UNSOLVED

drosgarage

updated

20 years ago

0

426

February 28th, 2007 00:00

Trojan

Hello all, I've got a trojan that I shouldn't have, however I was lazy and now I'm paying for it. here is my scan, can you guys help me? file of HijackThis v1.99.1 Scan saved at 9:03:17 PM, on 2/27/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16414) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\CTsvcCDA.EXE C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe C:\WINDOWS\system32\drivers\KodakCCS.exe C:\Program Files\Network Associates\Common Framework\FrameworkService.exe C:\Program Files\Network Associates\VirusScan\mcshield.exe C:\Program Files\Network Associates\VirusScan\vstskmgr.exe C:\PROGRA~1\NETWOR~1\COMMON~1\naPrdMgr.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\MsPMSPSv.exe C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe C:\Program Files\Common Files\Dell\EUSW\Support.exe C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Messenger\msmsgs.exe C:\PROGRA~1\AWS\WEATHE~1\Weather.exe C:\WINDOWS\system32\ctfmon.exe E:\Program Files\Kodak EasyShare software\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe E:\Program Files\iPod\bin\iPodService.exe C:\WINDOWS\System32\alg.exe C:\Program Files\Google\Web Accelerator\googlewebaccclient.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\Dell\Support\bin\ClientApplicationFrameWork.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Program Files\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/ymsgr6/*http://www.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://localhost:9100/proxy.pac R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file) O3 - Toolbar: Dictionary.com - {11359F4A-B191-42D7-905A-594F8CF0387B} - C:\WINDOWS\Downloaded Program Files\CONFLICT.2\lexbar.dll O3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dll O3 - Toolbar: WeatherBug Browser Bar - powered by MyWebSearch - {8EAB99C9-F9EC-4b64-A4BA-D9BCAE8779C2} - C:\Program Files\MyWebSearchWB\bar\2.bin\W6BAR.DLL O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Weather] C:\PROGRA~1\AWS\WEATHE~1\Weather.exe 1 O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: Kodak EasyShare software.lnk = E:\Program Files\Kodak EasyShare software\Kodak EasyShare software\bin\EasyShare.exe O4 - Global Startup: Run Google Web Accelerator.lnk = C:\Program Files\Google\Web Accelerator\GoogleWebAccWarden.exe O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Search &Dictionary - C:\Program files\Lexico\Toolbar\dictionary.htm O8 - Extra context menu item: Search &Thesaurus - C:\Program files\Lexico\Toolbar\thesaurus.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O11 - Options group: [INTERNATIONAL] International* O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab? O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O16 - DPF: {F0E2D69A-DC2F-4E9B-A993-684FB1C21DBC} - http://dictionary.reference.com/tools/toolbar/lexico.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: C:\PROGRA~1\Google\GO333C~1\GOEC62~1.DLL O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - E:\Program Files\iPod\bin\iPodService.exe O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe Please Help!!!
  • 1972vet

    3305 Posts

    199

    0

    Posted February 28th, 2007 03:00

    Scan here. Read This. Post your results.
  • 199

    0

    Posted February 28th, 2007 13:00

    Hello, I downloaded the AVG as you asked. Is this the report you need?


    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 10:22:48 AM 2/28/2007

    + Scan result:



    :mozilla.103:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.104:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.105:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.106:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.107:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.108:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.109:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.110:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.112:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.113:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    :mozilla.169:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\John\Cookies\john@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : No action taken.
    :mozilla.36:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.37:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.38:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.39:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
    :mozilla.41:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
    :mozilla.374:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
    :mozilla.375:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
    :mozilla.204:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Com : No action taken.
    :mozilla.326:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Counted : No action taken.
    :mozilla.40:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
    :mozilla.150:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.388:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.389:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.390:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.391:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.392:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.393:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.394:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.48:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
    :mozilla.344:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
    :mozilla.345:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
    :mozilla.346:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Liveperson : No action taken.
    :mozilla.67:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
    :mozilla.140:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Overture : No action taken.
    :mozilla.94:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Overture : No action taken.
    :mozilla.258:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
    :mozilla.269:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
    :mozilla.270:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
    :mozilla.271:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
    :mozilla.87:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
    :mozilla.88:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
    :mozilla.91:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
    :mozilla.92:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
    :mozilla.93:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
    :mozilla.275:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.276:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.277:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.278:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.279:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.280:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.281:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Revsci : No action taken.
    :mozilla.193:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.283:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.284:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.285:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.286:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.287:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
    :mozilla.114:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.115:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.116:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.117:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.118:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.119:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.120:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
    :mozilla.178:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
    :mozilla.77:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
    :mozilla.78:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
    :mozilla.80:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
    :mozilla.81:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
    :mozilla.82:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
    :mozilla.297:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.298:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.299:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.300:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.301:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.302:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.303:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.304:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
    :mozilla.305:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Trafic : No action taken.
    :mozilla.308:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
    :mozilla.309:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Valueclick : No action taken.
    :mozilla.164:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
    :mozilla.320:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.321:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.322:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.323:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
    :mozilla.165:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
    :mozilla.166:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
    :mozilla.167:C:\Documents and Settings\John\Application Data\Mozilla\Firefox\Profiles\wwduk4wc.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP4\A0002091.dll -> Trojan.Agent.acl : No action taken.


    ::Report end

    Thank you very much for your help.
  • 1972vet

    3305 Posts

    199

    0

    Posted February 28th, 2007 15:00

    Looks like you need to tweak the application a bit. None of it's findings were removed. Do this:

    Open the AVG Anti-Spyware application by double-clicking its icon on your desktop or in the system tray.

    • Then right click on AVG Anti-Spyware in the system tray and uncheck "Start with Windows".
    • Go to Start > Run and type: services.msc
      • Press "OK".
      • Click the "Extended tab" and scroll down the list to find AVG Anti-Spyware guard.
      • When you find the guard service, double-click on it.
      • In the Properties Window > General Tab that opens, click the "Stop" button.
      • From the drop-down menu next to "Startup Type", click on "Manual".
      • Now click "Apply", then "OK" and close the Services window.
      • Select the "Update" button and click "Start update". Wait until you see the "Update successful message. If you are having problems with the updater, manually update with the AVG Anti-Spyware Full database installer from here.

      Once the updates are installed do the following:
      Click on the " Scanner" button and choose the " Settings" tab.
      • Under "How to act?", click on "Recommended actions" and choose "Quarantine" to set default action for detected malware.
      • Under "How to Scan?" check all (default).
      • Under "Possibly unwanted software" check all (default).
      • Under "What to Scan?" make sure "Scan every file" is selected (default).
      • Under "Reports" select "Automatically generate report after every scan" and UNcheck "Only if threats were found".

      Close the application and reboot the computer into Safe mode. Once in safe mode continue with the instructions below:

      Open the AVG Anti-Spyware application and click the " Scan" tab.
      Click " Complete System Scan" to start.

      Note: Close all open windows, programs, and DO NOT USE the computer while AVG Anti-Spyware is scanning. If Explorer or other programs are open during the scan that means certain files will also be in use. Some malware will insert itself and hide in areas that are "protected" by Windows when the files are being used. This can hamper AVG Anti-Spyware's ability to clean properly and may result in reinfection.

      Note: If AVG Anti-Spyware "crashes" or "hangs" during the scan, try scanning again by doing this:
      • Scan one sector of the system at a time by using the "Custom Scan" feature. To do this select Scanner > Custom Scan and click on Add drive/directory/file. Browse to C:\Windows > System, add this folder to the list and click on "Start Scan". When the scan is complete, repeat the Custom Scan but this time, browse to and add the System32 folder. Then keep repeating this procedure until all your folders have been scanned. Make sure you include the Documents & Settings folder.
      • If this still does not help, then turn the ADS scanner off while making a Custom Scan. To do this select Scanner > Scan Settings and untick "Scan in NTFS Alternate Data Streams". Then repeat the steps above for performing a Custom Scan.
      When the scan has finished you will be presented with a list of infected objects found. Click " Apply all actions" to place the files in Quarantine.

      IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate " No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?

      Click on " Save Report" to view all completed scans. Click on the most recent scan you just performed and select " Save report as" - the default file name will be in date/time format as follows: Report-Scan-20060620-142816.txt. Save to your desktop. A copy of each report will also be saved in C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports\

      Exit AVG Anti-Spyware when done. Boot back to your normal Windows user mode and post the AVG Anti-Spyware scan log along with a fresh HijackThis log. Thanks!