PDA

View Full Version : virus burst (SMITFRAUD) logs have been posted as requested



maani.bhai
2006-10-04, 02:07
i have followed the instructions as posted and here are my three logs:


Logfile of HijackThis v1.99.1
Scan saved at 8:21:54 PM, on 01/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\programs\Grisoft\AVGFRE~1\avgamsvr.exe
D:\programs\Grisoft\AVGFRE~1\avgupsvc.exe
D:\programs\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\ehome\ehSched.exe
D:\programs\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe
C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\WINDOWS\system32\CTHELPER.EXE
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe
C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
C:\Program Files\SONY\sHotKey\sHotKey.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
C:\program files\support.com\client\bin\tgcmd.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\programs\iTunes\iTunesHelper.exe
D:\programs\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
D:\programs\Ipod\bin\iPodService.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\programs\Grisoft\AVGFRE~1\avgcc.exe
D:\programs\ewido anti-spyware 4.0\ewido.exe
D:\programs\Creative\SBAudigy\TaskBar\CTLTray.exe
D:\programs\Creative\SBAudigy\TaskBar\CTLTask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\wuauclt.exe
D:\programs\palmOne\HOTSYNC.EXE
D:\programs\Hijackthis\HijackThis.exe

N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\muneeb\Application Data\Mozilla\Profiles\default\cw1aoj8z.slt\prefs.js)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [sHotKey] "C:\Program Files\SONY\sHotKey\sHotKey.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] "c:\program files\support.com\client\bin\tgcmd.exe" /server
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [VAIO Recovery] C:\Windows\Sonysys\VAIO Recovery\PartSeal.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] D:\programs\Creative\SBAudigy\PROGRAM\ADGJDet.exe
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] "D:\programs\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OpwareSE2] "D:\programs\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AVG7_CC] D:\programs\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "D:\programs\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [TaskTray] D:\programs\Creative\SBAudigy\TaskBar\CTLTray.exe
O4 - HKCU\..\Run: [TaskBar] D:\programs\Creative\SBAudigy\TaskBar\CTLTask.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
O4 - Startup: HotSync Manager.lnk = D:\programs\palmOne\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart16.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\programs\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to Sunrise - D:\programs\Sunrise\sts\sts.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\programs\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
O14 - IERESET.INF: START_PAGE_URL=http://www.sony.com/vaiopeople
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{06207A36-57AA-4F92-8D8D-1DFD5C0BDDD2}: NameServer = 192.168.2.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{2296FF39-584D-44FD-B398-763740A546CB}: NameServer = 192.168.2.1
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - D:\programs\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - D:\programs\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - D:\programs\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\programs\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - D:\programs\Ipod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SIMATIC IEPG Help Service (s7oiehsx) - SIEMENS AG - C:\program files\common files\Siemens\S7IEPG\s7oiehsx.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SonicStageMonitoring - Sony Corporation - C:\Program Files\Common Files\Sony Shared\WMPlugIn\SonicStageMonitoring.exe
O23 - Service: Sony TV Tuner Controller - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\halsv.exe
O23 - Service: Sony TV Tuner Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\RM_SV.exe
O23 - Service: Sony TVTA Manager - Sony Corporation - C:\Program Files\Sony\Sony TV Tuner Library\SMceMan.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: VAIO Media Music Server (VAIOMediaPlatform-MusicServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Music\SSSvr.exe" /Service=VAIOMediaPlatform-MusicServer-AppServer /DisplayName="VAIO Media Music Server (file missing)
O23 - Service: VAIO Media Music Server (HTTP) (VAIOMediaPlatform-MusicServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-MusicServer-HTTP /RegRoot="Software\Sony Corporation\VAIO Media Platform\2.0" /RegExt="Applications\MusicServer\HTTP (file missing)
O23 - Service: VAIO Media Music Server (UPnP) (VAIOMediaPlatform-MusicServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Photo Server (VAIOMediaPlatform-PhotoServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Photo\appsrv\PhotoAppSrv.exe
O23 - Service: VAIO Media Photo Server (HTTP) (VAIOMediaPlatform-PhotoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-PhotoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\PhotoServer\HTTP (file missing)
O23 - Service: VAIO Media Photo Server (UPnP) (VAIOMediaPlatform-PhotoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe
O23 - Service: VAIO Media Video Server (VAIOMediaPlatform-VideoServer-AppServer) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Video\GPVSvr.exe" /Service=VAIOMediaPlatform-VideoServer-AppServer /DisplayName="VAIO Media Video Server (file missing)
O23 - Service: VAIO Media Video Server (HTTP) (VAIOMediaPlatform-VideoServer-HTTP) - Unknown owner - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-VideoServer-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\VideoServer\HTTP (file missing)
O23 - Service: VAIO Media Video Server (UPnP) (VAIOMediaPlatform-VideoServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe




SmitFraudFix v2.104

Scan done at 18:23:37.51, 01/10/2006
Run from D:\downloads©\badware\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\gqagksr.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\muneeb


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\muneeb\Application Data

C:\Documents and Settings\muneeb\Application Data\Microsoft\Internet Explorer\Quick Launch\VirusBurster 6.2.lnk FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\muneeb\STARTM~1\VirusBurster 6.2.lnk FOUND !
C:\DOCUME~1\muneeb\STARTM~1\Programs\VirusBurster FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\muneeb\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop

C:\DOCUME~1\muneeb\Desktop\VirusBurster.lnk FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\VideosCodec\ FOUND !
C:\Program Files\VirusBurster\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{b166be07-30a4-4d38-b781-44528a630706}"="hydrodictyon"

[HKEY_CLASSES_ROOT\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{b166be07-30a4-4d38-b781-44528a630706}\InProcServer32]
@="C:\WINDOWS\system32\gqagksr.dll"



»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

maani.bhai
2006-10-04, 02:09
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:59:40 PM 01/10/2006

+ Scan result:



HKU\S-1-5-21-221523587-2503773589-2712078438-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{479FD0CF-5BE9-4C63-8CDA-B6D371C67BD5} -> Adware.Generic : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.78:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.79:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.80:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.81:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.82:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.83:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.84:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.58:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.59:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.7search : Cleaned.
:mozilla.30:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.32:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.336:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.34:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.35:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.219:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned.
:mozilla.51:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.157:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.158:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.159:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.160:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.297:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Centrport : Cleaned.
:mozilla.168:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.169:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.22:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.268:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.242:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.243:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.244:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.245:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.151:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.152:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.153:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.154:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.155:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.156:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.150:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.100:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.206:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.222:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.250:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.272:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.98:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.99:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.282:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.54:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.117:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.118:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.119:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.198:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.53:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.36:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.323:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.324:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.48:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.55:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.180:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.181:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.182:C:\Documents and Settings\muneeb\Application Data\Mozilla\Firefox\Profiles\xynbgcgc.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

LonnyRJones
2006-10-09, 08:51
Hello maani.bhai

If you havent already go ahead and run smithfraudfix option 2 while the pc is in safe mode, then ewido as described here
http://forums.spybot.info/showthread.php?t=4015

maani.bhai
2006-10-09, 16:21
what do I do now, I need help figuring out which files from my logs are bad???

LonnyRJones
2006-10-10, 01:25
smithfraudfix will determine which files are bad and delete them when you run it in safe mode using option 2

Or have you ran option two already ?

maani.bhai
2006-10-10, 02:22
Yes, I have followed, and completed, the option two directions and have ran smitfraudfix in safe mode. the report that it gave me after the scan is posted at the top along with the hijack this, and ewido log. With reference to the posted logs, are there any files that i need to delete from my computer? sorry about the confusion, I appreciate your help!

LonnyRJones
2006-10-10, 02:46
The smithfraudfix log above wasnt ran in safe mode and it was using option 1

tashi
2006-10-16, 22:03
maani.bhai how is it going?

tashi
2006-10-22, 03:47
This topic has been archived.

If you need it re-opened please send me a private message (pm) and provide a link to the thread.
Applies only to the original topic starter.