Results 1 to 2 of 2

Thread: Malicious Cookie keeps coming back!

  1. #1
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default Malicious Cookie keeps coming back!

    I ran Spybot S&D yesterday it removed 2 malicious cookies one is back again after reboot: Win32 PornPopUp adbrite(dot)com 4 instances showing up as being in my Chrome browser.
    Note I could not run ERUNT as it said it was for Vista & Below. What registry backup tool is safe to use for windows 7?
    _________________________________________________________________

    DDS (Ver_10-03-17.01) - NTFSX64
    Run by X at 21:15:51.76 on Wed 06/09/2010
    Internet Explorer: 8.0.7600.16385
    Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.5887.4102 [GMT -7:00]


    ============== Running Processes ===============

    C:\Windows\system32\wininit.exe
    C:\Windows\system32\lsm.exe
    C:\Windows\system32\svchost.exe -k DcomLaunch
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k RPCSS
    C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
    C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
    C:\Windows\system32\svchost.exe -k netsvcs
    C:\Windows\system32\svchost.exe -k LocalService
    C:\Windows\system32\svchost.exe -k NetworkService
    C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
    C:\Windows\system32\nvvsvc.exe
    C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
    c:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\system32\taskhost.exe
    C:\Windows\Explorer.EXE
    C:\Windows\system32\WUDFHost.exe
    C:\Windows\system32\taskeng.exe
    C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
    C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
    C:\Windows\System32\StikyNot.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe
    C:\Windows\system32\SearchIndexer.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
    C:\Program Files\Alwil Software\Avast5\AvastUI.exe
    C:\Program Files\Windows Media Player\wmpnetwk.exe
    C:\Windows\system32\taskeng.exe
    C:\Windows\System32\svchost.exe -k secsvcs
    C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
    C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe
    C:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe
    C:\Windows\System32\spoolsv.exe
    c:\Program Files (x86)\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\splwow64.exe
    C:\Program Files (x86)\Spybot - Search & Destroy\SpybotSD.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
    C:\Windows\system32\SearchProtocolHost.exe
    C:\Windows\system32\SearchFilterHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Windows\system32\DllHost.exe
    C:\Users\X\Downloads\dds.scr
    C:\Windows\system32\conhost.exe
    C:\Windows\system32\wbem\wmiprvse.exe

    ============== Pseudo HJT Report ===============

    mLocal Page = c:\windows\syswow64\blank.htm
    uURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
    uURLSearchHooks: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
    mURLSearchHooks: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
    mURLSearchHooks: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
    mWinlogon: Userinit=userinit.exe
    BHO: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
    BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files (x86)\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
    BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~2\spybot~1\SDHelper.dll
    BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    BHO: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
    BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files (x86)\common files\microsoft shared\windows live\WindowsLiveLogin.dll
    BHO: TBSB05974 Class: {fcbccb87-9224-4b8d-b117-f56d924beb18} - c:\program files (x86)\search toolbar\tbcore3.dll
    TB: Search Toolbar: {0c8413c1-fad1-446c-8584-be50576f863e} - c:\program files (x86)\search toolbar\tbcore3.dll
    TB: Zynga Toolbar: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - c:\program files (x86)\zynga\tbZyng.dll
    TB: 4shared.com Toolbar: {09ec805c-cb2e-4d53-b0d3-a75a428b81c7} - c:\program files (x86)\4shared.com\tb4sha.dll
    TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    uRun: [RESTART_STICKY_NOTES] c:\windows\system32\StikyNot.exe
    uRun: [SpybotSD TeaTimer] c:\program files (x86)\spybot - search & destroy\TeaTimer.exe
    mRun: [hpsysdrv] c:\program files (x86)\hewlett-packard\hp odometer\hpsysdrv.exe
    mRun: [<NO NAME>]
    mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
    mRun: [Adobe Reader Speed Launcher] "c:\program files (x86)\adobe\reader 9.0\reader\Reader_sl.exe"
    mRun: [Adobe ARM] "c:\program files (x86)\common files\adobe\arm\1.0\AdobeARM.exe"
    StartupFolder: c:\users\x\appdata\roaming\micros~1\windows\startm~1\programs\startup\digsby.lnk - c:\program files (x86)\digsby\digsby.exe
    mPolicies-explorer: NoActiveDesktop = 1 (0x1)
    mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1)
    mPolicies-explorer: ForceActiveDesktopOn = 0 (0x0)
    mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5)
    mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
    mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
    IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files (x86)\windows live\writer\WriterBrowserExtension.dll
    IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~2\spybot~1\SDHelper.dll
    TB-X64: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File
    mRun-x64: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
    mRun-x64: [PC-Doctor for Windows localizer] c:\program files\pc-doctor for windows\localizer.exe
    Hosts: 127.0.0.1 www.spywareinfo.com

    ================= FIREFOX ===================

    FF - ProfilePath - c:\users\x\appdata\roaming\mozilla\firefox\profiles\f0969juz.default\
    FF - plugin: c:\program files (x86)\google\update\1.2.183.23\npGoogleOneClick8.dll
    FF - plugin: c:\program files (x86)\windows live\photo gallery\NPWLPG.dll
    FF - plugin: c:\users\default\appdata\local\huludesktop\instances\0.9.9.1\nphdplg.dll

    ---- FIREFOX POLICIES ----
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
    c:\program files (x86)\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
    c:\program files (x86)\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
    c:\program files (x86)\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

    ============= SERVICES / DRIVERS ===============

    R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-5-13 121936]
    R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-5-13 22096]
    R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-5-13 63568]
    R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
    R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
    R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-5-13 40384]
    S3 PCDSRVC{F36B3A4C-F95654BD-06000000}_0;PCDSRVC{F36B3A4C-F95654BD-06000000}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\pc-doctor for windows\pcdsrvc_x64.pkms [2009-9-16 23536]
    S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-5-14 1255736]
    S4 gupdate;Google Update Service (gupdate);c:\program files (x86)\google\update\GoogleUpdate.exe [2010-5-13 133104]

    =============== Created Last 30 ================

    2010-06-10 04:04:04 0 dc----w- c:\program files (x86)\Trend Micro
    2010-06-03 04:00:21 0 dc----w- c:\users\x\appdata\roaming\{8126D2ED-1984-4573-9D57-97637E10C716}
    2010-06-03 04:00:07 0 dc----w- C:\swsetup
    2010-05-28 16:21:04 0 dc----w- c:\program files (x86)\4shared.com
    2010-05-28 16:21:02 0 dc----w- c:\users\x\appdata\roaming\4shared Desktop
    2010-05-28 16:21:02 0 dc----w- c:\program files (x86)\4shared Desktop
    2010-05-27 07:01:36 0 dc----w- c:\programdata\Recovery
    2010-05-21 01:12:41 14336 -c--a-w- c:\windows\system32\drivers\sffp_sd.sys
    2010-05-19 01:46:00 0 dc----w- c:\program files (x86)\Conduit
    2010-05-19 01:45:59 0 dc----w- c:\program files (x86)\Zynga
    2010-05-18 17:54:59 0 dc----w- c:\users\x\appdata\roaming\Digsby
    2010-05-18 17:54:59 0 dc----w- c:\programdata\Digsby
    2010-05-18 16:01:21 0 dc----w- c:\programdata\Adobe
    2010-05-18 14:37:23 0 dc----w- c:\programdata\Chit Chat For FaceBook
    2010-05-18 10:51:16 118784 -c--a-w- c:\windows\syswow64\MSSTDFMT.DLL
    2010-05-18 10:51:16 1071088 -c--a-w- c:\windows\syswow64\MSCOMCTL.OCX
    2010-05-18 10:04:36 0 dc----w- c:\users\x\appdata\roaming\Trillian
    2010-05-18 08:02:17 65536 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TM.blf
    2010-05-18 08:02:17 524288 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TMContainer00000000000000000002.regtrans-ms
    2010-05-18 08:02:17 524288 --sha-w- c:\users\x\ntuser.dat{29d76893-6251-11df-b703-001fc6f9a588}.TMContainer00000000000000000001.regtrans-ms
    2010-05-18 05:13:42 0 dc----w- c:\program files (x86)\SpywareBlaster
    2010-05-18 05:11:41 0 dc----w- c:\programdata\Spybot - Search & Destroy
    2010-05-18 05:11:40 0 dc----w- c:\program files (x86)\Spybot - Search & Destroy
    2010-05-18 05:06:24 0 dc----w- c:\users\x\appdata\roaming\Free Download Manager
    2010-05-18 05:06:22 0 dc----w- c:\program files (x86)\Free Download Manager
    2010-05-16 02:02:19 0 dc----w- c:\programdata\{DA06AA03-DF24-4ECE-939E-1B0939235C66}
    2010-05-16 02:01:47 0 dc----w- c:\users\x\appdata\roaming\hpqLog
    2010-05-16 02:01:10 0 dc----w- c:\users\x\appdata\roaming\WinBatch
    2010-05-16 01:53:49 0 dc----w- c:\users\x\appdata\roaming\HP Support Assistant
    2010-05-16 01:53:48 0 dc----w- c:\users\x\appdata\roaming\HpUpdate
    2010-05-14 17:26:50 0 dc----w- c:\windows\syswow64\Wat
    2010-05-14 17:26:50 0 dc----w- c:\windows\system32\Wat
    2010-05-14 17:12:06 0 dc----w- c:\program files (x86)\MSXML 4.0
    2010-05-14 17:08:52 91648 ----a-w- c:\windows\syswow64\avifil32.dll
    2010-05-14 17:07:41 716800 ----a-w- c:\windows\syswow64\jscript.dll
    2010-05-14 17:06:43 464896 ----a-w- c:\windows\system32\drivers\srv.sys
    2010-05-14 17:06:43 162304 ----a-w- c:\windows\system32\drivers\srvnet.sys
    2010-05-14 15:50:07 0 dc----w- c:\windows\pss
    2010-05-14 04:37:13 63568 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2010-05-14 04:37:12 0 -c--a-w- c:\windows\syswow64\config.nt
    2010-05-14 04:36:37 38848 -c--a-w- c:\windows\syswow64\avastSS.scr
    2010-05-14 04:36:37 165032 -c--a-w- c:\windows\syswow64\aswBoot.exe
    2010-05-14 04:36:34 0 dc----w- c:\programdata\Alwil Software
    2010-05-14 04:36:34 0 dc----w- c:\program files\Alwil Software
    2010-05-14 02:20:49 270208 -c----w- c:\windows\system32\MpSigStub.exe
    2010-05-14 02:15:02 0 dc----w- c:\users\x\appdata\roaming\PictureMover

    ==================== Find3M ====================

    2010-05-21 01:12:38 7680 ----a-w- c:\windows\syswow64\instnm.exe
    2010-05-21 01:12:38 5120 ----a-w- c:\windows\syswow64\wow32.dll
    2010-05-21 01:12:38 25600 ----a-w- c:\windows\syswow64\setup16.exe
    2010-05-21 01:12:38 243200 ----a-w- c:\windows\system32\wow64.dll
    2010-05-21 01:12:38 2048 ----a-w- c:\windows\syswow64\user.exe
    2010-05-21 01:12:38 14336 ----a-w- c:\windows\syswow64\ntvdm64.dll
    2010-05-21 01:12:34 223448 ----a-w- c:\windows\system32\drivers\fvevol.sys
    2010-05-21 01:11:35 960512 ----a-w- c:\windows\system32\CPFilters.dll
    2010-05-21 01:11:35 641536 ----a-w- c:\windows\syswow64\CPFilters.dll
    2010-05-21 01:11:35 613888 ----a-w- c:\windows\system32\psisdecd.dll
    2010-05-21 01:11:35 552960 ----a-w- c:\windows\system32\msdri.dll
    2010-05-21 01:11:35 465408 ----a-w- c:\windows\syswow64\psisdecd.dll
    2010-05-14 17:14:29 220672 ----a-w- c:\windows\system32\wintrust.dll
    2010-05-14 17:14:29 172032 ----a-w- c:\windows\syswow64\wintrust.dll
    2010-05-14 17:14:15 139264 ----a-w- c:\windows\system32\cabview.dll
    2010-05-14 17:14:15 132608 ----a-w- c:\windows\syswow64\cabview.dll
    2010-05-14 17:14:00 612352 ----a-w- c:\windows\system32\vbscript.dll
    2010-05-14 17:14:00 427520 ----a-w- c:\windows\syswow64\vbscript.dll
    2010-05-14 17:13:46 976896 ----a-w- c:\windows\system32\inetcomm.dll
    2010-05-14 17:13:46 740864 ----a-w- c:\windows\syswow64\inetcomm.dll
    2010-05-14 17:13:27 70656 ----a-w- c:\windows\syswow64\fontsub.dll
    2010-05-14 17:13:27 148480 ----a-w- c:\windows\system32\t2embed.dll

  2. #2
    Junior Member
    Join Date
    Jun 2010
    Posts
    4

    Default this problem is resolved!

    New problem is pending here!
    http://forums.spybot.info/showthread...747#post374747

    could you please close this thread?

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •