRENT_USER\Software\FCRMFC"
start C:\export.txt
exit

[*]Go to File > Save As:. Save the file as "Export.bat" (Including the quotes)


[*]Double-click on Export.bat to run the file.


[*]A notepad file will open with the contents of C:\export.txt. Please post those back here.


Report Back

[*]Please post the reports from Smitfraudfix and AVG Anti-Spyware and the contents of C:\export.txt, along with a new HijackThis log in your next reply.



Smitfraudfix:



SmitFraudFix v2.242

Scan done at 18:37:07.09, Sun 10/28/2007
Run from C:\Documents and Settings\Sarah Kwak\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

216.93.248.82 www.sleepywood.net
216.93.248.82 sleepywood.net

»»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix

S!Ri's WS2Fix: LSP not Found.


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\bxsbang.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{DCB4631A-57DF-4AD4-9563-85249614E9DF}]
Deleting [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{DCB4631A-57DF-4AD4-9563-85249614E9DF}]
C:\WINDOWS\kthemup.exe Deleted
C:\WINDOWS\nssfrch.dll Deleted
C:\WINDOWS\ocgrep.dll Deleted
Deleting [HKEY_CLASSES_ROOT\CLSID\{A22B6C08-8412-4B9E-9EEC-BAD32BAE9349}]
C:\WINDOWS\privacy_danger\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CCS\Services\Tcpip\..\{3D4DF90D-922D-477B-9A51-8528E5085C46}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\..\{3D4DF90D-922D-477B-9A51-8528E5085C46}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\..\{3D4DF90D-922D-477B-9A51-8528E5085C46}: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.2.1


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


AVGAntispyware:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:45:50 PM 10/28/2007

+ Scan result:



:mozilla.565:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.566:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.513:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.514:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.515:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.516:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.517:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.518:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.519:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.520:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.521:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.522:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.523:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.524:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.525:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.526:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.527:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.528:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.529:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.530:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.532:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.533:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.534:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.535:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.536:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.537:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.538:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.539:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.540:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.541:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.542:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.543:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.544:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.545:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.546:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.547:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.646:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.650:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.112:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.113:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.114:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.115:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.477:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.495:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.905:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.289:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.290:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.731:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.310:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.311:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.312:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.313:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.314:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.315:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.316:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.704:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.772:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.779:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.740:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.742:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.74:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.76:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.77:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.78:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.79:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.89:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.816:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.24:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.422:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.818:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.398:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.399:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.42:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.43:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.44:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.45:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.47:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.48:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.66:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.288:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.857:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.130:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.332:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.141:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.142:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.143:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.144:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.145:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.152:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.430:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.431:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.432:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.433:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.734:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.735:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.736:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.737:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.10:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.11:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.12:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.16:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.17:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.6:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.7:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.8:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.9:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.729:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.468:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.469:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.470:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.739:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.743:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.799:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.803:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.804:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.153:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.154:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.569:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.570:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.914:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Information : Cleaned.
:mozilla.162:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.163:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.8:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.9:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.169:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.170:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.171:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.822:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.553:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.554:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.555:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.556:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.557:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.558:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.384:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.385:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.164:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.165:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.166:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.182:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.184:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.185:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.186:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.187:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.188:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.189:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.190:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.191:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.192:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.193:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.194:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.195:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.196:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.197:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.198:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.199:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.200:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.201:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.202:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.203:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.204:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.205:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.206:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.636:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.100:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.101:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.102:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.103:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.104:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.105:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.77:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.78:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.79:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.80:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.95:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.96:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.97:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.98:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.99:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.832:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.833:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.834:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.835:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.836:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.837:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.838:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.839:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.840:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.841:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.842:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.277:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.278:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.279:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.280:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.281:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.340:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.341:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.342:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.343:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.344:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.345:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.346:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.347:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.348:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.349:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.350:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.351:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.352:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.353:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.354:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.355:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.356:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.358:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.359:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.363:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.364:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.365:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.366:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.147:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.148:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.149:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.150:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.151:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.511:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.512:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.531:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.862:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.911:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.367:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.208:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.209:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.210:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.211:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.212:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.213:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.214:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.215:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.131:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.132:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.133:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.134:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.135:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.136:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.750:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.661:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.659:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.174:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.175:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.176:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.177:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.178:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.179:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.180:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.181:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.272:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.273:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.274:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.275:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.276:C:\Documents and Settings\Sarah Kwak\Application Data\Mozilla\Firefox\Profiles\xgo54xre.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned.


::Report end



export txt:

REGEDIT4

[HKEY_CURRENT_USER\Software\FCRMFC]
"Scanned"=dword:00000001




Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:02:55 PM, on 10/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\WINDOWS\system32\msiexec.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

O1 - Hosts: 216.93.248.82 www.sleepywood.net
O1 - Hosts: 216.93.248.82 sleepywood.net
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSVPS System - {90CF5384-7C70-4CD6-A30D-B2F14537B5C3} - C:\WINDOWS\movctrlwxq.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O3 - Toolbar: The nssfrch - {7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC} - C:\WINDOWS\nssfrch.dll (file missing)
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix\registrycleanfix.exe
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {2CD6A50D-0FE6-4A51-A9D6-AAEFED8DE88F} (Nexon Package Manager Control (T)) - http://s.nx.com/activex/public_new/nxpmt.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.playfirst.com/play/game/dinerda…h2.1.0.0.67.cab
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.playfirst.com/play/game/dinerda…tg.1.0.0.32.cab
O16 - DPF: {BC5E698E-77CF-45EF-80A3-090A4B6AAF83} (HGPlugin8USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin8USA.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin10USA.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O23 - Service: McAfee Application Installer Cleanup (0095271193610186) (0095271193610186mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\9527~1.EXE (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

–
End of file - 12742 bytes
  • Hi :)

    Backup the Registry
  • Download ERUNT
    • Save it to your desktop. Install the program, then run it.
    • In the box that opens place a check next to all items, then click OK. It may take a minute. Just let it go until it's done.
    • Click OK again when it's finished.
    • Close ERUNT.
    This is so the registry can be restored to this point if we need it.

    Fix Entries with HijackThis
  • Open HijackThis, perform a scan and put a check next to the following items (if present):

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: MSVPS System - {90CF5384-7C70-4CD6-A30D-B2F14537B5C3} - C:\WINDOWS\movctrlwxq.dll
    O3 - Toolbar: The nssfrch - {7D61C1B5-86AF-439F-9ACF-D19FDB5F55CC} - C:\WINDOWS\nssfrch.dll (file missing)
    O4 - HKCU\..\Run: [RegistryCleanFixMFC] C:\Program Files\RegistryCleanFix\registrycleanfix.exe
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)


    Close all programs except HijackThis and click on Fix checked.

    Run a .reg File
  • Copy the text below into a Notepad (Go to Start > Run, type Notepad and hit Enter) document:

    REGEDIT4
    
    [-HKEY_CURRENT_USER\Software\FCRMFC]

    Note: Make sure there is no blank line before REGEDIT4 and one blank line at the end.
  • Go to File > Save As:. Save the file as "Fix.reg" (Including the quotes)
  • Double-click on Fix.reg. When asked if you want to merge the file with the registry, click Yes.

    Download and Run OTMoveIt
  • Download OTMoveIt by OldTimer from here.
    • Double click on OTMoveIt to start OTMoveIt.
      [external image: Posted Image]
    • Untick the option to Unregister Dll's and Ocx's (1).
    • Select the contents of the below codebox, then press Ctrl+C to copy it to the clipboard.
      C:\WINDOWS\movctrlwxq.dll
      C:\WINDOWS\nssfrch.dll
      C:\Program Files\RegistryCleanFix
    • In OTMoveIt right-click on the box labelled Paste List of Files/Folders to be Moved.
    • Click Paste (2).
    • Click MoveIt! (3).
    • If it asks you to reboot allow that.
    • A logfile will be created at C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log (where mmddyyyy_hhmmss are numbers giving date and time the log was created).
    Report Back
  • Please post the report from OTMoveIt, along with a new HijackThis log in your next reply. Also tell me how everything is working.
The OTMoveIt thing doesn't work - I click 'MoveIt!', but it says the files can't be found and it can't create folder C:\_OTMoviteIt\MovedFiles\…

Here is another HijackThis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:59:36 PM, on 10/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\Spyware Doctor\svcntaux.exe
C:\Program Files\Spyware Doctor\swdsvc.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\SiteAdvisor\6172\SAService.exe
C:\Program Files\Spyware Doctor\SDTrayApp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\FRAPS\FRAPS.EXE
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Last.fm\LastFMHelper.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\agent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe

O1 - Hosts: 216.93.248.82 www.sleepywood.net
O1 - Hosts: 216.93.248.82 sleepywood.net
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O2 - BHO: McAntiPhishingBHO - {377C180E-6F0E-4D4C-980F-F45BD3D40CF4} - c:\PROGRA~1\mcafee\msk\mcapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.615.5858\swg.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dll
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exe
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
O4 - HKUS\S-1-5-18\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Last.fm Helper.lnk = C:\Program Files\Last.fm\LastFMHelper.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Download Link Using Mega Manager… - C:\Program Files\Megaupload\Mega Manager\mm_file.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {2931566C-B8A6-46C5-BF4D-E6AB9251E953} (Nexon Package Manager Control) - http://file.nx.com/activex/public_new/nxpm.cab
O16 - DPF: {2CD6A50D-0FE6-4A51-A9D6-AAEFED8DE88F} (Nexon Package Manager Control (T)) - http://s.nx.com/activex/public_new/nxpmt.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-CA/a-UNO1/GAME_UNO1.cab
O16 - DPF: {5F5F9FB8-878E-4455-95E0-F64B2314288A} (ijjiPlugin2 Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin11USA.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://www.playfirst.com/play/game/dinerda…h2.1.0.0.67.cab
O16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} (GomWeb Control) - http://app.ipop.co.kr/gom/GomWeb.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) - http://www.playfirst.com/play/game/dinerda…tg.1.0.0.32.cab
O16 - DPF: {BC5E698E-77CF-45EF-80A3-090A4B6AAF83} (HGPlugin8USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin8USA.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin9USA.cab
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gamedownlo…Plugin10USA.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab56986.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O23 - Service: McAfee Application Installer Cleanup (0202951193683724) (0202951193683724mcinstcleanup) - McAfee, Inc. - C:\WINDOWS\TEMP20295~1.EXE
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exe

–
End of file - 12140 bytes






Everything has been working fine since yesterday after I did everything you told me to do - just a little slow at start up, but I think that's because I have so many new anti-virus/spyware programs running now. Is it alright if I delete some of them later?
  • Hi :)

    The OTMoveIt thing doesn't work - I click 'MoveIt!', but it says the files can't be found and it can't create folder C:\_OTMoviteIt\MovedFiles\…


    That's OK, it means the files were deleted already :thumbup:

    Everything has been working fine since yesterday after I did everything you told me to do - just a little slow at start up, but I think that's because I have so many new anti-virus/spyware programs running now. Is it alright if I delete some of them later?


    We'll remove everything I've let you download, but there are a few programs you should have/keep (for instance, be sure to keep Ad-Aware and McAfee) in order to prevent future infections:

    Prevention
  • Congratulations, your log looks clean. Please advise of any problems you are still experiencing, or follow these simple steps to keep your computer clean in the future:
    • OTMoveIt Cleanup
    • Please open OTMoveIt.
      • Click on the CleanUp! button. If your Firewall gives a warning about OTMoveIt wanting to download a file, allow it.
      • Answer Yes to the prompt.
      • The program will ask for a reboot. Answer Yes.
    • Disable and Enable System Restore - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
      • Turn off System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Check Turn off System Restore
      • Click Apply, and then click OK
      • Reboot.
      • Turn on System Restore.
      • On the desktop, right-click My Computer
      • Click Properties
      • Click the System Restore tab
      • Uncheck Turn off System Restore
      • Click Apply, and then click OK
      NOTE: only do this ONCE, NOT on a regular basis!
    • Make your Internet Explorer more secure
      • From within Internet Explorer click on the Tools menu and then click on Options.
      • Click once on the Security tab.
      • Click once on the Internet icon so it becomes highlighted.
      • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt.
      • Change the Download unsigned ActiveX controls to Disable.
      • Change the Initialise and script ActiveX controls not marked as safe to Disable.
      • Change the Installation of desktop items to Prompt.
      • Change the Launching programs and files in an IFRAME to Prompt.
      • Change the Navigate sub-frames across different domains to Prompt.
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your Anti-Virus Software - It is very imprtant that you update your Anti-Virus software at least once a week (even more if you wish). If you do not update your Anti-Virus software then it will not be able to catch any of the new variants that may come out.
  • Visit Microsoft's Update Site Frequently - It is important that you visit http://update.microsoft.com/ regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. An article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

    Follow this list and your potential for being infected again will reduce dramatically.
  • Stand Up and Be Counted!

    Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you have to be registered to post after registering just find your country room and register your complaint.
    The infection you had was Smitfraud.
You're welcome :)

Happy surfing and stay safe!

Since this issue appears to be resolved … this topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI