PDA

View Full Version : Popups: smitfraud_c.toolbar888



jmerry
2007-04-13, 00:06
Hi folks,

I have contracted some adware and could use some help getting rid of it. The symptoms are primarily pop-ups in either firefox or internet explorer (I typically use firefox, but IE pop-ups happen anyway). I haven't been able to kill this myself using adware, counterspy, or spybot.

I tried to follow the directions in your sticky.

1. I ran Panda online virus scan. Here is the log:

Incident Status Location

Spyware:Spyware/Virtumonde Not disinfected C:\WINDOWS\system32\lhewxfgg.dll
Spyware:spyware/virtumonde Not disinfected c:\windows\system32\vtstt.dll
Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/hc/41409448]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[statse.webtrendslive.com/dcsajnkbj11e5hmi283hr30a8_2c7p]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Cookies\jen@2o7[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jen\Cookies\jen@dist.belnk[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jen\Cookies\jen@perf.overture[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jen\Cookies\jen@www.burstbeacon[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[winantivirus.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.winantivirus.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.errorsafe.com/]
Spyware:Cookie/ErrorSafe Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.errorsafe.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.112.2o7.net/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adtech.de/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.com.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.go.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.serving-sys.com/]

jmerry
2007-04-13, 00:07
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[winantispyware.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Justin\Cookies\justin@adultfriendfinder[2].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Justin\Cookies\justin@findwhat[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Cookies\justin@mediaplex[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Cookies\justin@realmedia[2].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Justin\Cookies\justin@statcounter[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Cookies\justin@stats1.reliablestats[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Cookies\justin@winantivirus[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix\SmitfraudFix\Process.exe
Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix\SmitfraudFix\restart.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix.zip[SmitfraudFix/restart.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Local Settings\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\Cache\633285D9d01[SmitfraudFix/Process.exe]
Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Justin\Local Settings\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\Cache\633285D9d01[SmitfraudFix/restart.exe]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Documents and Settings\Justin\Local Settings\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\Cache\A23E4567d01
Adware:Adware/IST.YourSiteBar Not disinfected C:\Documents and Settings\Justin\Local Settings\Temporary Internet Files\Content.IE5\KRI3EZQH\CAUUC02P.HTM
Adware:Adware/IST.YourSiteBar Not disinfected C:\Documents and Settings\Justin\Local Settings\Temporary Internet Files\Content.IE5\OR67CX8V\CA1AGNEC.HTM
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Cookies\jen@atwola[1].txt
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-ati.hitbox.com/]
Spyware:Cookie/Doubleclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Serving-sys Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adserver Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Versiontracker Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.versiontracker.com/]
Spyware:Cookie/Tribalfusion Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Zedo Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Coremetrics Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Valueclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Bluestreak Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/QuestionMarket Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.servedby.advertising.com/]
Spyware:Cookie/BurstBeacon Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.kount.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.advertising.com/]
Spyware:Cookie/CentrPort Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@atwola[2].txt
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@com[2].txt
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@go[2].txt
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@kount[1].txt
Spyware:Cookie/BurstBeacon

jmerry
2007-04-13, 00:08
2. I rebooted to safe mode. It was behaving strangely in that I was unable to see the desktop. But I was able to use task manager to launch spybot in safe mode. First time through it picked up lots of cookies, plus smitfraud-c.toolbar888. After asking it to fix those issues, I scanned again and it turned up clean.

(as a side note, I've run spybot out of safe mode and it also detects smitfraud-c.toolbar888, and "cleans" it, each time. But it always comes back, eventually).

3. Launched hijackthis. Here is the log:
Logfile of HijackThis v1.99.1
Scan saved at 2:36:53 PM, on 4/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\ZipGenius 6\zipgenius.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\xysnpbgd.dll",setvm
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)

I would really appreciate help on this, as I'd prefer not to have to reformat and reinstall everything.

Thanks,
Justin

Shaba
2007-04-18, 18:40
Hi jmerry

Rename HijackThis.exe to scanner.exe and post back a fresh HijackThis log, please :)

jmerry
2007-04-18, 20:05
Thanks for getting back to me.

Hijackthis.exe renamed to scanner.exe. Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 11:03:52 AM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tjdnssvd.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {9D7EF71F-92F4-4E1E-93DE-E21436E4C815} - C:\WINDOWS\system32\urqpmlk.dll
O2 - BHO: (no name) - {9F47BB32-3F3B-480A-A0BE-67D5D9194CB1} - C:\WINDOWS\system32\vtstt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\xysnpbgd.dll",setvm
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: urqpmlk - C:\WINDOWS\SYSTEM32\urqpmlk.dll
O20 - Winlogon Notify: vtstt - C:\WINDOWS\system32\vtstt.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)

Shaba
2007-04-18, 20:07
Hi

Please download VundoFix.exe (http://www.atribune.org/ccount/click.php?id=4) to your desktop.
Double-click VundoFix.exe to run it.
Click the Scan for Vundo button.
Once it's done scanning, click the Remove Vundo button.
You will receive a prompt asking if you want to remove the files, click YES
Once you click yes, your desktop will go blank as it starts removing Vundo.
When completed, it will prompt that it will reboot your computer, click OK.
Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

jmerry
2007-04-18, 20:31
Ok, I have done as you asked.

Vundofix ran and found several files. After deleting them it asked me to click OK for reboot. It did not run on reboot, but I did get this error message after logging into my account in windows xp:

ERROR LOADING C:\windows\system32\xysnpbgd.dll

It looks like this file was among those that vundofix found and killed.

Here is the Vundofix log:
------------
VundoFix V6.3.19

Checking Java version...

Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 11:12:19 AM 4/18/2007

Listing files found while scanning....

C:\WINDOWS\system32\dgbpnsyx.ini
C:\WINDOWS\system32\lhewxfgg.dll
C:\WINDOWS\system32\ttstv.bak1
C:\WINDOWS\system32\ttstv.bak2
C:\WINDOWS\system32\ttstv.ini
C:\WINDOWS\system32\ttstv.ini2
C:\WINDOWS\system32\ttstv.tmp
C:\WINDOWS\system32\vtstt.dll
C:\WINDOWS\system32\xysnpbgd.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\dgbpnsyx.ini
C:\WINDOWS\system32\dgbpnsyx.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\lhewxfgg.dll
C:\WINDOWS\system32\lhewxfgg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.bak1
C:\WINDOWS\system32\ttstv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.bak2
C:\WINDOWS\system32\ttstv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.ini
C:\WINDOWS\system32\ttstv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.ini2
C:\WINDOWS\system32\ttstv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.tmp
C:\WINDOWS\system32\ttstv.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtstt.dll
C:\WINDOWS\system32\vtstt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xysnpbgd.dll
C:\WINDOWS\system32\xysnpbgd.dll Has been deleted!

Performing Repairs to the registry.
Done!
------------


And here is the new scanner.exe (hijackthis) log:
-----------
Logfile of HijackThis v1.99.1
Scan saved at 11:26:50 AM, on 4/18/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tjdnssvd.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {9D7EF71F-92F4-4E1E-93DE-E21436E4C815} - C:\WINDOWS\system32\urqpmlk.dll
O2 - BHO: (no name) - {9F47BB32-3F3B-480A-A0BE-67D5D9194CB1} - C:\WINDOWS\system32\vtstt.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\xysnpbgd.dll",setvm
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: urqpmlk - C:\WINDOWS\SYSTEM32\urqpmlk.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)
----------

Thanks for your continued help!!

Shaba
2007-04-19, 08:00
Hi

Uninstall via add/remove programs these java runtime environments:

1.5.0.5

1.5.0.6

1.5.0.9

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tjdnssvd.dll
O2 - BHO: (no name) - {9F47BB32-3F3B-480A-A0BE-67D5D9194CB1} - C:\WINDOWS\system32\vtstt.dll (file missing)
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\xysnpbgd.dll",setvm

Close all windows including browser and press fix checked.


* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens,Click Scan for Vundo button.
* Once the scan is complete, Right Click inside the listbox (white box) and click add more files
* Copy&Paste the 2 entries below into the top 2 boxes

C:\WINDOWS\system32\urqpmlk.dll
C:\WINDOWS\system32\klmpqru.*

* Click Add Files and Click Close Window
* Click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.

jmerry
2007-04-19, 19:35
Hi

Uninstall via add/remove programs these java runtime environments:

1.5.0.5

1.5.0.6

1.5.0.9

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tjdnssvd.dll
O2 - BHO: (no name) - {9F47BB32-3F3B-480A-A0BE-67D5D9194CB1} - C:\WINDOWS\system32\vtstt.dll (file missing)
O4 - HKLM\..\Run: [PrintDrive] rundll32.exe "C:\WINDOWS\system32\xysnpbgd.dll",setvm

Close all windows including browser and press fix checked.


I have done the above steps. However, when I try to do what you said to do below, I do not see an option to "put a check next to run vundofix as a task" after I double-click on Vundofix.exe. All I can see to do is scan for Vundo or Remove Vundo. Not sure what I'm doing wrong...



* Double-click VundoFix.exe to run it.
* Put a check next to Run VundoFix as a task.
* You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
* When VundoFix re-opens,Click Scan for Vundo button.
* Once the scan is complete, Right Click inside the listbox (white box) and click add more files
* Copy&Paste the 2 entries below into the top 2 boxes

C:\WINDOWS\system32\urqpmlk.dll
C:\WINDOWS\system32\klmpqru.*

* Click Add Files and Click Close Window
* Click the Remove Vundo button.
* You will receive a prompt asking if you want to remove the files, click YES
* Once you click yes, your desktop will go blank as it starts removing Vundo.
* When completed, it will prompt that it will shutdown your computer, click OK.
* Turn your computer back on.
* Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Thanks!
Justin

Shaba
2007-04-19, 19:36
Hi

"I do not see an option to "put a check next to run vundofix as a task" after I double-click on Vundofix.exe"

Ok, then just skip this -> "put a check next to run vundofix as a task" and move on, please :)

jmerry
2007-04-19, 20:05
Ok, did it--thanks for your ongoing help! I really appreciate it.

Vundofix log (I think some of this is from the first run, but I'll include it anyway--also I did remove java release 6 from add/remove programs, I don't know what it's still showing up):
-------

VundoFix V6.3.19

Checking Java version...

Java version is 1.5.0.5
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Java version is 1.5.0.9
Old versions of java are exploitable and should be removed.

Scan started at 11:12:19 AM 4/18/2007

Listing files found while scanning....

C:\WINDOWS\system32\dgbpnsyx.ini
C:\WINDOWS\system32\lhewxfgg.dll
C:\WINDOWS\system32\ttstv.bak1
C:\WINDOWS\system32\ttstv.bak2
C:\WINDOWS\system32\ttstv.ini
C:\WINDOWS\system32\ttstv.ini2
C:\WINDOWS\system32\ttstv.tmp
C:\WINDOWS\system32\vtstt.dll
C:\WINDOWS\system32\xysnpbgd.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\dgbpnsyx.ini
C:\WINDOWS\system32\dgbpnsyx.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\lhewxfgg.dll
C:\WINDOWS\system32\lhewxfgg.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.bak1
C:\WINDOWS\system32\ttstv.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.bak2
C:\WINDOWS\system32\ttstv.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.ini
C:\WINDOWS\system32\ttstv.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.ini2
C:\WINDOWS\system32\ttstv.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ttstv.tmp
C:\WINDOWS\system32\ttstv.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\vtstt.dll
C:\WINDOWS\system32\vtstt.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\xysnpbgd.dll
C:\WINDOWS\system32\xysnpbgd.dll Has been deleted!

Performing Repairs to the registry.
Done!

VundoFix V6.3.19

Checking Java version...

Java version is 1.5.0.6
Old versions of java are exploitable and should be removed.

Scan started at 10:40:06 AM 4/19/2007

Listing files found while scanning....

C:\WINDOWS\system32\ayadd.bak1
C:\WINDOWS\system32\ayadd.ini
C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\eodborpf.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\ayadd.bak1
C:\WINDOWS\system32\ayadd.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\ayadd.ini
C:\WINDOWS\system32\ayadd.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\ddaya.dll
C:\WINDOWS\system32\ddaya.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\eodborpf.dll
C:\WINDOWS\system32\eodborpf.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\urqpmlk.dll
C:\WINDOWS\system32\urqpmlk.dll Could not be deleted.

Performing Repairs to the registry.
Done!

Beginning removal...

Attempting to delete C:\WINDOWS\system32\urqpmlk.dll
C:\WINDOWS\system32\urqpmlk.dll Has been deleted!

Performing Repairs to the registry.
Done!
-----------------------------
And hijackthis:
-----------------------------
Logfile of HijackThis v1.99.1
Scan saved at 10:58:18 AM, on 4/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\igoftlfs.dll
O2 - BHO: (no name) - {22EA464C-DF30-4527-B233-5D513C5F03B5} - C:\WINDOWS\system32\ddaya.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: (no name) - {9D7EF71F-92F4-4E1E-93DE-E21436E4C815} - C:\WINDOWS\system32\urqpmlk.dll (file missing)
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)

Shaba
2007-04-19, 20:08
Hi

Open HijackThis, click do a system scan only and checkmark these:

O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\igoftlfs.dll
O2 - BHO: (no name) - {22EA464C-DF30-4527-B233-5D513C5F03B5} - C:\WINDOWS\system32\ddaya.dll (file missing)
O2 - BHO: (no name) - {9D7EF71F-92F4-4E1E-93DE-E21436E4C815} - C:\WINDOWS\system32\urqpmlk.dll (file missing)
O4 - Startup: PowerReg Scheduler V3.exe

Close all windows including browser and press fix checked

Reboot

Delete if present:

C:\WINDOWS\system32\igoftlfs.dll

Empty Recycle Bin

To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

http://img.bleepingcomputer.com/tutorials/hijackthis/uninstall-man.gif

5. Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

Post:

- a fresh HijackThis log
- uninstall list

jmerry
2007-04-19, 20:23
Thanks for the continued help!

Fresh hijackthis log:
------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:20:49 AM, on 4/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)
---------------------
And here is uninstall_list.txt:
---------------------

Ad-Aware SE Personal
Adobe Illustrator 10
Adobe Photoshop 7.0
Adobe Reader 7.0.9
Adobe SVG Viewer 3.0
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
BioWare Premium Module: Neverwinter Nights - Pirates of the Sword Coast
BioWare Premium Module: Neverwinter Nights - Wyvern Crown of Cormyr
Community Expansion Pack version 1.50
Creative System Information
DivX
DivX Player
Evil Genius
FastStone Image Viewer 2.29
GameSpy Arcade
Google Earth
HijackThis 1.99.1
hp instant support
HP Memories Disc
HP Photo and Imaging 2.2 - Scanjet 3970 Series
iTunes
Macromedia Flash Player 8
McAfee VirusScan Enterprise
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Mozilla Firefox (2.0.0.3)
Mozilla Thunderbird (1.5.0.8)
MSN Music Assistant
Napster
Napster Burn Engine
NCSS 2000 - PASS 2000
Nero OEM
Neverwinter Nights Gold Edition
OOTP Baseball 2006
OOTP Baseball 2007
Panda ActiveScan
Photosmart 130,230,7150,7345,7350,7550 (Remove only)
ProCite 5
QuickTime
Radio@Netscape
Realtek AC'97 Audio
REALTEK Gigabit and Fast Ethernet NIC Driver
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923789)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
SigmaPlot 4.01
SigmaPlot 8.0
Spybot - Search & Destroy 1.4
SSH Secure Shell
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
Windows Genuine Advantage v1.3.0254.0
Windows Installer 3.1 (KB893803)
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
ZipGenius 6 (6.0.2.1060)

-Justin

Shaba
2007-04-20, 10:12
Hi

Run a scan with panda and post its log along with a fresh HijackThis log, please :)

jmerry
2007-04-20, 20:52
Hi there,

Sorry it took so long--Panda is not quick! :)

As a side note, I have seen no pop-ups after what we did yesterday. Also, I may not be around tomorrow, but will be in on Sunday, so if I don't respond immediately, that is why.

Thanks so much for your ongoing help. I can't tell you how much I appreciate it.
-Justin


Here is the Panda log:
-------------------------

Incident Status Location

Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/hc/41409448]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[statse.webtrendslive.com/dcsajnkbj11e5hmi283hr30a8_2c7p]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Cookies\jen@2o7[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Jen\Cookies\jen@dist.belnk[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Jen\Cookies\jen@perf.overture[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jen\Cookies\jen@www.burstbeacon[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.2o7.net/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.com.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.winantiviruspro.com/]
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[stats1.reliablestats.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.advertising.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.winantispyware.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.systemdoctor.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.adtech.de/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.go.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.hotlog.ru/]

jmerry
2007-04-20, 20:53
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.overture.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\9bbtmrqv.default\cookies.txt[server.iad.liveperson.net/hc/89451406]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Justin\Cookies\justin@2o7[2].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Justin\Cookies\justin@adultfriendfinder[2].txt
Spyware:Cookie/DelfinMedia Not disinfected C:\Documents and Settings\Justin\Cookies\justin@delfinproject[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Justin\Cookies\justin@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Justin\Cookies\justin@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Justin\Cookies\justin@fastclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\Justin\Cookies\justin@findwhat[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Justin\Cookies\justin@hitbox[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Justin\Cookies\justin@mediaplex[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Justin\Cookies\justin@realmedia[2].txt
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Justin\Cookies\justin@revenue[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Justin\Cookies\justin@searchportal.information[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Justin\Cookies\justin@stats.drivecleaner[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Justin\Cookies\justin@stats1.reliablestats[1].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Justin\Cookies\justin@statse.webtrendslive[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Justin\Cookies\justin@tribalfusion[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Cookies\justin@winantispyware[2].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Justin\Cookies\justin@winantivirus[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Justin\Cookies\justin@www.drivecleaner[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Justin\Cookies\justin@zedo[2].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Adware:Adware/IST.YourSiteBar Not disinfected C:\Documents and Settings\Justin\Local Settings\Temporary Internet Files\Content.IE5\KRI3EZQH\CAUUC02P.HTM
Adware:Adware/IST.YourSiteBar Not disinfected C:\Documents and Settings\Justin\Local Settings\Temporary Internet Files\Content.IE5\OR67CX8V\CA1AGNEC.HTM
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\eodborpf.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\lhewxfgg.dll.bad
Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\xysnpbgd.dll.bad
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Cookies\jen@atwola[1].txt
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-ati.hitbox.com/]
Spyware:Cookie/Doubleclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Serving-sys Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adserver Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Versiontracker Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.versiontracker.com/]
Spyware:Cookie/Tribalfusion Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Zedo Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Coremetrics Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[data.coremetrics.com/]

jmerry
2007-04-20, 20:54
Spyware:Cookie/Valueclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Bluestreak Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/QuestionMarket Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.servedby.advertising.com/]
Spyware:Cookie/BurstBeacon Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.kount.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.advertising.com/]
Spyware:Cookie/CentrPort Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@atwola[2].txt
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@com[2].txt
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@go[2].txt
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@kount[1].txt
Spyware:Cookie/BurstBeacon Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@www.burstbeacon[2].txt

------------------

Hijack this:
------------------
Logfile of HijackThis v1.99.1
Scan saved at 11:45:37 AM, on 4/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)

Shaba
2007-04-21, 10:47
Hi

Please download ATF Cleaner by Atribune (http://www.atribune.org/ccount/click.php?id=1) and save
it to desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit to close ATF-Cleaner.

Empty this folder:

C:\VundoFix Backups\

Empty Recycle Bin

Re-scan with panda

Post:

- a fresh HijackThis log
- panda report

jmerry
2007-04-23, 21:48
Hi,

Thanks again for your continued help!

I've done as you asked. Below is the panda log.

Many of the things that pop up (after the registry items) are either on my wife's account, or from an old backup that could probably be deleted off of my D: drive. Smitfraudfix is something I downloaded before seeking help in these forums, but I never did anything with it.
----------------

Incident Status Location

Adware:adware/ist.yoursitebar Not disinfected Windows Registry
Adware:adware/ist.istbar Not disinfected Windows Registry
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/hc/41409448]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[statse.webtrendslive.com/dcsajnkbj11e5hmi283hr30a8_2c7p]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\sj8e9tga.default\cookies.txt[.mediaplex.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Justin\Desktop\Files\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\kiueul9g.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Jen\Cookies\jen@atwola[1].txt
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-ati.hitbox.com/]
Spyware:Cookie/Doubleclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Mediaplex Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Atlas DMT Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Serving-sys Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Adserver Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Versiontracker Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.versiontracker.com/]
Spyware:Cookie/Tribalfusion Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.com.com/]
Spyware:Cookie/2o7 Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Zedo Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Coremetrics Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[data.coremetrics.com/]
Spyware:Cookie/Valueclick Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Bluestreak Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.go.com/]
Spyware:Cookie/Hitbox Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/QuestionMarket Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.servedby.advertising.com/]
Spyware:Cookie/BurstBeacon Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.kount.com/]
Spyware:Cookie/Advertising Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.advertising.com/]
Spyware:Cookie/CentrPort Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\jhkumn5x.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Atwola Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@atwola[2].txt
Spyware:Cookie/BurstNet Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@burstnet[1].txt
Spyware:Cookie/Com.com Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@com[2].txt
Spyware:Cookie/Go Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@go[2].txt
Spyware:Cookie/Kount Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@kount[1].txt
Spyware:Cookie/BurstBeacon Not disinfected D:\NewStorageArea 12-13-04\Documents and Settings\Justin\Cookies\justin@www.burstbeacon[2].txt
-------------------

jmerry
2007-04-23, 21:49
Logfile of HijackThis v1.99.1
Scan saved at 12:41:10 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\runservice.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\system32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\scanner.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://docs.google.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1105909760687
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Unknown owner - C:\WINDOWS\system32\CTsvcCDA.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: TiVo Beacon (TivoBeacon2) - Unknown owner - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (file missing)

Shaba
2007-04-24, 08:27
Hi

Those are just cookies; empty cookies in Mozilla Firefox for both Jen and Justin.

Any problems left?

jmerry
2007-04-24, 09:50
No, everything seems great! Thank you so much for your help!! I couldn't have gotten this done without your assistance, and I really, really appreciate it.
-Justin

Shaba
2007-04-24, 16:33
Hi

Then you're clean!

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and reenable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html)

Reenable system restore with instructions from tutorial above

Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the Tools menu and then click on Options.
Click once on the Security tab
Click once on the Internet icon so it becomes highlighted.
Click once on the Custom Level button.
Change the Download signed ActiveX controls to Prompt

Change the Download unsigned ActiveX controls to Disable

Change the Initialize and script ActiveX controls not marked as safe to Disable

Change the Installation of desktop items to Prompt

Change the Launching programs and files in an IFRAME to Prompt

Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.

If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.
Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

See this link for a listing of some online & their stand-alone antivirus programs:

Virus, Spyware, and Malware Protection and Removal Resources (http://www.bleepingcomputer.com/forums/topic405.html)


Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.


Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

For a tutorial on Firewalls and a listing of some available ones see the link below:

Understanding and Using Firewalls (http://www.bleepingcomputer.com/tutorials/tutorial60.html)


Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com (http://www.windowsupdate.com) regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.


Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

A tutorial on installing & using this product can be found here:

Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer (http://www.bleepingcomputer.com/forums/?showtutorial=48)


Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

A tutorial on installing & using this product can be found here:

Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/tutorials/tutorial49.html)


Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

IE/Spyad (http://www.spywarewarrior.com/uiuc/resource.htm) <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
MVPS Hosts file (http://mvps.org/winhelp2002/hosts.htm) <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
Google Toolbar (http://toolbar.google.com/) <= Get the free google toolbar to help stop pop up windows.
Winpatrol (http://www.winpatrol.com/) <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

Stand Up and Be Counted ---> Malware Complaints (http://www.malwarecomplaints.info/index.php) <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place (http://castlecops.com/postlite7736-.html)

Happy surfing and stay clean!

jmerry
2007-04-24, 19:34
I have done the system restore thing, and will check out the other recommended software. I have also posted in the malware complaint forum.

It's incredible that you and your colleagues spend your free time helping people like me resolve these problems. Thanks so much. -j

Shaba
2007-04-26, 19:23
Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.