UNSOLVED

Anubis132

updated

20 years ago

A

Anubis132

23 Posts

0

1764

September 7th, 2006 00:00

Half-squashed infection--Need help with sysprotect

I got a big infection today, shame on me. This included Spyware Quake, Smitfraud-C, safety toolbar, and sysprotect. I squashed most of it manually or with Spybot, but Sysprotect remains elusive. Here's my log--it's shorter than I expected it to be. Looks like there's some leftover stuff, too.
 
Edit: New symptom: Browser rerouts to or a popup appears with the URL www.worlddatinghere.com.
 
Logfile of HijackThis v1.99.1
Scan saved at 6:07:51 PM, on 9/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTSvcCDA.EXE
C:\WINDOWS\system32\hpnra.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Rick\Desktop\HijackThis.exe
O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
 

Message Edited by Anubis132 on 09-06-200609:01 PM

  • bamajim

    10376 Posts

    378

    0

    Posted September 7th, 2006 01:00

    Anubis132

    Thanks for the log, hhowever you have turned off some programs in msconfig.

    You need to go back into msconfig and turn them all back on. We need to have a full picture of what is going on with your pc.

    Once that is done->>Re run Hijackthis and post a fresh log please

    thanks bamajim Graduate of Malware Removal University

    Message Edited by bamajim on 09-06-200609:15 PM

  • Anubis132

    23 Posts

    378

    0

    Posted September 7th, 2006 03:00

    New logfile. The only things I had turned off were Rundll P17, NMBgMonitor, and 827a6046.exe. The 827a file I deleted myself, and I recognized P17 as some spyware-related thing I've seen before, if memory serves.
     
    Logfile of HijackThis v1.99.1
    Scan saved at 9:29:50 PM, on 9/6/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\hpnra.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Documents and Settings\Rick\Desktop\HijackThis.exe
    O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
    O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [827a6046.exe] C:\WINDOWS\system32\827a6046.exe
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
     
  • bamajim

    10376 Posts

    378

    0

    Posted September 7th, 2006 12:00

    Anubis132

    Please go here

    And Download SmitFraudFix by S!ri

    • Rt click smitfraudfix.exe ->>Extract all the archive content to your desktop
      Open the Smitfraud folder 
      Double-click smitfraudfix.cmd
      Select 1 and hit Enter to create a report of the infected files. The report can be found at the root of the system drive, usually at C:\rapport.txt
      Open that file, Ctrl+A to copy, and post a copy of that log as a reply to this thread
    • Do Not run option 2 until instructed to do so


      bamajim    Graduate of Malware Removal University



     

  • Anubis132

    23 Posts

    378

    0

    Posted September 7th, 2006 13:00

    Quoth smitfraudfix:
     
    SmitFraudFix v2.83
    Scan done at  7:54:54.48, Thu 09/07/2006
    Run from C:\Documents and Settings\Rick\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in normal mode
    »»»»»»»»»»»»»»»»»»»»»»»» C:\

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web

    »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
    C:\WINDOWS\system32\issearch.exe FOUND !
    C:\WINDOWS\system32\ot.ico FOUND !
    »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Rick\Application Data
    C:\Documents and Settings\Rick\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk FOUND !
    »»»»»»»»»»»»»»»»»»»»»»»» Start Menu
    C:\DOCUME~1\Rick\STARTM~1\SpyQuake2.com 2.3.lnk FOUND !
    C:\DOCUME~1\Rick\STARTM~1\Programs\SpyQuake2.com FOUND !
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !
    »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Rick\FAVORI~1
    C:\DOCUME~1\Rick\FAVORI~1\Antivirus Test Online.url FOUND !
    »»»»»»»»»»»»»»»»»»»»»»»» Desktop

    »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

    »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys

    »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
     
    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
    "Source"="About:Home"
    "SubscribedURL"="About:Home"
    "FriendlyName"="My Current Home Page"
     
    »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
    !!!Attention, following keys are not inevitably infected!!!
    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"
     
    »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
    !!!Attention, following keys are not inevitably infected!!!
    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
    "AppInit_DLLs"=""
    »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection

    »»»»»»»»»»»»»»»»»»»»»»»» End
  • Anubis132

    23 Posts

    378

    0

    Posted September 7th, 2006 15:00

    Ok. I won't be able to do this until this afternoon, but I'll post the results.
  • bamajim

    10376 Posts

    378

    0

    Posted September 7th, 2006 15:00


    Anubis132

    You may want to print out these instructions for reference

    We need to temporarily disable Spybot SD so it doesn't interfere with our fix

    Disable Spybot S&D "resident tea timer"
    • 1) Run Spybot-S&D
      2) Go to the Mode menu, select " Advanced Mode"
      3) In the left pane, click Tools ->> Resident
      4) Uncheck " Resident TeaTimer" and OK any prompts
      5) Reboot your PC
    Go here and Download Ewido Antimalware 4.0
    ( 30 day free trial version) Save it to Your Desktop
     
    Double Click Ewido-setup
    (It will create its own folder)
    Once the program starts You will be at the Status menu
    • Under "Your computers Security"
      Click change status on Resident shield to inactive
      Click Update now (next to last update)
      After the update loads
      Under Automatic updates Uncheck download and install updates automatically(recommended)
      (you can always select maual updates the next day)
    At the top toolbar Click Scanner Then the settings tab
    • Under How to act? Set default action for detected malwareTo Quarantine
      Under how to scan All boxes should be checked
      Under Possibly unwanted software All boxes should be checked
      Under reports Select Automatically generate report after every scan
      Uncheck Only if threats were found
      Under what to scan Scan every file should be highlited
    Exit Ewido (Do not run it yet)

    Next Re Run Hijackthis and place checks beside the following entries
    • O3 - Toolbar: Safety Bar - {052b12f7-86fa-4921-8482-26c42316b522} - C:\Program Files\Safety Bar\SafetyBar.dll (file missing)
      O4 - HKLM\..\Run: [827a6046.exe] C:\WINDOWS\system32\827a6046.exe
      O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)

    Close all other open windows except Hijackthis and Select " Fix checked"

    Next Using Windows Explorer (Rt Click Start ->>Explore and using the tree of folders on the left)
    Locate and delete the following folder
    • C:\Program Files\Safety Bar
    Locate and delete the following file
    • C:\WINDOWS\system32\827a6046.exe
    Close Windows Explorer

    Reboot your PC into Safe Mode
    This can be done by
    • Restart your PC, and after it starts, but before you see the Windows Splash screen
      Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
      Use your arrow keys and select Safe Mode and then Enter
    Next Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
    • Select option #2 - Clean by typing 2 and press Enter.
      Wait for the tool to complete and disk cleanup to finish.
      You will be prompted : " Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
      The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question " Replace infected file ?" by typing Y and hit Enter.
    A reboot may be needed to finish the cleaning process, if your computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

    The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.

    Next Run Ewido
    • Click scanner
      Select Complete system scan
    Once the scan finishes
    • Select Apply all actions (The items found will be quarantined)
      Click save report as (Another window will open)
      Save it to your desktop
      (By default It will be saved in the Ewido folder as)
      C:\Program Files\ewido anti-spyware 4.0\Reports
    Exit Ewido
     
    Reboot your PC in Normal Mode
    • Double click the report-scan txt. you saved to your desktop
      It will open in Notepad
      Copy and paste that report as a reply to this thread
    Do not run any other options untill instructed to do so

    Finally Re run Hijackthis and post a fresh hijackthis log

    Your reply should include
    • your rapport.txt from Smitfraud
      your report_scan.txt from Ewido
      a fresh Hijackthis log
    thanks bamajim  Graduate of Malware Removal University
     


  • bamajim

    10376 Posts

    268

    0

    Posted September 7th, 2006 23:00

    Anubis132

    Still think there is a thing or 2 in hiding. We will do this in 2 posts

    First Locate the Hijackthis.exe in your folder ->>Rt click Hijackthis.exe and Select rename. Change the name to H.exe

    Re run H.exe (formerly Hijackthis.exe) and post a fresh Hijackthis log

    thanks bamajim      Graduate of Malware Removal University

  • Anubis132

    23 Posts

    378

    0

    Posted September 7th, 2006 23:00

    Here it is:

     

    SmitFraudFix v2.83

    Scan done at 14:35:12.17, Thu 09/07/2006
    Run from C:\Documents and Settings\Rick\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    Fix ran in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
    "incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"


    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\system32\issearch.exe Deleted
    C:\WINDOWS\system32\ot.ico Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
     
    Registry Cleaning done.
     
    »»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End

     

    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

     + Created at: 5:00:15 PM 9/7/2006

     + Scan result: 

    C:\Documents and Settings\Rick\Local Settings\Temp\Cliprex_WhenUSave_InstallerInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    E:\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Application Data\Microsoft\Internet Explorer\Quick Launch\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\SpyQuake2.com 2.3 Website.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Start Menu\Programs\SpyQuake2.com\Uninstall SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Start Menu\SpyQuake2.com 2.3.lnk -> Adware.SpywareQuake : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Local Settings\Temporary Internet Files\Content.IE5\K9ER4HIR\wlzip32[1].exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc1.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc8.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc12.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc136.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc139.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc151.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc19.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc64.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc26.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc30.txt -> TrackingCookie.Admarketplace : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc33.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc36.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc37.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc45.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc52.txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc218.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc219.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc56.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc58.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc61.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc68.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc82.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc44.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc131.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc95.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc113.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc87.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc88.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc89.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc90.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc132.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc243.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc179.txt -> TrackingCookie.Onestat : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc153.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc71.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc35.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc157.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc181.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc168.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc31.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc180.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc189.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc41.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc190.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc94.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc192.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc193.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rick\Cookies\rick@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc24.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
    C:\RECYCLER\S-1-5-21-1417001333-1500820517-839522115-1004\Dc264.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).


    ::Report end

     

    -----------------HJT-----------------

    Logfile of HijackThis v1.99.1
    Scan saved at 5:03:16 PM, on 9/7/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\CTSvcCDA.EXE
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\userinit.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\MsPMSPSv.exe
    C:\WINDOWS\system32\hpnra.exe
    C:\WINDOWS\system32\Rundll32.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Rick\Desktop\HijackThis.exe

    O4 - HKLM\..\Run: [HP Network Registry Agent] C:\WINDOWS\system32\hpnra.exe
    O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
    O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSvcCDA.EXE
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

     

  • Anubis132

    23 Posts

    378

    0

    Posted September 7th, 2006 23:00

    Still getting popups from Worlddatinghere.com and mysafetrip.com
    Other symptoms gone or not evident
  • bamajim

    10376 Posts

    378

    0

    Posted September 7th, 2006 23:00

    Anubis132

    Well done. Before we proceed can you give me an update on how your PC is running now?

    thanks bamajim    Graduate of Malware Removal University