problems with a few malwares

pimuni

New member
Hello, I have been trying to delete some malware with Spybot, but they keep reappearing. The main problems are SmitFraud and Virtumonde, but I also have several tracking cookies. Several different pages pop up randomly, including the one for WinAntivirusPro2006. I have tried using a few other programs to fix this problem. Ad-aware doesn't find any problems and AVG finds trojan.agent.acl. I used the SmitfraudFix.exe (in safe mode) and did the whole process, so it must have gotten rid of that problem. (Still haven't checked for other activity). I would like some help please.
 
here is the SmitfraudFix.exe log:
-----------

SmitFraudFix v2.144

Scan done at 19:43:53.96, Sat 02/24/2007
Run from C:\Documents and Settings\HP_Administrator\Desktop\downloads\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

-----------------
 
here is my hijackthis log:
---------------

Logfile of HijackThis v1.99.1
Scan saved at 8:01:30 PM, on 2/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [DllRunning] rundll32.exe "C:\WINDOWS\system32\acolgxsn.dll",setvm
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe

-------------
 
Hi pimuni and welcome to the Forums :)

You're infected.

Rename HijackThis.exe to Scanner.exe

At first you need to disable a few realtime protections. These may interfere with our cleaning process.
We'll enable these when you're clean...

Disable Windows Defender's realtime protection.
  • Open Windows Defender
  • Click on "Tools"
  • Click on "General Settings"
  • Scroll down to "Real-time protection options"
  • Uncheck "Turn on Real-time protection (recommended)"
  • Click "Save"
  • Exit the program.
Disable AVG Anti-Spyware guard.
  • Open AVG Anti-Spyware
  • Click Shield
  • Click under "resident shield is"
  • Change it to inactive
  • Close the program
Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis (scanner.exe) log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
 
thanks for the reply

VundoFix Log

VundoFix V6.3.9

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.5

Java version is 1.5.0.6

Java version is 1.5.0.9

Scan started at 3:31:41 PM 2/26/2007

Listing files found while scanning....

C:\WINDOWS\system32\agryakpj.exe
C:\WINDOWS\system32\cbpynnin.exe
C:\WINDOWS\system32\cpshekly.dll
C:\WINDOWS\system32\eocnwupj.ini
C:\WINDOWS\system32\jcmpbbje.exe
C:\WINDOWS\system32\jpuwncoe.dll
C:\WINDOWS\system32\llhsbvbt.exe
C:\WINDOWS\system32\ssttu.dll

Beginning removal...

Attempting to delete C:\WINDOWS\system32\agryakpj.exe
C:\WINDOWS\system32\agryakpj.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\cbpynnin.exe
C:\WINDOWS\system32\cbpynnin.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\eocnwupj.ini
C:\WINDOWS\system32\eocnwupj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jcmpbbje.exe
C:\WINDOWS\system32\jcmpbbje.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\jpuwncoe.dll
C:\WINDOWS\system32\jpuwncoe.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\llhsbvbt.exe
C:\WINDOWS\system32\llhsbvbt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ssttu.dll
C:\WINDOWS\system32\ssttu.dll Has been deleted!

Performing Repairs to the registry.
Done!

----------------------

HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 3:44:07 PM, on 2/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\SOUNDMAN.EXE
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\ALCWZRD.EXE
C:\WINDOWS\ALCMTR.EXE
C:\Program Files\Zune\ZuneLauncher.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O2 - BHO: (no name) - {00EADF9D-1825-2299-5B73-08D3E1EA4736} - C:\WINDOWS\system32\xkybivk.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {230D0EEB-E247-DB25-2352-0BB0F6DC30BA} - C:\WINDOWS\system32\eljswve.dll
O2 - BHO: (no name) - {57229570-FAC3-46DD-9F2E-1D60E37FE3F9} - C:\WINDOWS\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} - C:\WINDOWS\system32\gebcawv.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {841FB5E2-C782-441A-96FC-90C667F2F77C} - C:\WINDOWS\system32\pmkjh.dll (file missing)
O2 - BHO: (no name) - {D16FBE66-0186-5D28-DB49-2E909CD539BC} - C:\WINDOWS\system32\pkv.dll (file missing)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\cpshekly.dll (file missing)
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: gebcawv - C:\WINDOWS\SYSTEM32\gebcawv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winubg32 - winubg32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
 
Hi again :)

Before we'll continue I would like you to do something for me...
I need you too upload few malware files for further inspection.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
Please go here to upload a suspicious file for analysis.
  • Enter your username from this forum
  • Copy and paste the link to this thread
    • Click "Browse" on the 1. field.
      Browse to the following file and click the file with your mouse, press "Open"
      C:\WINDOWS\system32\gebcawv.dll
    • Click "Browse" on the 2. field.
      Browse to the following file and click the file with your mouse, press "Open"
      C:\WINDOWS\system32\xkybivk.dll
    • Click "Browse" on the 3. field.
      Browse to the following file and click the file with your mouse, press "Open"
      C:\WINDOWS\system32\eljswve.dll
  • In the comments, please mention that I asked you to upload this file
  • Click on Send File
Please let me know when you have done this and then we'll get you cleaned :bigthumb:
 
ok, done so

---
Your file (gebcawv.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.

Your file (xkybivk.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.

Your file (eljswve.dll) was successfully submitted. If someone requested you submit this file please let them know that you have submitted the file.

---
 
Hi again, we'll continue :)
Thank you for the upload.

You should print these instructions or save these to a text file. Follow these instructions carefully.

Open AVG Anti-Spyware:
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner by Atribune to your desktop.
Do NOT run yet.

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
==================

We'll run VundoFix again.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once the scan is complete, Right Click inside the listbox (white box) and click add more files
  • Copy&Paste the 2 entries below into the top 2 boxes
  • C:\WINDOWS\system32\gebcawv.dll
  • C:\WINDOWS\system32\vwacbeg.*
  • Click Add Files and Click Close Window
  • Click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.

O2 - BHO: (no name) - {00EADF9D-1825-2299-5B73-08D3E1EA4736} - C:\WINDOWS\system32\xkybivk.dll
O2 - BHO: (no name) - {230D0EEB-E247-DB25-2352-0BB0F6DC30BA} - C:\WINDOWS\system32\eljswve.dll
O2 - BHO: (no name) - {57229570-FAC3-46DD-9F2E-1D60E37FE3F9} - C:\WINDOWS\system32\ssttu.dll (file missing)
O2 - BHO: (no name) - {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} - C:\WINDOWS\system32\gebcawv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {841FB5E2-C782-441A-96FC-90C667F2F77C} - C:\WINDOWS\system32\pmkjh.dll (file missing)
O2 - BHO: (no name) - {D16FBE66-0186-5D28-DB49-2E909CD539BC} - C:\WINDOWS\system32\pkv.dll (file missing)
O2 - BHO: (no name) - {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} - C:\WINDOWS\system32\cpshekly.dll (file missing)
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [pbdygom.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll",krekaab
O4 - HKLM\..\Run: [{6CF45265-0BB9-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [{6CF45265-0BB8-1033-0216-050823200001}] "C:\Program Files\Common Files\{6CF45265-0BB8-1033-0216-050823200001}\Update.exe" mc-110-12-0000272
O4 - HKLM\..\Run: [syswin] C:\WINDOWS\system32\v6.exe
O4 - HKLM\..\Run: [skupmcg.dll] C:\WINDOWS\system32\rundll32.exe "C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll",tskdzsb
O16 - DPF: {DBA230D1-8467-4e69-987E-5FAE815A3B45} -
O20 - Winlogon Notify: gebcawv - C:\WINDOWS\SYSTEM32\gebcawv.dll
O20 - Winlogon Notify: winubg32 - winubg32.dll (file missing)

You also have a Norton leftover running, we'll remove it:
  • Start
  • Run
  • Type services.msc to the field and press enter.
  • A window opens, scroll down to Symantec Network Drivers Service (SNDSrvc)
  • Rightclick it and choose Stop
  • Then choose Properties
  • Set Startup to Disabled
  • Click Apply and OK.
Then, open HijackThis.
  • Open the Misc Tools section
  • Delete an NT service
  • Copy the following line to the box and press OK; SNDSrvc
  • Answer Yes
  • Close HIjackThis

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.

Go to the My Computer and delete the following files (if present):
C:\WINDOWS\system32\xkybivk.dll
C:\WINDOWS\system32\eljswve.dll
C:\WINDOWS\system32\v6.exe
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\pbdygom.dll
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\skupmcg.dll

Go to the My Computer and delete the following folders (if present):
C:\Program Files\Common Files\{6CF45265-0BB9-1033-0216-050823200001}

Use the Windows search
  • Start
  • Search
  • All files and folders
  • More advanced options
Checkmark these options:
  • "Search system folders"
  • "Search hidden files and folders"
  • "Search subfolders"
  • Search for this and delete if found: winubg32.dll
Run ATF Cleaner
  • Under Main choose: Select All
    Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
    Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      scanavgjk2.jpg
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
- contents of C:\vundofix.txt
 
here you go:

AVG Log

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 7:29:53 PM 2/28/2007

+ Scan result:



C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP360\A0100130.dll -> Downloader.Busky : Cleaned with backup (quarantined).
:mozilla.258:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-1.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.368:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.369:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.466:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.467:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.468:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.682:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Real : Cleaned.
:mozilla.124:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.127:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.128:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.129:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.130:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.131:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.132:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.133:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.134:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-3.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.162:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.163:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.18:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-1.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.232:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-2.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.412:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.413:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.414:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.415:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.416:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.417:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.418:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.419:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.420:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.421:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.422:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
 
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.423:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.424:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application
Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.425:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.426:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.427:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.428:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.429:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.430:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.431:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.432:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.433:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-10.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-11.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-8.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-9.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-4.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-5.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-6.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\11g9qe4b.default\cookies-7.txt -> TrackingCookie.Revsci : Cleaned.
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP358\A0100049.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP359\A0100118.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP360\A0100133.dll -> Trojan.Agent.acl : Cleaned with backup (quarantined).


::Report end

------------------------
 
HijackThis Log

Logfile of HijackThis v1.99.1
Scan saved at 7:35:43 PM, on 2/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\hphmon06.exe
C:\HP\KBD\KBD.EXE
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
c:\program files\mcafee.com\agent\mcdetect.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\ALCWZRD.EXE
C:\Program Files\Windows Defender\MSASCui.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\HJT\Scanner.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 167.222.8.87:8055
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAudPropShortcut.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AlcWzrd] ALCWZRD.EXE
O4 - HKLM\..\Run: [Zune Launcher] "C:\Program Files\Zune\ZuneLauncher.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WhatPulse] C:\PROGRA~1\WHATPU~1\WHATPU~1.EXE
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Picture Package Menu.lnk = ?
O4 - Global Startup: Picture Package VCD Maker.lnk = ?
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xportar a Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Researcher - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Program Files\Common Files\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131084685812
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

-----------------------

VundoFix Log

VundoFix V6.3.9

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.5

Java version is 1.5.0.6

Java version is 1.5.0.9

Scan started at 4:57:39 PM 2/28/2007

Listing files found while scanning....

C:\WINDOWS\system32\cpshekly.dll
C:\WINDOWS\system32\ivvyixpc.exe
C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\kytguoyr.dll
C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\rjapryhd.exe
C:\WINDOWS\system32\ryougtyk.ini
C:\WINDOWS\system32\sdrhncsj.exe

Beginning removal...

Attempting to delete C:\WINDOWS\system32\gebcawv.dll
C:\WINDOWS\system32\gebcawv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ivvyixpc.exe
C:\WINDOWS\system32\ivvyixpc.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.bak1
C:\WINDOWS\system32\jjkmp.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.bak2
C:\WINDOWS\system32\jjkmp.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\jjkmp.ini
C:\WINDOWS\system32\jjkmp.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\kytguoyr.dll
C:\WINDOWS\system32\kytguoyr.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmkjj.dll
C:\WINDOWS\system32\pmkjj.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\rjapryhd.exe
C:\WINDOWS\system32\rjapryhd.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\ryougtyk.ini
C:\WINDOWS\system32\ryougtyk.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\sdrhncsj.exe
C:\WINDOWS\system32\sdrhncsj.exe Has been deleted!

Performing Repairs to the registry.
Done!
 
oh and also, I coudn't delete that Norton process, because the system wouldn't let me delete anything from symantec.
 
Hi again, it is looking clean now :)
How is the computer running?

The Norton leftover seems to be gone now.

Now you can clean AVG's Quarantine:
  • Open AVG Anti-Spyware
  • Click Infections
  • Click Quarantine tab
  • Click Select all
  • Click Remove finally
  • Close the program
You can remove the tools we used.

Then you should update your Java to the latest version (6.0)
  • [*]Start
    [*]Control Panel
    [*]Add/Remove Programs
  • Delete the old Javas, Java 2 Runtime Environment, SE v1.4.1_03
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    J2SE Runtime Environment 5.0 Update 11
  • Download the latest version of Java Runtime Environment (JRE) 6.0.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement."
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Install it
Now you can make your hidden files hidden again.
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Check "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.

=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:
  • Clear your system restore
    This will clear the system restore folders from possible malware that was left behind during the cleaning process.
  • Use ATF Cleaner
    Download and install ATF Cleaner. Clean your temporary files & folders with it regularly.
  • Use Ad-Aware
    Download and install Ad-Aware. Update it and scan your computer regularly with it.
  • Use AVG Anti-Spyware
    Update it and scan your computer regularly with it.
  • Use Spybot S&D
    Download and install Spybot S&D. Update it and scan your computer regularly with it.
  • Install SpywareBlaster
    SpywareBlaster will prevent spyware from being installed.
  • Install MVPS Hosts file
    This prevents your computer from connecting to harmful sites.
  • Use Firefox browser
    Firefox is faster, safer and better browser than Internet Explorer.
  • Keep your systen up-to-date
    Visit Windows Update regularly.
  • Keep your antivirus and firewall up-to-date
    Scan your computer regularly with your antivirus.
  • Read this article by TonyKlein
    So how did I get infected in the first place?
  • Stand Up and Be Counted !
    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Stay clean and be safe :bigthumb:
 
thank you so much for all the help! my computer is running a bit faster and is not taking as long as it used to during startup. :eek:
 
That's great news and you're very welcome :D:

As the problem appears to be resolved this topic has been archived.

If you need it re-opened please send a private message (pm) to a forum staff member and provide a link to the thread; this applies only to the original topic starter.

Glad we could help :2thumb:
 
Back
Top