
UNSOLVED
SysProtect Removal - HijackThis log
Here is my Hijackthis Log. I would like to remove SysProtect from my computer. Thanks in advance for your help!!
Logfile of HijackThis v1.99.1
Scan saved at 11:04:08 AM, on 25/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\51fdb205.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe
C:\WINDOWS\?ssembly\?ti2evxx.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\system32\winmine.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Keren\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [51fdb205.exe] C:\WINDOWS\System32\51fdb205.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Pwr32ctr] c:\windows\system32\pwr32ctr.exe
O4 - HKCU\..\Run: [Nvidex32] c:\windows\system32\nvidex32.exe
O4 - HKCU\..\Run: [Dxsty] c:\windows\system32\dxsty.exe
O4 - HKCU\..\Run: [Info32x] c:\windows\system32\info32x.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [51fdb205.exe] C:\Documents and Settings\Keren\Local Settings\Application Data\51fdb205.exe
O4 - HKCU\..\Run: [Eseo] "C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe" -vt yazb
O4 - HKCU\..\Run: [Dyranowz] C:\WINDOWS\?ssembly\?ti2evxx.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\System32\services.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
Logfile of HijackThis v1.99.1
Scan saved at 11:04:08 AM, on 25/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\51fdb205.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe
C:\WINDOWS\?ssembly\?ti2evxx.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\system32\winmine.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Keren\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [51fdb205.exe] C:\WINDOWS\System32\51fdb205.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Pwr32ctr] c:\windows\system32\pwr32ctr.exe
O4 - HKCU\..\Run: [Nvidex32] c:\windows\system32\nvidex32.exe
O4 - HKCU\..\Run: [Dxsty] c:\windows\system32\dxsty.exe
O4 - HKCU\..\Run: [Info32x] c:\windows\system32\info32x.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [51fdb205.exe] C:\Documents and Settings\Keren\Local Settings\Application Data\51fdb205.exe
O4 - HKCU\..\Run: [Eseo] "C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe" -vt yazb
O4 - HKCU\..\Run: [Dyranowz] C:\WINDOWS\?ssembly\?ti2evxx.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O10 - Broken Internet access because of LSP provider 'ctxnsp.dll' missing
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\System32\services.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
Responses (10)
Solutions (0)
- ---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:48:31 PM 26/06/2006
+ Scan result:
C:\WINDOWS\system32\config\systemprofile\My Documents\Τasks\iexplore.exe -> Adware.ClickSpring : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WinRes.WindowsResources.1 -> Adware.CoolWebSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ajqgn.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\system32\services.dll -> Adware.PurityScan : Cleaned with backup (quarantined).
[1168] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[1204] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[1592] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[680] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[692] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[868] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
[968] C:\WINDOWS\System32\services.dll -> Adware.PurityScan : Error during cleaning.
C:\WINDOWS\system32\jkkllll.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\Documents and Settings\Boris\Local Settings\Application Data\51fdb205.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Application Data\51fdb205.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temp\winC1.tmp.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\WINDOWS\system32\51fdb205.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temp\OA.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\My Documents\ѕеcurity\smss.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Y1123OA.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
C:\Documents and Settings\Boris\Local Settings\Temporary Internet Files\Content.IE5\QP0FALI5\L[1].exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
C:\WINDOWS\temp\win48.tmp.exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
C:\vbsys2.dll -> Hijacker.Agent.ac : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temp\winBC.tmp.exe -> Hijacker.Small : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temporary Internet Files\Content.IE5\0HO1MJOH\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup (quarantined).
C:\Documents and Settings\Boris\Local Settings\Temporary Internet Files\Content.IE5\FACRNHS9\SystemDoctor2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temporary Internet Files\Content.IE5\NN9RFPCW\send_ocx_sof[1].htm -> Not-A-Virus.Exploit.HTML.CodeBaseExec : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temporary Internet Files\Content.IE5\WVM58JIP\send_car_int[1].htm -> Not-A-Virus.Exploit.HTML.CodeBaseExec : Cleaned with backup (quarantined).
:mozilla.210:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.122:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.136:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.139:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.163:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.201:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.213:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@msnservices.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@workopolis.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
C:\Documents and Settings\Boris\Cookies\boris@rotator.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.60:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\Keren\ApplicationReply - Ewido continued...
Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup (quarantined).
:mozilla.149:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.135:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.47:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.48:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.49:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.50:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.199:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.41:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.56:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined).
:mozilla.129:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined).
:mozilla.169:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.137:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.144:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@www.myaffiliateprogram[1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.216:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.217:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\Boris\Cookies\boris@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Cookies\keren@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.97:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.98:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.185:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.77:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.44:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.45:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.46:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.130:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.132:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.133:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.134:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.42:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.43:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.131:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.72:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Boris\Application Data\Mozilla\Firefox\Profiles\sagge1i4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.92:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Keren\Application Data\Mozilla\Firefox\Profiles\07oev7si.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temp\cliBA.tmp -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\Documents and Settings\Keren\Local Settings\Temp\cliEC.tmp -> Trojan.Agent.vg : Cleaned with backup (quarantined).
C:\WINDOWS\system32\winrkp32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
[632] C:\WINDOWS\system32\winrkp32.dll -> Trojan.Agent.vg : Error during cleaning.
C:\Documents and Settings\Keren\Local Settings\Temp\svrhost.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
::Report endReply - Thanks for your quick reply! I think I did everything correctly!!!
VundoFix V4.2.84
Running as SYSTEM
from c:\windows\system32\VundoFix.exe
Checking Java version...
Java version is 1.4.2.1
Scan started at 10:53:03 PM 26/06/2006
Listing files found while scanning....
C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\xbeeg.bak2
C:\WINDOWS\system32\xbeeg.ini
C:\WINDOWS\system32\xbeeg.ini2
C:\WINDOWS\system32\geebx.dll
C:\WINDOWS\system32\xbeeg.ini2
C:\WINDOWS\system32\xbeeg.bak2
C:\WINDOWS\system32\xbeeg.ini
C:\WINDOWS\system32\xbeeg.ini2
C:\WINDOWS\system32\geebx.dll
Attempting to delete C:\WINDOWS\system32\xbeeg.bak1
C:\WINDOWS\system32\xbeeg.bak1 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xbeeg.bak2
C:\WINDOWS\system32\xbeeg.bak2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\xbeeg.ini
C:\WINDOWS\system32\xbeeg.ini Has been deleted!
Attempting to delete C:\WINDOWS\system32\xbeeg.ini2
C:\WINDOWS\system32\xbeeg.ini2 Has been deleted!
Attempting to delete C:\WINDOWS\system32\geebx.dll
C:\WINDOWS\system32\geebx.dll Has been deleted!
Performing Repairs to the registry.
Done!Reply - and my Hijack #2 log
Hijack #2 log
Logfile of HijackThis v1.99.1
Scan saved at 10:58:20 PM, on 26/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\?ssembly\?ti2evxx.exe
C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\Keren\Desktop\HIjak\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll (file missing)
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O2 - BHO: (no name) - {DF3C8EFD-EC96-4A86-B180-C131B755518B} - C:\WINDOWS\System32\geebx.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Pwr32ctr] c:\windows\system32\pwr32ctr.exe
O4 - HKCU\..\Run: [Nvidex32] c:\windows\system32\nvidex32.exe
O4 - HKCU\..\Run: [Dxsty] c:\windows\system32\dxsty.exe
O4 - HKCU\..\Run: [Info32x] c:\windows\system32\info32x.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [51fdb205.exe] C:\Documents and Settings\Keren\Local Settings\Application Data\51fdb205.exe
O4 - HKCU\..\Run: [Dyranowz] C:\WINDOWS\?ssembly\?ti2evxx.exe
O4 - HKCU\..\Run: [Eseo] "C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe" -vt ndrv
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: MetaFrame Password Manager Agent Background Process.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: C:\WINDOWS\System32\services.dll
O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeReply - It looks as if you and ewido were busy.
When we are finished, I suggest that you keep ewido and use it regularly, as it updates almost daily.
Please print these instructions so you can refer to them easily because you will be working in Safemode and you will not have the internet.
First, I suggest that you remove SpyBlocs using Add/Remove Programs. It is listed as a Rogue Program:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
http://www.castlecops.com/startuplist-4655.html
After removing SpyBlocs, reboot into Safemode:
Turn on the computer.
Immediately begin tapping the F8 key
Use the arrow keys to highlight Safe Mode and press the Enter key.
Configure to show all files/folders:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Show hidden files and folders
Uncheck: Hide protected operating system files
Click on Apply.
Next go to the side of the Search box and select All files and folders. Go down to More advanced options.
Be sure the first three boxes are selected:
Search System folders
Search Hidden Files and folders
Search SubFolders
Launch HijackThis and place a checkmark next to these:
R3 - URLSearchHook: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll (file missing)
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: (no name) - {0FA95A75-C0B3-C34A-9D94-97FC5C81B7B6} - C:\WINDOWS\System32\ajqgn.dll (file missing)
O2 - BHO: (no name) - {DF3C8EFD-EC96-4A86-B180-C131B755518B} - C:\WINDOWS\System32\geebx.dll (file missing)
O4 - HKCU\..\Run: [Pwr32ctr] c:\windows\system32\pwr32ctr.exe
O4 - HKCU\..\Run: [Nvidex32] c:\windows\system32\nvidex32.exe
O4 - HKCU\..\Run: [Dxsty] c:\windows\system32\dxsty.exe
O4 - HKCU\..\Run: [Info32x] c:\windows\system32\info32x.exe
O4 - HKCU\..\Run: [51fdb205.exe] C:\Documents and Settings\Keren\Local Settings\Application Data\51fdb205.exe
O4 - HKCU\..\Run: [Dyranowz] C:\WINDOWS\?ssembly\?ti2evxx.exe
O4 - HKCU\..\Run: [Eseo] "C:\DOCUME~1\Keren\MYDOCU~1\CURITY~1\smss.exe" -vt ndrv
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O20 - AppInit_DLLs: C:\WINDOWS\System32\services.dll
O20 - Winlogon Notify: winrkp32 - winrkp32.dll (file missing)
If you removed SpyBlocs fix this one as well:
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
Delete the specified files IF they exist:
C:\WINDOWS\System32\ services.dll --file
C:\WINDOWS\system32\ winrkp32.dll --file
If you removed this program delete:
C:\PROGRAM FILES\ SpyBlocs -- FOLDER
Regarding these:
The question marks and symbols are text that is not recognized by Windows, so you will have to do some detective work to make sure you do not delete legitimate files.
This folder could perhaps be "Assembly" or something similar. The file in it will end with "ti2evxx.exe". If in doubt, right-click on it and look at the Properties. If it says "Microsoft" it is legitimate, so you should not delete it!
C:\WINDOWS\?ssembly\ ?ti2evxx.exe --file
C:\DOCUME~1\Keren\MYDOCU~1\ CURITY~1\--FOLDER may be named "Security".
After deleteing those, reboot normally.
Rehide files/folders:
Go to Start>Search and at the top select Tools>Folder Options
Select the View tab
Display the contents of system folders
Check: Hide protected operating system files
Click on Apply.
Please post a fresh HJT log. Thanks.Message Edited by Bugbatter on 06-27-200612:12 PM
Reply - Hi Bugbatter,
I could not remove SpyBlocs because it said that there was no uninstal.log file.
Here is the most recent Hijack This log: THANKS!!
Logfile of HijackThis v1.99.1
Scan saved at 8:37:56 PM, on 29/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Documents and Settings\Keren\Desktop\HIjak\HijackThis.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - {C4C5334F-A385-FE2E-A930-F8EA6DC273B0} - C:\WINDOWS\System32\dmtbrqk.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O2 - BHO: (no name) - {C4C5334F-A385-FE2E-A930-F8EA6DC273B0} - C:\WINDOWS\System32\dmtbrqk.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_01\bin\npjpi142_01.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeReply - With SpyBlocs you have two choices. You can leave it as is, and just be aware that it has false positives, or you can delete the folder in your Program Files, and then fix the entry in HijackThis.
That is up to you.
Please boot into Safemode as you did before.
Configure to show hidden files as you did before.
Please launch HijackThis and place a checkmark next to the following:
R3 - URLSearchHook: (no name) - {C4C5334F-A385-FE2E-A930-F8EA6DC273B0} - C:\WINDOWS\System32\dmtbrqk.dll
O2 - BHO: (no name) - {C4C5334F-A385-FE2E-A930-F8EA6DC273B0} - C:\WINDOWS\System32\dmtbrqk.dll
If you removed SpyBlocs, fix this entry:
O4 - HKLM\..\Run: [SpyBlocs] C:\PROGRA~1\SpyBlocs\SpyBlocs.exe
Close all windows except HJT and click "Fix Checked".
If you have not done so and you are removing SpyBlocs, delete the folder for it here: C:\PROGRA~1\ SpyBlocs
Delete this file:
C:\WINDOWS\System32\ dmtbrqk.dll --file
Reboot normally.
Go back and rehide protected files.
Download and scan all user profiles with CCleaner
Select the BASIC version. HERE
1. Before first use, select Options > Advanced and UNCHECK " Only delete files in Windows Temp folder older than 48 hours"
2. Then select the items you wish to clean up.
In the Windows Tab:
o Clean all entries in the "Internet Explorer" section except Cookies.
o Clean all the entries in the "Windows Explorer" section.
o Clean all entries in the "System" section.
o Clean all entries in the "Advanced" section.
o Clean any others that you choose.
In the Applications Tab:
o Clean all except cookies in the Firefox/Mozilla section if you use it.
o Clean all in the Opera section if you use it.
o Clean Sun Java in the Internet Section.
o Clean any others that you choose.
3. Click the " Run Cleaner" button.
4. A pop up box will appear advising this process will permanently delete files from your system.
5. Click " OK" and it will scan and clean your system.
6. Click " exit" when done.
REBOOT.
Your outdated Java made you susceptible to Vundo.
Please follow these steps to remove older version Java components:
1. Close any open programs you may have running, especially your web
browser
2. Click Start > Control Panel
* Depending on your OS or configuration, you may have to click Start
>Settings > Control Panel
3. Open Add or Remove Programs
* If you have Windows 98 or Windows 2000, open Add/Remove
Programs
4. Click once on any item listing Java Runtime Environment in the name
* Not every version of Java will begin with "Java" so be sure to read
each entry in the list
5. Click the Remove or Change/Remove button
6. Follow steps 4 and 5 as many times as necessary to remove all
versions of Java. ** If at any time during the uninstallations, you are asked to reboot, do so. Then return to Add/Remove and continue removing any other versions of Java until all components of Java have been removed.
7. Delete the Java folder in Program Files.
8. Proceed with reinstalling Java. You will need to use Internet Explorer for this.
Go to Sun Java and click the link to download the Windows (Offline Installation) package: Save it, do not run it.
When the download is complete, close the browser and install it.
Reboot.
Please post a fresh HijackThis log. Thanks.Reply - The Spyblocs folder is no where to be found, so I couldn't delete it.
Thanks for your follow up. I have re-posted the Hijak log.
Have a nice weekend!
Logfile of HijackThis v1.99.1
Scan saved at 5:04:04 PM, on 30/06/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Keren\Desktop\HIjak\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\MSN Toolbar\01.02.5000.1021\en-ca\msntb.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_07\bin\jusched.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {407F5185-3B2E-4196-982B-1E258C46F8FD} - ftp://ftp.ea.com/pub/easports/patches/nhl2003/en-us/nhl.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://scan.safety.live.com/resource/download/scanner/wlscbase5059.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) - http://www.sibelius.com/download/software/win/ActiveXPlugin.cab
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} (Yahoo! Toolbar) - http://us.dl1.yimg.com/download.companion.yahoo.com/dl/toolbar/yiebio5_1_6_0.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = bfcorp.local,brookfield.com
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeReply - That looks good. SpyBlocs seems to be gone.
You might want to keep CCleaner and use it regularly. It updates every so often.
You can keep ewido to use on demand after the trial runs out. The only difference is that you will have to update it manually. If you are finding that the realtime guard is making your computer slower, disable it to run at Windows Startup.
You can delete VundoFix. Hopefully, you won't need that any longer.
After something like this it is a good idea to purge the Restore Points and start fresh.
If everything is running well....
To flush the XP System Restore Points:
(Using XP, you must be logged in as Administrator to do this.)
Go to Start>Run and type msconfig Press enter.
When msconfig opens, click the Launch System Restore Button.
On the next page, click the System Restore Settings Link on the left.
Check the box labeled Turn Off System Restore.
Reboot. Go back in and turn System Restore ON. A new Restore Point will be created.
Here is my standard list of simple steps that you can take to reduce the chance of infection in the future.
You may have already taken some of these steps:
1. Visit Windows Update:
Make sure that you have all the Critical Updates recommended for your operating system and IE. The first defense against infection is a properly patched OS.
Windows Update: http://v4.windowsupdate.microsoft.com/en/default.asp
2. Adjust your security settings for ActiveX:
Go to Internet Options/Security/Internet, press 'default level', then OK.
Now press "Custom Level."
In the ActiveX section, set the first two options ("Download signed and unsigned ActiveX controls) to 'prompt', and 'Initialize and Script ActiveX controls not marked as safe" to 'disable'.
3. Download and install the following free programs:
a. SpywareBlaster:
http://www.javacoolsoftware.com/spywareblaster.html
Tutorial here: http://www.bleepingcomputer.com/forums/tutorial49.html
b. SpywareGuard:
http://www.javacoolsoftware.com/spywareguard.html
Tutorial here: http://www.bleepingcomputer.com/tutorials/tutorial50.html
Periodically check for updates in both programs.
4. Please use a firewall and realtime anti-virus. Keep the anti-virus software and firewall software up to date.
Note: Zone Alarm Firewall (Zone Labs) http://www.zonelabs.com/store/content/company/products/trial_zaFamily/trial_zaFamily.jsp?lid=home_freedownloads
Sunbelt Kerio has a free version: http://www.kerio.com/kpf_download.html
5. You might consider installing Mozilla / Firefox.
http://www.mozilla.org/
6. Install spyware detection and removal programs:
You may also want to consider installing either or both of AdAware (free version) and Spybot S&D (freeware). Use these programs to regularly scan your system for and remove many forms of spyware/malware.
a. Ad-aware: http://www.lavasoft.de/software/adaware/
b. SpyBot S&D: http://safer-networking.org/en/news/2005-05-31.html
I would check for updates in SpyBot once a week or so.
Check for updates in Ad-aware frequently.
If you have recently installed Ewido, it is a free trial product for 30 days. After that you can purchase it for full features OR you can also keep the free version to use as an on-demand scanner (recommended).
You will still be able to manually update Ewido using the *update* button
7. Before using or purchasing any Spyware/Malware protection/removal program, always check the Rogue/Suspect Spyware List.
Here is the link:
http://www.spywarewarrior.com/rogue_anti-spyware.htm
If you want to know just how effective your anti-spyware program is, or how well any of the "rogue" programs listed at the above link work, check this for an independent comparison of several anti-spyware programs: http://www.spywarewarrior.com/asw-test-guide.htm
8. If you have not already done so, you might want to install CCleaner and run it in each user's profile: http://www.ccleaner.com/
** UNcheck the option to install the Yahoo toolbr.
9. If you use Adobe Reader it may need to be updated to be sure that you have a more secure version. If you are using a version prior to v. 6.05, you should update to 6.05, preferably version 7.08. It would be best to remove prior versions before updating to a new version.
Info here: http://www.adobe.com/support/downloads/product.jsp?product=10&platform=Windows
If you need additional assistance, the Adobe forums are here: http://www.adobe.com/support/forums/main.html
10. Make sure you are using the most udpated version of Java.
If you need to update, remove all prior versions using Add/Remove Programs, and delete the Java folder in Program Files.
You can go here to download the latest version: Sun Java and click the link to download the Windows (Offline Installation) package: Save it, do not run it. When the download is complete, close the browser.
Proceed with reinstalling Java. Reboot.
11. Here are some helpful articles:
"So how did I get infected in the first place?"
http://computercops.biz/postlite7736-.html
"I'm not pulling your leg, honest"
by Sandi Hardmeier
http://www.microsoft.com/windows/IE/community/columns/pulling.mspx
Let us know if we have not resolved your problem. Otherwise, you are good to go.
Happy and Safe Surfing!Reply

Bugbatter
4 Apprentice
•
20487 Posts
312
0
Posted June 26th, 2006 02:00
Welcome :) I see a few infections in your log.
Please print these instructions so you can refer to them easily.
Download ewido anti-spyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
- Once you have downloaded Ewido anti-spyware, locate the icon on the desktop and double-click it to launch the set up program.
- Select "Change state" to inactivate 'Resident Shield' and 'Automatic Updates'. Right click on ewido in the system tray and uncheck "Start with Windows".
- You can change those settings AFTER I have verified that your system is clean. Do not do it before then, or our fixes during the next few days may not work.
- Once the setup is complete you will need run ewido and update the definition files.
- On the main screen select the icon "Update" then select the "Update now" link.
- Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
- Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
- Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
- Under "Reports"
- Select "Automatically generate report after every scan"
- Un-Select "Only if threats were found"
- Close ewido anti-spyware, Do Not run a scan just yet.
- In Safe Mode, load Ewido and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
- Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
- Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
- Restart back into Normal Mode.
- Double-click VundoFix.exe to run it.
- Put a check next to Run VundoFix as a task.
- You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
- When VundoFix re-opens, click the Scan for Vundo button.
- Once it's done scanning, click the Remove Vundo button.
- You will receive a prompt asking if you want to remove the files, click YES
- Once you click yes, your desktop will go blank as it starts removing Vundo.
- When completed, it will prompt that it will shutdown your computer, click OK.
- Turn your computer back on.
- Please post the contents of C:\vundofix.txt, your report from Ewido, and the new HiJackThis log.
You may need several replies to do this if your posts are cut off.Please reboot your computer into Safe Mode. To boot into Safe Mode, please restart your computer. Tap F8 before Windows loads. Select Safe Mode on the screen that appears.
Please download VundoFix.exe to your desktop.
Rightclick on an empty space on your desktop and choose New > Folder
Name it HijackThis (HJT, or whatever)
Rightclick HijackThis.exe, choose Cut.
Doubleclick (to open) the folder you created.
Rightclick inside and choose Paste.
Run another scan with HJT.
Message Edited by Bugbatter on 06-25-200610:06 PM