PDA

View Full Version : problems with a few malwares



pimuni
2007-02-25, 02:09
Hello, I have been trying to delete some malware with Spybot, but they keep reappearing. The main problems are SmitFraud and Virtumonde, but I also have several tracking cookies. Several different pages pop up randomly, including the one for WinAntivirusPro2006. I have tried using a few other programs to fix this problem. Ad-aware doesn't find any problems and AVG finds trojan.agent.acl. I used the SmitfraudFix.exe (in safe mode) and did the whole process, so it must have gotten rid of that problem. (Still haven't checked for other activity). I would like some help please.

pimuni
2007-02-25, 02:10
here is the SmitfraudFix.exe log:
-----------

SmitFraudFix v2.144

Scan done at 19:43:53.96, Sat 02/24/2007
Run from C:\Documents and Settings\HP_Administrator\Desktop\downloads\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

-----------------

pimuni
2007-02-25, 02:11
here is my hijackthis log:
---------------

Logfile of HijackThis v1.99.1
Scan saved at 8:01:30 PM, on 2/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\acolgxsn.dll",setvm
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

-------------

pimuni
2007-02-25, 02:29
i apologize for so many posts, but i thought it would be easier to read this way. Anyways, here is what Spybot just found:

http://img.photobucket.com/albums/v517/pimuni/malware123.jpg

Mr_JAk3
2007-02-26, 13:55
Hi pimuni and welcome to the Forums :)

You're infected.

Rename HijackThis.exe to Scanner.exe

At first you need to disable a few realtime protections. These may interfere with our cleaning process.
We'll enable these when you're clean...

Disable Windows Defender's realtime protection.
Open Windows Defender
Click on "Tools"
Click on "General Settings"
Scroll down to "Real-time protection options"
Uncheck "Turn on Real-time protection (recommended)"
Click "Save"
Exit the program.
Disable AVG Anti-Spyware guard.
Open AVG Anti-Spyware
Click Shield
Click under "resident shield is"
Change it to inactive
Close the program
Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis (scanner.exe) log.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

pimuni
2007-02-26, 21:46
thanks for the reply

VundoFix Log

VundoFix V6.3.9

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.5

Java version is 1.5.0.6

Java version is 1.5.0.9

Scan started at 3:31:41 PM 2/26/2007

Listing files found while scanning....

C:\WINDOWS\system32\agryakpj.exe
C:\WINDOWS\system32\cbpynnin.exe
C:\WINDOWS\system32\cpshekly.dll
C:\WINDOWS\system32\eocnwupj.ini
C:\WINDOWS\system32\jcmpbbje.exe
C:\WINDOWS\system32\jpuwncoe.dll
C:\WINDOWS\system32\llhsbvbt.exe
C:\WINDOWS\system32\ssttu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\agryakpj.exe
C:\WINDOWS\system32\agryakpj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbpynnin.exe
C:\WINDOWS\system32\cbpynnin.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\eocnwupj.ini
C:\WINDOWS\system32\eocnwupj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jcmpbbje.exe
C:\WINDOWS\system32\jcmpbbje.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\jpuwncoe.dll
C:\WINDOWS\system32\jpuwncoe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llhsbvbt.exe
C:\WINDOWS\system32\llhsbvbt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssttu.dll
C:\WINDOWS\system32\ssttu.dll Has been deleted!

Performing Repairs to the registry.
Done!

----------------------

HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 3:44:07 PM, on 2/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O2 - BHO: (no name) - {00EADF9D-1825-2299-5B73-08D3E1EA4736} - C:\WINDOWS\system32\xkybivk.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {230D0EEB-E247-DB25-2352-0BB0F6DC30BA} - C:\WINDOWS\system32\eljswve.dll
O2 - BHO: (no name) - {57229570-FAC3-46DD-9F2E-1D60E37FE3F9} - C:\WINDOWS\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} - C:\WINDOWS\system32\gebcawv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {841FB5E2-C782-441A-96FC-90C667F2F77C} - C:\WINDOWS\system32\pmkjh.dll (file missing)
O2 - BHO: (no name) - {D16FBE66-0186-5D28-DB49-2E909CD539BC} - C:\WINDOWS\system32\pkv.dll (file missing)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\cpshekly.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: gebcawv - C:\WINDOWS\SYSTEM32\gebcawv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winubg32 - winubg32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

Mr_JAk3
2007-02-27, 10:09
Hi again :)

Before we'll continue I would like you to do something for me...
I need you too upload few malware files for further inspection.

Make your hidden files visible:
Go to My Computer
Select the Tools menu and click Folder Options
Click the View tab.
Checkmark the "Display the contents of system folders"
Under the Hidden files and folders select "Show hidden files and folders"
Uncheck "Hide protected operating system files"
Click Apply and then the OK and close My Computer.
Please go here (http://www.uploadmalware.com/) to upload a suspicious file for analysis.
Enter your username from this forum
Copy and paste the link to this thread
Click "Browse" on the 1. field.
Browse to the following file and click the file with your mouse, press "Open"
C:\WINDOWS\system32\gebcawv.dll
Click "Browse" on the 2. field.
Browse to the following file and click the file with your mouse, press "Open"
C:\WINDOWS\system32\xkybivk.dll
Click "Browse" on the 3. field.
Browse to the following file and click the file with your mouse, press "Open"
C:\WINDOWS\system32\eljswve.dll

In the comments, please mention that I asked you to upload this file
Click on Send File
Please let me know when you have done this and then we'll get you cleaned :bigthumb:

pimuni
2007-02-27, 21:33
ok, done so

---
Your file (gebcawv.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.

Your file (xkybivk.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.

Your file (eljswve.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.
---

Mr_JAk3
2007-02-28, 08:46
Hi again, we'll continue :)
Thank you for the upload.

You should print these instructions or save these to a text file. Follow these instructions carefully.

Open AVG Anti-Spyware:
On the main screen under Your Computer's security.
Click on Change state next to Resident shield. It should now change to inactive.
Click on Change state next to Automatic updates. It should now change to inactive.
Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
Wait until you see the Update succesfull message.
Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates (http://www.ewido.net/en/download/updates/).
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1) by Atribune to your desktop.
Do NOT run yet.

Make your hidden files visible:
Go to My Computer
Select the Tools menu and click Folder Options
Click the View tab.
Checkmark the "Display the contents of system folders"
Under the Hidden files and folders select "Show hidden files and folders"
Uncheck "Hide protected operating system files"
Click Apply and then the OK and close My Computer.
==================

We'll run VundoFix again.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once the scan is complete, Right Click inside the listbox (white box) and click add more files
Copy&Paste the 2 entries below into the top 2 boxes
C:\WINDOWS\system32\gebcawv.dll
C:\WINDOWS\system32\vwacbeg.*
Click Add Files and Click Close Window
Click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.

Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.

O2 - BHO: (no name) - {00EADF9D-1825-2299-5B73-08D3E1EA4736} - C:\WINDOWS\system32\xkybivk.dll
O2 - BHO: (no name) - {230D0EEB-E247-DB25-2352-0BB0F6DC30BA} - C:\WINDOWS\system32\eljswve.dll
O2 - BHO: (no name) - {57229570-FAC3-46DD-9F2E-1D60E37FE3F9} - C:\WINDOWS\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} - C:\WINDOWS\system32\gebcawv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {841FB5E2-C782-441A-96FC-90C667F2F77C} - C:\WINDOWS\system32\pmkjh.dll (file missing)
O2 - BHO: (no name) - {D16FBE66-0186-5D28-DB49-2E909CD539BC} - C:\WINDOWS\system32\pkv.dll (file missing)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\cpshekly.dll (file missing)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O20 - Winlogon Notify: gebcawv - C:\WINDOWS\SYSTEM32\gebcawv.dll
O20 - Winlogon Notify: winubg32 - winubg32.dll (file missing)

You also have a Norton leftover running, we'll remove it:

Start
Run
Type services.msc to the field and press enter.
A window opens, scroll down to Symantec Network Drivers Service (SNDSrvc)
Rightclick it and choose Stop
Then choose Properties
Set Startup to Disabled
Click Apply and OK.
Then, open HijackThis.
Open the Misc Tools section
Delete an NT service
Copy the following line to the box and press OK; SNDSrvc
Answer Yes
Close HIjackThis

Restart your computer to the safe mode:
Restart your computer
Start tapping the F8 key when the computer restarts.
When the start menu opens, choose Safe mode
Press Enter. The computer then begins to start in Safe mode.

Go to the My Computer and delete the following files (if present):
C:\WINDOWS\system32\xkybivk.dll
C:\WINDOWS\system32\eljswve.dll
C:\WINDOWS\system32\v6.exe
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll

Go to the My Computer and delete the following folders (if present):
C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}

Use the Windows search Start
Search
All files and folders
More advanced options Checkmark these options: "Search system folders"
"Search hidden files and folders"
"Search subfolders"
Search for this and delete if found: winubg32.dll

Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Click on Scanner on the toolbar.
Click on the Settings tab.
Under How to act?
Click on Recommended Action and choose Quarantine from the popup menu.
Under How to scan?
All checkboxes should be ticked.
Under Possibly unwanted software:
All checkboxes should be ticked.
Under Reports:
Select Automatically generate report after every scan and uncheck Only if threats were found.
Under What to scan?
Select Scan every file.
Click on the Scan tab.
Click on Complete System Scan to start the scan process.
Let the program scan the machine.
When the scan has finished, follow the instructions below.
IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
At the bottom of the window click on the Apply all Actions button. (3)
http://img509.imageshack.us/img509/4851/scanavgjk2.jpg
When done, click the Save Scan Report button. (4)
Click the Save Report as button.
Save the report to your Desktop.
Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
- contents of C:\vundofix.txt

pimuni
2007-03-01, 01:41
here you go:

AVG Log

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:29:53 PM 2/28/2007

+ Scan result:



C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP360\A0100130.dll -> Downloader.Busky : Cleaned with backup (quarantined).
:mozilla.258:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-1.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.368:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.369:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.466:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.467:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.468:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.682:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Real : Cleaned.
:mozilla.124:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.127:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.128:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.129:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.130:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.131:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.132:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.133:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.134:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.162:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.163:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.18:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.232:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.

pimuni
2007-03-01, 01:42
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application
Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP358\A0100049.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP359\A0100118.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP360\A0100133.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).


::Report end

------------------------

pimuni
2007-03-01, 01:43
HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 7:35:43 PM, on 2/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Windows Defender\MSASCui.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

-----------------------

VundoFix Log

VundoFix V6.3.9

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.5

Java version is 1.5.0.6

Java version is 1.5.0.9

Scan started at 4:57:39 PM 2/28/2007

Listing files found while scanning....

C:\WINDOWS\system32\cpshekly.dll
C:\WINDOWS\system32\ivvyixpc.exe
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\kytguoyr.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\rjapryhd.exe
C:\WINDOWS\system32\ryougtyk.ini
C:\WINDOWS\system32\sdrhncsj.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\gebcawv.dll
C:\WINDOWS\system32\gebcawv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ivvyixpc.exe
C:\WINDOWS\system32\ivvyixpc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\jjkmp.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\jjkmp.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\jjkmp.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\kytguoyr.dll
C:\WINDOWS\system32\kytguoyr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\pmkjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rjapryhd.exe
C:\WINDOWS\system32\rjapryhd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ryougtyk.ini
C:\WINDOWS\system32\ryougtyk.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sdrhncsj.exe
C:\WINDOWS\system32\sdrhncsj.exe Has been deleted!

Performing Repairs to the registry.
Done!

pimuni
2007-03-01, 03:22
oh and also, I coudn't delete that Norton process, because the system wouldn't let me delete anything from symantec.

Mr_JAk3
2007-03-01, 19:23
Hi again, it is looking clean now :)
How is the computer running?

The Norton leftover seems to be gone now.

Now you can clean AVG's Quarantine:
Open AVG Anti-Spyware
Click Infections
Click Quarantine tab
Click Select all
Click Remove finally
Close the program
You can remove the tools we used.

Then you should update your Java to the latest version (6.0) Start
Control Panel
Add/Remove Programs
Delete the old Javas, Java 2 Runtime Environment, SE v1.4.1_03
J2SE Runtime Environment 5.0 Update 5
J2SE Runtime Environment 5.0 Update 6
J2SE Runtime Environment 5.0 Update 9
J2SE Runtime Environment 5.0 Update 11
Download the latest version of Java Runtime Environment (JRE) 6.0 (http://java.sun.com/javase/downloads/index.jsp).
Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
Click the "Download" button to the right.
Check the box that says: "Accept License Agreement."
The page will refresh.
Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
Install it

Now you can make your hidden files hidden again.
Go to My Computer
Select the Tools menu and click Folder Options
Click the View tab.
Checkmark the "Display the contents of system folders"
Under the Hidden files and folders select "Show hidden files and folders"
Check "Hide protected operating system files"
Click Apply and then the OK and close My Computer.

=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:
Clear your system restore (http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx)
This will clear the system restore folders from possible malware that was left behind during the cleaning process.

Use ATF Cleaner (http://www.atribune.org/ccount/click.php?id=1)
Download and install ATF Cleaner. Clean your temporary files & folders with it regularly.

Use Ad-Aware (http://www.bleepingcomputer.com/forums/?showtutorial=48)
Download and install Ad-Aware. Update it and scan your computer regularly with it.

Use AVG Anti-Spyware (http://www.ewido.net/en/)
Update it and scan your computer regularly with it.

Use Spybot S&D (http://www.bleepingcomputer.com/forums/?showtutorial=43)
Download and install Spybot S&D. Update it and scan your computer regularly with it.

Install SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html)
SpywareBlaster will prevent spyware from being installed.

Install MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm)
This prevents your computer from connecting to harmful sites.

Use Firefox browser (http://www.mozilla.org)
Firefox is faster, safer and better browser than Internet Explorer.

Keep your systen up-to-date (http://windowsupdate.microsoft.com)
Visit Windows Update regularly.

Keep your antivirus and firewall up-to-date
Scan your computer regularly with your antivirus.

Read this article by TonyKlein (http://forums.spybot.info/showthread.php?t=279)
So how did I get infected in the first place?

Stand Up and Be Counted ! (http://www.malwarecomplaints.info/index.php)
The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.


Stay clean and be safe :bigthumb:

pimuni
2007-03-01, 23:32
thank you so much for all the help! my computer is running a bit faster and is not taking as long as it used to during startup. :eek:

Mr_JAk3
2007-03-02, 07:41
That's great news and you're very welcome :D:

As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.

Glad we could help :2thumb: