PDA

View Full Version : help with win32.trojanDropper



wingeater
2007-04-24, 21:34
Logfile of HijackThis v1.99.1
Scan saved at 3:29:16 PM, on 4/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\Program Files\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Java\jre1.5.0_11\bin\jucheck.exe
C:\hijackthis\hijackthis\HijackThis.exe
C:\WINDOWS\system32\cidaemon.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [LiveMonitor] C:\Program Files\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\dtv\EXPLBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1160879733781
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

wingeater
2007-04-24, 21:35
Incident Status Location

Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/Outster Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[.outster.com/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[.paycounter.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\nqjqlw4g.default\cookies.txt[landing.domainsponsor.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Dad\Cookies\dad@atwola[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Dad\Cookies\dad@ccbill[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Dad\Cookies\dad@com[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Dad\Cookies\dad@doubleclick[1].txt
Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Dad\Cookies\dad@gostats[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Dad\Cookies\dad@go[1].txt
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Dad\Cookies\dad@i.screensavers[2].txt
Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Dad\Cookies\dad@kinghost[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Dad\Cookies\dad@mediaplex[1].txt
Spyware:Cookie/Outster Not disinfected C:\Documents and Settings\Dad\Cookies\dad@outster[1].txt
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Dad\Cookies\dad@toplist[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Dad\Cookies\dad@www.burstbeacon[1].txt
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Dad\Cookies\dad@yadro[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.paycounter.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.xiti.com/]
Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.i.screensavers.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Jamie\Application Data\Mozilla\Firefox\Profiles\2xq2bqu4.default\cookies.txt[.sexlist.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@burstnet[2].txt
Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@ccbill[1].txt
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@go[2].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@systemdoctor[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@www.burstbeacon[1].txt
Spyware:Cookie/Systemdoctor Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@www.systemdoctor[1].txt
Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Jamie\Cookies\jamie@www3.addfreestats[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Meme\Cookies\meme@atwola[1].txt

pskelley
2007-04-25, 14:27
Welcome to the forum, You have not provided any information about this "win32.trojanDropper" the name, location, program finding it? HJT is showing nothing but an out of date Java program, and the antivirus scan is showing nothing but cookies that you should know how to delete?

If you are still having malware issues, let do this.

1) Open Hijackthis.
Click the "Open the Misc Tools" section Button.
Click the "Open Uninstall Manager" Button.
Click the "Save list..." Button.
Save it to your desktop. Copy and paste the contents into your reply.

2) Follow the directions in this link to download, install, updated and run AVG Anti-Spyware 7.5. Make sure you choose to delete or at least quarantine anything it finds and save the scan report to post.
http://forums.security-central.us/showthread.php?t=3165

3) Provide some information about this item as suggested above. What symptoms are you experiencing, any error messages from Windows? If so post them "word for word"

Restart the computer and post information, the uninstall list and the scan report. Use post reply, stay in this topic.

Thanks

wingeater
2007-04-26, 18:51
The win32.trojanDopper had come up with AdAware, but after running AGV I ran AdAware again and it didn't show up anymore. I do get a windows error during shutdown, but I can never read it because it shutsdown before I can read it. The other problem I get is that spybot always gives me a "microsoft.WindowsSecurityCenter_disabled" registry change. I have it fixed and then after rebooting it returns.


Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Adobe Shockwave Player
Agere Systems PCI-SV92PP Soft Modem
AppCore
ArcSoft PhotoImpression 3.0
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Decoder
ATI Display Driver
ATI HFX Pack
ATI HYDRAVISION
ATI Multimedia Center 9.10
ATI Parental Control & Encoder
ATI Problem Report Wizard
ATI Remote Wonder 3.03
AuthorScript Engine 1.0
AV
Brother HL-2040
ccCommon
Comanche 4 Demo
Copy Utility
DAO
EPSON Photo Print
EPSON Smart Panel
EPSON TWAIN 5
Eye of the Storm 3000
GameShadow
GameShadow
GTAIII
GUIDE PLUS+(TM) for Windows® System - ATI
HijackThis 1.99.1
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows XP (KB896344)
Hotfix for Windows XP (KB914440)
Hotfix for Windows XP (KB915865)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB928388)
Hotfix for Windows XP (KB929120)
Hoyle Board Games 4
Hoyle Card Games 3 Demo
Internet Worm Protection
J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11
LiveUpdate 1.7 (Symantec Corporation)
LiveUpdate 3.1 (Symantec Corporation)
LiveUpdate Notice (Symantec Corporation)
MediaKey
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office XP Professional
Microsoft Plus! for Windows XP
Microsoft User-Mode Driver Framework Feature Pack 1.0
MSI Live Update 3
MSXML 4.0 SP2 (KB927978)
Nero Suite
Norton AntiVirus
Norton AntiVirus (Symantec Corporation)
Norton AntiVirus Help
Norton AntiVirus Parent MSI
Norton AntiVirus SYMLT MSI
Norton Protection Center
Panda ActiveScan
PF1250-1650 Guide
Pinnacle Hollywood FX for Studio
QuickTime
S3 S3Display
S3 S3Gamma2
S3 S3Info2
S3 S3Overlay
S3 S3TrayPlus
ScanToWeb
Security Update for Microsoft .NET Framework 2.0 (KB917283)
Security Update for Microsoft .NET Framework 2.0 (KB922770)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926247)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Sentinel System Driver
Sid Meier's Civilization 4
SmartSound Quicktracks Plugin
SPBBC 32bit
Spybot - Search & Destroy 1.4
Studio 9
Symantec
Symantec Real Time Storage Protection Component
SymNet
TitanTV Client components for ATI
UniChrome Pro IGP Display Driver and Utilities
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB904942)
Update for Windows XP (KB908531)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920342)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB925876)
Update for Windows XP (KB929338)
Update for Windows XP (KB931836)
VIA Platform Device Manager
VIA Vinyl Audio Codecs Driver Setup Program
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 7
Windows Media Encoder 9 Series
Windows Media Encoder 9 Series
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Format SDK Hotfix - KB891122
Windows Media Player 11
Windows Media Player 11
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
World of Warcraft
Xfire (remove only)





---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:45:56 AM 4/26/2007

+ Scan result:



:mozilla.173:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.247realmedia : No action taken.
:mozilla.245:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.145:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.146:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.147:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.33:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.6:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.7:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.302:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.303:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.304:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.305:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.239:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@www.burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.205:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.207:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.208:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Meme\Cookies\meme@ads.cnn[1].txt -> TrackingCookie.Cnn : No action taken.
:mozilla.19:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.115:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.116:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.117:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.118:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.119:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.11:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.120:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.121:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.12:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.13:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.14:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.15:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.16:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.240:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.242:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.19:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Hotlog : No action taken.
:mozilla.283:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Imrworldwide : No action taken.
:mozilla.209:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Information : No action taken.
:mozilla.274:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Live : No action taken.
:mozilla.275:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Live : No action taken.
:mozilla.276:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Live : No action taken.
C:\Documents and Settings\Meme\Cookies\meme@search.live[2].txt -> TrackingCookie.Live : No action taken.
:mozilla.324:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Masterstats : No action taken.
:mozilla.347:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.349:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@data2.perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
:mozilla.189:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Paycounter : No action taken.
:mozilla.28:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc15.txt -> TrackingCookie.Paycounter : No action taken.
:mozilla.206:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.357:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Sexlist : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.277:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.278:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.280:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.281:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.252:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.256:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.257:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Dad\Cookies\dad@anad.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Dad\Cookies\dad@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@anad.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@anat.tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.230:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Toplist : No action taken.
:mozilla.241:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Jamie\Cookies\jamie@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
C:\Documents and Settings\Meme\Cookies\meme@m.webtrends[1].txt -> TrackingCookie.Webtrends : No action taken.
:mozilla.143:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Xhit : No action taken.
:mozilla.144:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Xhit : No action taken.
:mozilla.229:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.231:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.232:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.247:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.248:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.249:C:\RECYCLER\S-1-5-21-725345543-1708537768-2146997909-1004\Dc16.txt -> TrackingCookie.Zedo : No action taken.


::Report end

pskelley
2007-04-26, 19:21
Let's start with this one which I get also and ignore rather than make any changes:
Why does Spybot-S&D flag changes in the Windows Security Center?
http://www.safer-networking.org/en/faq/46.html
http://www.safer-networking.org/en/faq/index.html
http://forums.spybot.info/showthread.php?t=250

Can't help without the error, but here are some resources.
http://www.generation.net/~hleboeuf/
http://www.dummies.com/WileyCDA/DummiesArticle/id-1642.html
http://www.google.com/search?=en&q=shutdown+error+messages&btnG=Google+Search

Uninstall list:

J2SE Runtime Environment 5.0 Update 10
J2SE Runtime Environment 5.0 Update 11

http://forums.spybot.info/showpost.php?p=12880&postcount=2
Download the newest version and uninstall all old versions in Add Remove Programs

Have a look at the list yourself, if you see any you don't know, investigate them, I probably don't know them either. If you see any you no longer use, uninstall them. Leave the Windows stuff alone, it will go away when SP3 is released.

AVG Anti-Spyware

Why did you take no action when I specified delete or quarantine?

Empty the Recycle Bin and that will take care most of them, the rest are cookies.

These instructions will take care of the cookies if followed:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html

http://www.microsoft.com/windowsxp/using/helpandsupport/learnmore/tips/mcgill1.mspx

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

wingeater
2007-04-26, 20:09
sorry I did take action, but I saved the log before I deleted them.

pskelley
2007-05-01, 12:08
As the problem appears to be resolved this topic has been closed.

If you need it re-opened please send me or a forum staff member a private message (pm) and provide a link to the thread; this applies only to the original topic starter.

Anyone else with similar problems please start a new topic.

Thanks