PDA

View Full Version : Zlob.Downloader logs



morpheus_77
2006-07-11, 20:07
Hey... i followed all the instructions from the sticky on how to remove spyware such as zlob.downloader using ewido and hijackthis and smitfraud. So far it all seems to have worked. I'm going to post my logs anyways just to make sure that i don't have anything further to do. Thanks!

morpheus_77
2006-07-11, 20:08
file of HijackThis v1.99.1
Scan saved at 1:58:21 PM, on 11/07/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\NetAssistant\bin\mpbtn.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [Mouse Suite 98 Daemon] ICO.EXE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [AIM] C:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138383301296
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe

morpheus_77
2006-07-11, 20:09
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 1:45:39 PM 11/07/2006

+ Scan result:



:mozilla.136:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.137:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.138:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.139:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.100:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.101:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.102:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.124:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.125:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.126:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.128:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.129:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.130:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.131:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.132:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.133:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.134:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.135:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.284:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.544:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.572:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.654:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.88:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.89:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.90:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.91:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.92:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.93:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.94:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.96:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.97:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.98:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.99:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bailey\Cookies\bailey@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Bailey\Cookies\bailey@torstardigital.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.159:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.160:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.161:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.178:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.179:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.43:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.44:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.62:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.63:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.17:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.920:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Bailey\Cookies\bailey@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.308:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.309:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.921:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.864:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.368:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.369:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.829:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.830:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.342:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.343:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.344:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.45:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.387:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.388:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.389:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.409:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.248:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.249:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.250:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.251:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.252:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.253:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.254:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.41:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.42:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.46:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.47:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.48:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.49:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.50:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.458:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.492:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
:mozilla.641:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.642:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.660:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.658:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.180:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.181:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.182:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.183:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.

morpheus_77
2006-07-11, 20:10
:mozilla.184:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.674:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.675:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.676:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.677:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.678:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.679:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.680:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.681:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.717:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.400:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.401:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.402:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.403:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.404:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.742:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.743:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.744:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.745:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.355:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.356:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.357:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.358:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.359:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.360:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.361:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.362:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.363:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.364:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.365:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.366:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.934:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.795:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.796:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.797:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.798:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.799:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.801:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.802:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.803:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Bailey\Cookies\bailey@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.812:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.813:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.814:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.815:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.816:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.817:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.818:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.819:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.37:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.38:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.39:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.185:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.186:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.187:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.701:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.702:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.703:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.704:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.705:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.843:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.856:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.857:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.858:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.859:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.860:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.861:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.862:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.863:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Bailey\Cookies\bailey@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.846:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.847:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.848:C:\Documents and Settings\Bailey\Application Data\Mozilla\Firefox\Profiles\bwiy6wv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

morpheus_77
2006-07-11, 20:12
SmitFraudFix v2.69

Scan done at 12:41:33.68, 11/07/2006
Run from C:\Documents and Settings\Bailey\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


Again i think i'm ok. But i figure its best left up to the experts to decide. Again thanks alot!

LonnyRJones
2006-07-13, 15:04
Looks fine morpheus_77

Are there any current problems ?

morpheus_77
2006-07-13, 16:23
Nope, everything seems to be working fine. Thanks for looking it over.

LonnyRJones
2006-07-13, 19:41
Great

You should ensure all chat/messenger and media programs are up to date, uninstall those that do not get used.
Acrobat reader and suns java have a more recent versions.

Think Prevention: Put in place a good hosts file
http://www.mvps.org/winhelp2002/hosts.htm

Also see "So how did I get infected in the first place?"
http://forums.spybot.info/showthread.php?t=279

tashi
2006-07-19, 00:52
As the problem appears to be resolved this topic will be archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.