Unsolved

This post is more than 5 years old

589

February 25th, 2008 17:00

Anything Wrong with this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:45:49 PM, on 2/25/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Lexmark 7100 Series\ezprint.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft SQL Server\MSSQL$APHELION\Binn\sqlservr.exe
C:\WINDOWS\system32\lxbxcoms.exe
C:\Program Files\Intuit\QuickBooks 2008\qbw32.exe
C:\Program Files\Common Files\Intuit\QuickBooks\axlbridge.exe
C:\PROGRA~1\Intuit\QUICKB~2\QBDBMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1ACFAC1D-32DD-1171-A87E-1E943A9D88C7} - C:\WINDOWS\System32\vtuu.dll (file missing)
O2 - BHO: (no name) - {598F4775-6FB6-477B-9842-E0426824E077} - C:\DOCUME~1\Gagne\LOCALS~1\Temp\~DP37.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [DrefIW] C:\WINDOWS\system32\SysDref.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [kzifip] C:\WINDOWS\kzifip.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [DrefIW] C:\WINDOWS\system32\SysDref.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: SCP.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.fitnessmanager.com
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&&unknown&unknown&1&4&&unknown&unknown&1&4&&unknown&unknown&1&4&&unknown&unknown&
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191963956093
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/activex/virtools/CacheManager.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{625E7E14-FEEA-4904-B6E7-F6238F69A6FC}: NameServer = 192.168.1.254
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 9776 bytes

4 Apprentice

 • 

20.5K Posts

February 28th, 2008 16:00

Welcome to DCF :)

It looks to me as if you have a worm and remnants of Vundo.

While I am reviewing the rest of your log, you can help me by doing the following:

* Have you have posted this issue on another forum? If so, please provide a link to the topic.

* If you are using any cracked software, please remove it.
Definition of cracked software:
http://en.wikipedia.org/wiki/Software_cracking

* If you are using any P2P (file sharing) programs, please remove them before we clean your computer.
The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state.

* If this computer belongs to someone else, do you have authority to apply the fixes we will use?

* Have you already fixed entries using HijackThis? If so, please restore all the backups and then post another log.

* After we begin working, please print or copy all instructions to Notepad in order to assist you when carrying out procedures.
Please follow all instructions in sequence. Do not, on your own, install/re-install any programs or run any fixes or scanners that you have not been instructed to use because this may cause conflicts with the tools that I am using.

** We may be using some specialized tools during our fix. Certain embedded files that are part of legitimate programs or specialized fix tools such as process.exe, restart.exe, SmiUpdate.exe, reboot.exe, ws2fix.exe, prcviewer.exe and nircmd.exe may at times be detected by some anti-virus/anti-malware scanners as a "RiskTool", "Hacking tool", "Potentially unwanted tool", or even "malware (virus/trojan)" when that is not the case.
Such programs have legitimate uses in contexts where an authorized user or administrator has knowingly installed it. These detections do not necessarily mean the file is malware or a bad program. It means it has the potential for being misused by others. Anti-virus scanners cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert you or even automatically remove them.

* If your replies do not fit in one post while we are handling your issue, please reply to yourself until all text is submitted. It may take several posts.

I look forward to your reply.

March 1st, 2008 00:00

Hello,

I have not posted this issue on any other forum, and I do not have any cracked software or P2P programs installed. I have not fixed any of the HijackThis entries yet, and this computer belongs to me so thats not an issue.
One thing I have tried is (Start > Run > sfc /scannow) but it only runs for about two minutes (no files were replaced) then the computer crashes, and restarts with a winlogon.exe error. So I look forward to your reply to help get this machine running properly.

Thanks

4 Apprentice

 • 

20.5K Posts

March 1st, 2008 01:00



Please disable Spyware Doctor so it does not interfere with our tools:
1. First, disable the OnGuard Tools. This way, when you exit Spyware Doctor, these tools won't stay resident in the background.
2. Click the "Settings" button on the left side.
3. Click the "Startup Settings" link.
4. Uncheck "Run at Windows Startup".
5. Click the "Apply" button.
Exit by a right-click on the "Spyware Doctor" icon in the system tray and choose "Exit".
[To enable Spyware Doctor when you are finished, open the program, Settings>Startup Settings> CHECK "Run at Windows Startup">APPLY
Exit. Reboot.]

To disable PCTools Browser Monitor: If you are running Internet Explorer, click Tools > Manage Add-ons. If PCTools Browser Monitor is on the list, click it & select Disable. You will need to restart your browser after making the change.

Please launch Hijackthis and place a checkmark next to the following:

O2 - BHO: (no name) - {1ACFAC1D-32DD-1171-A87E-1E943A9D88C7} - C:\WINDOWS\System32\vtuu.dll (file missing)
O2 - BHO: (no name) - {598F4775-6FB6-477B-9842-E0426824E077} - C:\DOCUME~1\Gagne\LOCALS~1\Temp\~DP37.dll (file missing)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll (file missing)
O4 - HKLM\..\Run: [DrefIW] C:\WINDOWS\system32\SysDref.exe
O4 - HKLM\..\Run: [kzifip] C:\WINDOWS\kzifip.exe
O4 - HKCU\..\Run: [DrefIW] C:\WINDOWS\system32\SysDref.exe
O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v3/vet_install_popup.pl?1&4&&unknown&unknown&1&4&&unknown&unknown&1&4&&unknown&unknown&1&4&&unknown&unknown&

Close HijackThis and click "Fix Checked".
Close hijackThis.
Reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key.
Use the arrow keys to highlight Safe Mode and press the Enter key.

Configure to show all files/folders:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Uncheck: Hide protected operating system files
Click on Apply.
Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
Be sure the first three boxes are selected:
Search System folders
Search Hidden Files and folders
Search SubFolders


Delete the specified files:
C:\WINDOWS\ kzifip.exe
C:\WINDOWS\system32\ SysDref.exe

Reboot normally,

Rehide files:
Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Check: Hide protected operating system files
Click on Apply.

Please do an online virus scan with Panda ActiveScan
>Here
. You need to use Internet Explorer for this scan.
  • Once you get to the Panda site, scroll down a bit and click on Scan your PC
  • A new window will appear; click on Check Now!
  • A new window will appear; fill in the boxes (Country, State, email addy)
  • Click on Scan Now! >
  • If you have never used TotalScan before, you will be prompted to install an ActiveX control (asinst.cab) : click on Install. Panda will install the component, and then install the latest signature files.
  • From "Select a device to scan...", choose "My Computer"
  • Allow the scan to run. It'll take a while.
  • When complete, click on "See Report", and then on "Save report"; save it to a convenient location.
  • Please post that report in your next reply. Simply open the text file, then copy/paste the content here. Also, please include a fresh HJT log. Thanks!

March 3rd, 2008 11:00

Spyware:Cookie/ErrorSafe                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.errorsafe.com/]                                                                                                                                             
Spyware:Cookie/ErrorSafe                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[www.errorsafe.com/]                                                                                                                                          
Spyware:Cookie/ErrorSafe                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.errorsafe.com/]                                                                                                                                             
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.drivecleaner.com/]                                                                                                                                          
Spyware:Cookie/Advertising                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.advertising.com/]                                                                                                                                           
Spyware:Cookie/Tribalfusion                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.tribalfusion.com/]                                                                                                                                          
Spyware:Cookie/Adrevolver                                                       Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.adrevolver.com/]                                                                                                                                            
Spyware:Cookie/Bfast                                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.bfast.com/]                                                                                                                                                 
Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[server.iad.liveperson.net/]                                                                                                                                  
Spyware:Cookie/Overture                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.perf.overture.com/]                                                                                                                                         
Spyware:Cookie/Overture                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.overture.com/]                                                                                                                                              
Spyware:Cookie/WebtrendsLive                                                    Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[statse.webtrendslive.com/]                                                                                                                                   
Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[server.iad.liveperson.net/hc/73382804]                                                                                                                       
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[stats.drivecleaner.com/]                                                                                                                                

March 3rd, 2008 11:00

Here is the Panda Activescan Log:

 


Incident                                                                        Status                        Location                                                                                                                                                                                                                                                       

Adware:adware/wupd                                                              Not disinfected               c:\windows\system32\ide21201.vxd                                                                                                                                                                                                                               
Adware:adware/sahagent                                                          Not disinfected               c:\windows\downloaded program files\sporder_.dll                                                                                                                                                                                                               
Spyware:Cookie/Advertising                                                      Not disinfected               C:\Documents and Settings\Gagne\Cookies\gagne@advertising[1].txt                                                                                                                                                                                               
Spyware:Cookie/Apmebf                                                           Not disinfected               C:\Documents and Settings\Gagne\Cookies\gagne@apmebf[1].txt                                                                                                                                                                                                    
Spyware:Cookie/Clickbank                                                        Not disinfected               C:\Documents and Settings\Gagne\Cookies\gagne@clickbank[1].txt                                                                                                                                                                                                 
                                                                                                                                                                                                                                                                         

March 3rd, 2008 11:00

Spyware:Cookie/Go                                                               Not disinfected               C:\Documents and Settings\Gagne\Cookies\gagne@go[1].txt                                                                                                                                                                                                        
Spyware:Cookie/Doubleclick                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.doubleclick.net/]                                                                                                                                           
Spyware:Cookie/Statcounter                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.statcounter.com/]                                                                                                                                           
Spyware:Cookie/Advertising                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.advertising.com/]                                                                                                                                           
Spyware:Cookie/Atlas DMT                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.atdmt.com/]                                                                                                                                                 
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.questionmarket.com/]                                                                                                                                        
Spyware:Cookie/Casalemedia                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.casalemedia.com/]                                                                                                                                           
Spyware:Cookie/YieldManager                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[ad.yieldmanager.com/]                                                                                                                                        
Spyware:Cookie/Tribalfusion                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.tribalfusion.com/]                                                                                                                                          
Spyware:Cookie/WebtrendsLive                                                    Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[statse.webtrendslive.com/]                                                                                                                                   
Spyware:Cookie/Mediaplex                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.mediaplex.com/]                                                                                                                                            

March 3rd, 2008 11:00

Spyware:Cookie/Adtech                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.adtech.de/]                                                                                                                                                 
Spyware:Cookie/Zedo                                                             Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.zedo.com/]                                                                                                                                                  
Spyware:Cookie/BurstBeacon                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[www.burstbeacon.com/]                                                                                                                                        
Spyware:Cookie/BurstNet                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.burstnet.com/]                                                                                                                                              
Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[server.iad.liveperson.net/hc/82761755]                                                                                                                       
Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[server.iad.liveperson.net/]                                                                                                                                  
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.247realmedia.com/]                                                                                                                                          
Spyware:Cookie/Xiti                                                             Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.xiti.com/]                                                                                                                                                  
Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[server.iad.liveperson.net/hc/40053794]                                                                                                                       
Spyware:Cookie/Hitbox                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.phg.hitbox.com/]                                                                                                                                            
Spyware:Cookie/Overture                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.perf.overture.com/]                                                                                                                                         
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.realmedia.com/]                                                                                                                                             
Spyware:Cookie/Belnk                                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.dist.belnk.com/]                                                                                                                                            
Spyware:Cookie/Belnk                                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.belnk.com/]                                                                                                                                                

March 3rd, 2008 11:00

Spyware:Cookie/Apmebf                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.apmebf.com/]                                                                                                                                                
Spyware:Cookie/Mediaplex                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.mediaplex.com/]                                                                                                                                             
Spyware:Cookie/Atwola                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.atwola.com/]                                                                                                                                                
Spyware:Cookie/HotLog                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.hotlog.ru/]                                                                                                                                                 
Spyware:Cookie/SpyLog                                                           Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.spylog.com/]                                                                                                                                                
Spyware:Cookie/WUpd                                                             Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.revenue.net/]                                                                                                                                               
Spyware:Cookie/DomainSponsor                                                    Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[landing.domainsponsor.com/]                                                                                                                                  
Spyware:Cookie/FastClick                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.fastclick.net/]                                                                                                                                             
Spyware:Cookie/Hitslink                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[counter.hitslink.com/]                                                                                                                                       
Spyware:Cookie/Adrevolver                                                       Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.adrevolver.com/]                                                                                                                                            
Spyware:Cookie/Overture                                                         Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.overture.com/]                                                                                                                                              
Spyware:Cookie/Bluestreak                                                       Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.bluestreak.com/]                                                                                                                                                                                                                                                                                      

March 3rd, 2008 11:00

Spyware:Cookie/Server.iad.Liveperson                                            Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[server.iad.liveperson.net/hc/70668281]                                                                                                                       
Spyware:Cookie/GoStats                                                          Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-1.txt[.gostats.com/]                                                                                                                                               
Spyware:Cookie/Casalemedia                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.casalemedia.com/]                                                                                                                                           
Spyware:Cookie/YieldManager                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[ad.yieldmanager.com/]                                                                                                                                  
Spyware:Cookie/QuestionMarket                                                   Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.questionmarket.com/]                                                                                                                                        
Spyware:Cookie/Doubleclick                                                      Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.doubleclick.net/]                                                                                                                                           
Spyware:Cookie/Atlas DMT                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.atdmt.com/]                                                                                                                                                 
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.realmedia.com/]                                                                                                                                             
Spyware:Cookie/Mediaplex                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.mediaplex.com/]                                                                                                                                             
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.drivecleaner.com/]                                                                                                                                          
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[www.drivecleaner.com/]                                                                                                                                       
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[www.drivecleaner.com/.freeware/]                                                                                                                             
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.drivecleaner.com/]                                                                                                          

4 Apprentice

 • 

20.5K Posts

March 3rd, 2008 12:00

If you'd like to clean out those cookies, you might consider using CCleaner. It is a good program to keep and use for regular maintenance.
Note: You will need to reset all your cookies for sites that need them, so be sure you know your login information (passwords, etc.).

Download and scan each user profile with CCleaner:
http://www.ccleaner.com/download/builds
** Select to download the SLIM version.

**Because CCleaner removes everything in temp folders, if you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner.


1. Before first use, select Options > Advanced and UNCHECK
" Only delete files in Windows Temp folder older than 48 hours"
2. Then select the items you wish to clean up.
In the Windows Tab:
• Clean all entries in the "Internet Explorer" section
• Clean all the entries in the "Windows Explorer" section.
• Clean all entries in the "System" section.
• Clean all entries in the "Advanced" section.
• Clean any others that you choose.
In the Applications Tab:
• Clean all in the Firefox/Mozilla section if you use it.
• Clean all in the Opera section if you use it.
• Clean Sun Java in the Internet Section.
• Clean any others that you choose.
3. Click the " Run Cleaner" button.
4. A pop up box will appear advising this process will permanently delete files from your system.
5. Click " OK" and it will scan and clean your system.
6. Click " exit" when done.
REBOOT.

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. It is possible that you may be running Java code in your applications that absolutely require a specific version of the JRE to run. Please follow these steps to remove older version Java components and update.

Updating Java:

  • Download the latest version of Java Runtime Environment (JRE) 6.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u4 allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each of the Java versions.

  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.

Official JAVA Installation Instructions if needed.


That will have you in good shape.

Here is my standard list of 10 simple steps that you can take to reduce the chance of infection in the future.

You may have already taken some of these steps, and depending on your current security, you may not need to implement all of these:

1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp

2. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (by Checkpoint) has a free version http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads

3. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/

4. Do not use file sharing. Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known
vulnerabilities.

5. Before using or purchasing any Spyware/Malware protection/removal program, always check the following Rogue/Suspect Spyware Lists.
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://www.malwarebytes.org/database.php

6. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbar that is checked by default for the Standard version, or download the toolbar-free versions (Slim or Basic) when given the option for those.

7. Make sure you are using the most updated version of Java.
The current version is Java Runtime Environment (JRE) 6u4

You can go here to download the latest version of Java Runtime Environment (JRE) 6.
Scroll down to where it says " Java Runtime Environment (JRE) 6u4 allows end-users to run Java applications".

Click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.

Remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
Reboot your computer once all Java components are removed.
Then from your desktop double-click on jre-6u4-windows-i586-p.exe to install the newest version.
Official JAVA Installation Instructions if needed.
Reboot.

8. Practice Safe Surfing with with TrendProtect by Trendmicro.
TrendProtect is a browser plugin that assigns a safety rating to domains listed in your search engine. TrendProtect also adds a new button to your browser's toolbar area. The icon and color of the button changes to indicate whether the page currently open is safe, unsafe, trusted, or unrated, or whether it contains unwanted content.

The following color codes are used by TrendProtect to indicate the safety of each site.

Red for Warning
Yellow for Use Caution
Green for Safe
Grey for Unknown

9. Here are some helpful articles:
"So how did I get infected in the first place?"
by TonyKlein
http://computercops.biz/postlite7736-.html

"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx

10. This is an excellent resource for users of all levels. General computer maintenance as well as internet security is covered.
Rootkits for Dummies
(Paperback)
by Larry Stevenson (Author), Nancy Altholz (Author)

Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!

March 3rd, 2008 12:00

Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[drivecleaner.com/]                                                                                                                                           
Spyware:Cookie/DriveCleaner                                                     Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[drivecleaner.com/.freeware/]                                                                                                                                 
Spyware:Cookie/RealMedia                                                        Not disinfected               C:\~backup\Front\Mozilla Application Data\Mozilla\Firefox\Profiles\f2pxvkli.default\cookies-2.txt[.247realmedia.com/]

 

Also here is my latest Hijackthis log:

 

  Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 6:31:39 AM, on 3/3/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16608)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\Program Files\Microsoft SQL Server\MSSQL$APHELION\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Lexmark 7100 Series\ezprint.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O1 - Hosts: 127.255.255.255 serial.alcohol-soft.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [FaxCenterServer4_in_1] "C:\Program Files\Lexmark 7100 Series\fm3032.exe" /s
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe"
O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Acronis True Image Monitor] "C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O4 - Startup: SCP.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone: *.fitnessmanager.com
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1191963956093
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} - http://a532.g.akamai.net/f/532/6712/5m/virtools.download.akamai.com/6712/player/install/installer.exe
O16 - DPF: {DA80E089-4648-43D5-93B4-7F37917084E6} (CacheManager.CacheManagerCtrl) - http://www.candystand.com/assets/activex/virtools/CacheManager.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{625E7E14-FEEA-4904-B6E7-F6238F69A6FC}: NameServer = 192.168.1.254
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Intuit QuickBooks FCS (QBFCService) - Intuit Inc. - C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe

--
End of file - 8330 bytes                                                                                                                                                                       

No Events found!

Top