PDA

View Full Version : problem with cmdservice



bboyzen
2006-11-15, 22:37
i apologize if i dont post this the way it is supposed to be. im just tryin to get the cmdservice off my wifes pc. shes buggin me to get this off.

here is my HJT log file:

Logfile of HijackThis v1.99.1
Scan saved at 3:05:16 PM, on 11/15/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Common Files\{FC494D1E-0573-1033-0613-020430200001}\Update.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\AIM\aim.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://login.yahoo.com/config/login_verify2?&.src=ym
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [My Web Search Community Tools] "C:\Program Files\MyWebSearch\bar\2.bin\m3IMPipe.exe"
O4 - HKCU\..\Run: [rofr] C:\PROGRA~1\COMMON~1\rofr\rofrm.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm035YYUS
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com/uploader/SlideImageUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1163557597953
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Zango/ie/bridge-c18.cab?2de704c7de34659d1426bdbf7305713b71f63c21a9362cd448d0394fa7e25770eb7c2f805dd491215862bf84e3cc4da159cef9c612b7dca9fb551573457330:22b32e0c79951ba72dbf4c44a0363a5c
O18 - Protocol: bw+0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {C3DC3604-5B73-4E0E-BF51-7D3B407DA12B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\guard.tmp (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

bboyzen
2006-11-15, 22:48
Incident Status Location
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Guest\Cookies\guest@ad.yieldmanager[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Guest\Cookies\guest@adrevolver[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Guest\Cookies\guest@advertising[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Guest\Cookies\guest@apmebf[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Guest\Cookies\guest@as-us.falkag[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Guest\Cookies\guest@bluestreak[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Guest\Cookies\guest@casalemedia[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Guest\Cookies\guest@fastclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Guest\Cookies\guest@qksrv[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Guest\Cookies\guest@realmedia[2].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Guest\Cookies\guest@server.iad.liveperson[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Guest\Cookies\guest@stats1.reliablestats[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Guest\Cookies\guest@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[2].txt
Spyware:Cookie/Versiontracker Not disinfected C:\Documents and Settings\Guest\Cookies\guest@versiontracker[1].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Guest\Cookies\guest@www.myaffiliateprogram[1].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Guest\Cookies\guest@zedo[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@ad.yieldmanager[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@adrevolver[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@advertising[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@apmebf[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@atwola[1].txt

bboyzen
2006-11-15, 22:49
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@casalemedia[2].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@cs.sexcounter[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@fastclick[2].txt
Spyware:Cookie/Malwarewipe Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@malwarewipe[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@overture[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@realmedia[1].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@stats1.reliablestats[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@trafficmp[1].txt
Spyware:Cookie/Winantivirus Not disinfected C:\Documents and Settings\Holloway\Cookies\holloway@winantivirus[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Holloway\Desktop\SmitfraudFix\Process.exe
Possible Virus. Not disinfected C:\Documents and Settings\Holloway\Desktop\SmitfraudFix\swsc.exe
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@ad.yieldmanager[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@adrevolver[2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@adrevolver[3].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@advertising[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@atdmt[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@belnk[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@casalemedia[2].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@fastclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@mediaplex[1].txt
Spyware:Cookie/Mysearch Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@mysearch[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@realmedia[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@serving-sys[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Holloway\Local Settings\Temp\Cookies\holloway@tribalfusion[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\LocalService\Cookies\system@2o7[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\LocalService\Cookies\system@ads.pointroll[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\LocalService\Cookies\system@atdmt[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\LocalService\Cookies\system@atwola[1].txt
Spyware:Cookie/Enhance Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.enhance[2].txt
Spyware:Cookie/GoClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@c.goclick[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@doubleclick[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\LocalService\Cookies\system@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@fastclick[2].txt
Spyware:Cookie/Findwhat Not disinfected C:\Documents and Settings\LocalService\Cookies\system@findwhat[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\LocalService\Cookies\system@hitbox[1].txt
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\LocalService\Cookies\system@linksynergy[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\LocalService\Cookies\system@media.fastclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\LocalService\Cookies\system@mediaplex[1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\LocalService\Cookies\system@statcounter[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\LocalService\Cookies\system@stats.drivecleaner[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\LocalService\Cookies\system@www.drivecleaner[2].txt

bboyzen
2006-11-15, 22:51
Adware:Adware/Maxifiles Not disinfected C:\Program Files\Common Files\{FC494D1E-0573-1033-0613-020430200001}\services.dll
Spyware:Cookie/Versiontracker Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23B.tmp
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23C.tmp
Spyware:Cookie/2o7 Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24.tmp
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25.tmp
Spyware:Cookie/Advertising Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq26.tmp
Spyware:Cookie/Atlas DMT Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq27.tmp
Spyware:Cookie/Casalemedia Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28.tmp
Spyware:Cookie/Clickbank Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29.tmp
Spyware:Cookie/Com.com Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2B.tmp
Spyware:Cookie/FastClick Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2D.tmp
Spyware:Cookie/Mediaplex Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp
Spyware:Cookie/QuestionMarket Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2F.tmp
Spyware:Cookie/YieldManager Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3.tmp
Spyware:Cookie/SexList Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq30.tmp
Spyware:Cookie/Tribalfusion Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq31.tmp
Spyware:Cookie/Doubleclick Not disinfected C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5.tmp
Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
Adware:Adware/DeluxeComunications Not disinfected C:\WINDOWS\system32\dxclib303562752(2).dll
Adware:Adware/Maxifiles Not disinfected C:\WINDOWS\system32\install.exe
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\kmdusl.dll
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\nvmsmgr.dll
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\o4lu0e39eh.dll
Adware:Adware/Look2Me Not disinfected C:\WINDOWS\system32\wicsvc.dll
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\allure@ad.yieldmanager[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\allure@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\allure@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\WINDOWS\Temp\Cookies\allure@ads.addynamix[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\WINDOWS\Temp\Cookies\allure@ads.pointroll[2].txt
Spyware:Cookie/Advertising Not disinfected C:\WINDOWS\Temp\Cookies\allure@advertising[1].txt
Spyware:Cookie/Apmebf Not disinfected C:\WINDOWS\Temp\Cookies\allure@apmebf[1].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\Temp\Cookies\allure@as-us.falkag[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\WINDOWS\Temp\Cookies\allure@atdmt[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\WINDOWS\Temp\Cookies\allure@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\allure@drivecleaner[1].txt
Spyware:Cookie/FastClick Not disinfected C:\WINDOWS\Temp\Cookies\allure@fastclick[1].txt
Spyware:Cookie/Findwhat Not disinfected C:\WINDOWS\Temp\Cookies\allure@findwhat[1].txt
Spyware:Cookie/FortuneCity Not disinfected C:\WINDOWS\Temp\Cookies\allure@fortunecity[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\WINDOWS\Temp\Cookies\allure@mediaplex[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\WINDOWS\Temp\Cookies\allure@qksrv[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\WINDOWS\Temp\Cookies\allure@realmedia[1].txt
Spyware:Cookie/Searchportal Not disinfected C:\WINDOWS\Temp\Cookies\allure@searchportal.information[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\WINDOWS\Temp\Cookies\allure@server.iad.liveperson[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\allure@stats.drivecleaner[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\WINDOWS\Temp\Cookies\allure@stats1.reliablestats[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\WINDOWS\Temp\Cookies\allure@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\WINDOWS\Temp\Cookies\allure@tribalfusion[2].txt

bboyzen
2006-11-15, 22:53
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\allure@www.drivecleaner[2].txt
Spyware:Cookie/myaffiliateprogram Not disinfected C:\WINDOWS\Temp\Cookies\allure@www.myaffiliateprogram[1].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\Temp\Cookies\allure@zedo[2].txt
Spyware:Cookie/2o7 Not disinfected C:\WINDOWS\Temp\Cookies\holloway@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\WINDOWS\Temp\Cookies\holloway@ad.yieldmanager[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\holloway@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\WINDOWS\Temp\Cookies\holloway@adrevolver[2].txt
Spyware:Cookie/Advertising Not disinfected C:\WINDOWS\Temp\Cookies\holloway@advertising[2].txt
Spyware:Cookie/Apmebf Not disinfected C:\WINDOWS\Temp\Cookies\holloway@apmebf[2].txt
Spyware:Cookie/Falkag Not disinfected C:\WINDOWS\Temp\Cookies\holloway@as-us.falkag[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\WINDOWS\Temp\Cookies\holloway@atdmt[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\WINDOWS\Temp\Cookies\holloway@doubleclick[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\holloway@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\WINDOWS\Temp\Cookies\holloway@fastclick[1].txt
Spyware:Cookie/Mediaplex Not disinfected C:\WINDOWS\Temp\Cookies\holloway@mediaplex[1].txt
Spyware:Cookie/QkSrv Not disinfected C:\WINDOWS\Temp\Cookies\holloway@qksrv[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\WINDOWS\Temp\Cookies\holloway@searchportal.information[1].txt
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\WINDOWS\Temp\Cookies\holloway@server.iad.liveperson[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\holloway@stats.drivecleaner[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\WINDOWS\Temp\Cookies\holloway@stats1.reliablestats[2].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\WINDOWS\Temp\Cookies\holloway@trafficmp[2].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\WINDOWS\Temp\Cookies\holloway@www.drivecleaner[2].txt
Spyware:Cookie/Zedo Not disinfected C:\WINDOWS\Temp\Cookies\holloway@zedo[1].txt

Mr_JAk3
2006-11-20, 19:10
Hi bboyzen and welcome to Safer Networking Forums :)

You got some infections there...

1. Download this file - combofix.exe (http://download.bleepingcomputer.com/sUBs/combofix.exe)
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

tashi
2006-11-27, 19:38
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a private message (pm) and provide a link to the thread.

Applies only to the original topic starter.