PDA

View Full Version : Malicious Cookie keeps coming back!



lizzyhock
2010-06-10, 04:35
I ran Spybot S&D yesterday it removed 2 malicious cookies one is back again after reboot: Win32 PornPopUp adbrite(dot)com 4 instances showing up as being in my Chrome browser.
Note I could not run ERUNT as it said it was for Vista & Below. What registry backup tool is safe to use for windows 7?
_________________________________________________________________

DDS (Ver_10-03-17.01) - NTFSX64
Run by X at 21:15:51.76 on Wed 06/09/2010
Internet Explorer: 8.0.7600.16385
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5887.4102 [GMT -7:00]


============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskhost.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\WUDFHost.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\System32\StikyNot.exe
C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
C:\Windows\System32\spoolsv.exe
c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\splwow64.exe
C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Users\X\Downloads\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

mLocal Page = c:\windows\syswow64\blank.htm
uURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
uURLSearchHooks: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
mURLSearchHooks: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
mWinlogon: Userinit=userinit.exe
BHO: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~2\spybot~1\SDHelper.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: TBSB05974 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files (x86)\search toolbar\tbcore3.dll
TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - c:\program files (x86)\search toolbar\tbcore3.dll
TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
TB: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe
mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
mRun: [<NO NAME>]
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
StartupFolder: c:\users\x\appdata\roaming\micros~1\windows\startm~1\programs\startup\digsby.lnk - c:\program files (x86)\digsby\digsby.exe
mPolicies-explorer: NoActiveDesktop = 1 (0x1)
mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~2\spybot~1\SDHelper.dll
TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
mRun-x64: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
mRun-x64: [PC-Doctor for Windows localizer] c:\program files\pc-doctor for windows\localizer.exe
Hosts: 127.0.0.1 www.spywareinfo.com

================= FIREFOX ===================

FF - ProfilePath - c:\users\x\appdata\roaming\mozilla\firefox\profiles\f0969juz.default\
FF - plugin: c:\program files (x86)\google\update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
FF - plugin: c:\users\default\appdata\local\huludesktop\instances\0.9.9.1\nphdplg.dll

---- FIREFOX POLICIES ----
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-5-13 121936]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-5-13 22096]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-5-13 63568]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-9-16 23536]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-14 1255736]
S4 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-5-13 133104]

=============== Created Last 30 ================

2010-06-10 04:04:04 0 dc----w- c:\program files (x86)\Trend Micro
2010-06-03 04:00:21 0 dc----w- c:\users\x\appdata\roaming\{8126D2ED-1984-4573-9D57-97637E10C716}
2010-06-03 04:00:07 0 dc----w- C:\swsetup
2010-05-28 16:21:04 0 dc----w- c:\program files (x86)\4shared.com
2010-05-28 16:21:02 0 dc----w- c:\users\x\appdata\roaming\4shared Desktop
2010-05-28 16:21:02 0 dc----w- c:\program files (x86)\4shared Desktop
2010-05-27 07:01:36 0 dc----w- c:\programdata\Recovery
2010-05-21 01:12:41 14336 -c--a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-05-19 01:46:00 0 dc----w- c:\program files (x86)\Conduit
2010-05-19 01:45:59 0 dc----w- c:\program files (x86)\Zynga
2010-05-18 17:54:59 0 dc----w- c:\users\x\appdata\roaming\Digsby
2010-05-18 17:54:59 0 dc----w- c:\programdata\Digsby
2010-05-18 16:01:21 0 dc----w- c:\programdata\Adobe
2010-05-18 14:37:23 0 dc----w- c:\programdata\Chit Chat For FaceBook
2010-05-18 10:51:16 118784 -c--a-w- c:\windows\syswow64\MSSTDFMT.DLL
2010-05-18 10:51:16 1071088 -c--a-w- c:\windows\syswow64\MSCOMCTL.OCX
2010-05-18 10:04:36 0 dc----w- c:\users\x\appdata\roaming\Trillian
2010-05-18 08:02:17 65536 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TM.blf
2010-05-18 08:02:17 524288 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TMContainer00000000000000000002.regtrans-ms
2010-05-18 08:02:17 524288 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TMContainer00000000000000000001.regtrans-ms
2010-05-18 05:13:42 0 dc----w- c:\program files (x86)\SpywareBlaster
2010-05-18 05:11:41 0 dc----w- c:\programdata\Spybot - Search & Destroy
2010-05-18 05:11:40 0 dc----w- c:\program files (x86)\Spybot - Search & Destroy
2010-05-18 05:06:24 0 dc----w- c:\users\x\appdata\roaming\Free Download Manager
2010-05-18 05:06:22 0 dc----w- c:\program files (x86)\Free Download Manager
2010-05-16 02:02:19 0 dc----w- c:\programdata\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
2010-05-16 02:01:47 0 dc----w- c:\users\x\appdata\roaming\hpqLog
2010-05-16 02:01:10 0 dc----w- c:\users\x\appdata\roaming\WinBatch
2010-05-16 01:53:49 0 dc----w- c:\users\x\appdata\roaming\HP Support Assistant
2010-05-16 01:53:48 0 dc----w- c:\users\x\appdata\roaming\HpUpdate
2010-05-14 17:26:50 0 dc----w- c:\windows\syswow64\Wat
2010-05-14 17:26:50 0 dc----w- c:\windows\system32\Wat
2010-05-14 17:12:06 0 dc----w- c:\program files (x86)\MSXML 4.0
2010-05-14 17:08:52 91648 ----a-w- c:\windows\syswow64\avifil32.dll
2010-05-14 17:07:41 716800 ----a-w- c:\windows\syswow64\jscript.dll
2010-05-14 17:06:43 464896 ----a-w- c:\windows\system32\drivers\srv.sys
2010-05-14 17:06:43 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-05-14 15:50:07 0 dc----w- c:\windows\pss
2010-05-14 04:37:13 63568 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-05-14 04:37:12 0 -c--a-w- c:\windows\syswow64\config.nt
2010-05-14 04:36:37 38848 -c--a-w- c:\windows\syswow64\avastSS.scr
2010-05-14 04:36:37 165032 -c--a-w- c:\windows\syswow64\aswBoot.exe
2010-05-14 04:36:34 0 dc----w- c:\programdata\Alwil Software
2010-05-14 04:36:34 0 dc----w- c:\program files\Alwil Software
2010-05-14 02:20:49 270208 -c----w- c:\windows\system32\MpSigStub.exe
2010-05-14 02:15:02 0 dc----w- c:\users\x\appdata\roaming\PictureMover

==================== Find3M ====================

2010-05-21 01:12:38 7680 ----a-w- c:\windows\syswow64\instnm.exe
2010-05-21 01:12:38 5120 ----a-w- c:\windows\syswow64\wow32.dll
2010-05-21 01:12:38 25600 ----a-w- c:\windows\syswow64\setup16.exe
2010-05-21 01:12:38 243200 ----a-w- c:\windows\system32\wow64.dll
2010-05-21 01:12:38 2048 ----a-w- c:\windows\syswow64\user.exe
2010-05-21 01:12:38 14336 ----a-w- c:\windows\syswow64\ntvdm64.dll
2010-05-21 01:12:34 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys
2010-05-21 01:11:35 960512 ----a-w- c:\windows\system32\CPFilters.dll
2010-05-21 01:11:35 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
2010-05-21 01:11:35 613888 ----a-w- c:\windows\system32\psisdecd.dll
2010-05-21 01:11:35 552960 ----a-w- c:\windows\system32\msdri.dll
2010-05-21 01:11:35 465408 ----a-w- c:\windows\syswow64\psisdecd.dll
2010-05-14 17:14:29 220672 ----a-w- c:\windows\system32\wintrust.dll
2010-05-14 17:14:29 172032 ----a-w- c:\windows\syswow64\wintrust.dll
2010-05-14 17:14:15 139264 ----a-w- c:\windows\system32\cabview.dll
2010-05-14 17:14:15 132608 ----a-w- c:\windows\syswow64\cabview.dll
2010-05-14 17:14:00 612352 ----a-w- c:\windows\system32\vbscript.dll
2010-05-14 17:14:00 427520 ----a-w- c:\windows\syswow64\vbscript.dll
2010-05-14 17:13:46 976896 ----a-w- c:\windows\system32\inetcomm.dll
2010-05-14 17:13:46 740864 ----a-w- c:\windows\syswow64\inetcomm.dll
2010-05-14 17:13:27 70656 ----a-w- c:\windows\syswow64\fontsub.dll
2010-05-14 17:13:27 148480 ----a-w- c:\windows\system32\t2embed.dll

lizzyhock
2010-06-18, 14:41
New problem is pending here!
http://forums.spybot.info/showthread.php?p=374747#post374747

could you please close this thread?