1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Malware removal

Discussion in 'Virus & Other Malware Removal' started by rulito, Feb 17, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
    I keep getting a lot of pop-ups while surfing. At the beginning they were sort of "not too bad", but now I a getting mostly adultfriendfinder stuff, and casino type and today porn pup-ups.

    I downloaded hijackthis and run a scan, but I don't know what to do with it.

    Here is de result of the scan>

    Logfile of HijackThis v1.99.1
    Scan saved at 9:32:10 AM, on 2/17/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE
    C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\parentalcontrol\parentalcontrol.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\LimeWire\LimeWire.exe
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Andrea Quintal\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX3500 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE /P26 "EPSON Stylus CX3500 Series" /O6 "USB001" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [parentalcontrol] "C:\Program Files\parentalcontrol\parentalcontrol.exe" "C:\Program Files\parentalcontrol\parentalcontrol.dll" "parentalcontrol"
    O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB002" /M "Stylus C67"
    O4 - HKLM\..\Run: [nurbnounsettingsaxis] C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN\PLANDRV.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    O4 - HKCU\..\Run: [BAITLOG] C:\DOCUME~1\ANDREA~1\APPLIC~1\TRUSTF~1\OptionRegs.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk895YYMX
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/SmileyCentralFWBInitialSetup1.0.0.15.cab
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://andreamonitaa-z.spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

    Thanks for any help you can provide.

    rulito.
     
  2. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Hi and welcome :)

    Download AVG Anti-Spyware from HERE and save that file to your desktop.

    When the trial period expires it becomes feature-limited freeware but is still worth keeping as a good on-demand scanner.


    1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double click it to launch the set up program.
    2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button. The update will start and a progress bar will show the updates being installed.
    4. Once the update has completed, select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close AVG Anti-Spyware. Do Not run a scan just yet, we will run it in safe mode.
    1. Reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.

      IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning as it may interfere with the scanning process:
    2. Launch AVG Anti-Spyware by double clicking the icon on your desktop.
    3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    4. AVG will now begin the scanning process. Please be patient as this may take a little time.
      Once the scan is complete, do the following:
    5. If you have any infections you will be prompted. Then select "Apply all actions."
    6. Next select the "Reports" icon at the top.
    7. Select the "Save report as" button in the lower lef- hand of the screen and save it to a text file on your system (make sure to remember where you saved that file. This is important).
    8. Close AVG Anti-Spyware and reboot your system back into Normal Mode.


    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report


    Come back here and post a new HijackThis log along with the logs from the AVG and Panda scans.
     
  3. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
    I did all the reccomended steps. Here is the HThis result:
    Logfile of HijackThis v1.99.1
    Scan saved at 4:46:50 PM, on 2/19/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE
    C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\parentalcontrol\parentalcontrol.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    c:\progra~1\intern~1\iexplore.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Documents and Settings\Andrea Quintal\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX3500 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE /P26 "EPSON Stylus CX3500 Series" /O6 "USB001" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [parentalcontrol] "C:\Program Files\parentalcontrol\parentalcontrol.exe" "C:\Program Files\parentalcontrol\parentalcontrol.dll" "parentalcontrol"
    O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB002" /M "Stylus C67"
    O4 - HKLM\..\Run: [nurbnounsettingsaxis] C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN\PLANDRV.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
    O4 - HKCU\..\Run: [BAITLOG] C:\DOCUME~1\ANDREA~1\APPLIC~1\TRUSTF~1\OptionRegs.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZNxmk895YYMX
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://andreamonitaa-z.spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

    Next I will post the AVG report.
     
  4. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
    Here is the AVG Report.

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 9:40:37 AM 2/19/2007

    + Scan result:



    C:\Program Files\Screensavers.com\SSSInst\bin\SSSInst.dll -> Adware.Comet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP120\A0021548.dll -> Adware.Comet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\db -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\report -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\report\aggr_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\report\send_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\cs\res1\WhiteList.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Claudia Rodriguez\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\db -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\report -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\report\aggr_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\report\send_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\cs\res1\WhiteList.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\shprrprt_1151780397.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Application Data\ShopperReports\shprrprt_1151780528.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Raùl Quintal\Local Settings\Temp\HbToolsU.exe -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\Config.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\db -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\db\Aliases.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\db\Sites.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\dwld -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\dwld\WhiteList.xip -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\persist.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\report -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\report\aggr_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\report\send_storage.xml -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\res1 -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\cs\res1\WhiteList.dbs -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365504.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365558.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365565.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365585.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365619.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365626.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365646.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365680.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365687.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365707.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365741.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365748.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365768.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365802.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365809.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\Documents and Settings\Rulo Quintal\Application Data\ShopperReports\shprrprt_1163365829.log -> Adware.HotBar : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{BFAA719B-281F-45B6-9E39-9D4BB578C2A4}\RP115\A0021253.dll -> Adware.Shopper : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{2A1E37A4-04F1-5535-0715-F2C7C83EB4EE} -> Adware.SpyOnThis : Cleaned with backup (quarantined).
    C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea_q[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][url]www.adbrite[/url][2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Adbrite : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Addynamix : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt -> TrackingCookie.Adjuggler : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][2].txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Bfast : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Bfast : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Bluemountain : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Casalemedia : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Clickbank : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Clickbank : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Clickzs : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Coremetrics : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Euroclick : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Falkag : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Fastclick : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Goclick : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Hotlog : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Information : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt -> TrackingCookie.Linksynergy : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][4].txt -> TrackingCookie.Liveperson : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Lop : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Lop : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.Lop : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Lop : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Lop : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Masterstats : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt -> TrackingCookie.Masterstats : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Mediaplex : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Onestat : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Overture : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Paycounter : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Paycounter : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Pointroll : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Pro-market : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Qksrv : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Realmedia : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Revenue : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][2].txt -> TrackingCookie.Ru4 : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Serving-sys : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Sexcounter : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Sexlist : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Sexlist : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Sextracker : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt -> TrackingCookie.Spylog : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt -> TrackingCookie.Starware : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][2].txt -> TrackingCookie.Starware : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt -> TrackingCookie.Starware : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Statcounter : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Targetnet : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Targetnet : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Trafficmp : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Trafic : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Tribalfusion : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Valueclick : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt -> TrackingCookie.Xxxcounter : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Xxxcounter : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Yadro : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned.


    ::Report end

    Next I run the Panda scan and still found infected stuff. Next I will post the report.
     
  5. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
    Here is the Panda Scan.


    Incident Status Location

    Adware:Adware/Lop Not disinfected c:\docume~1\andrea~1\applic~1\trustf~1\optionregs.exe
    Potentially unwanted tool:application/mywebsearch Not disinfected hkey_current_user\software\MyWebSearch
    Adware:adware/abox Not disinfected Windows Registry
    Dialer:dialer.asl Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A1426AC5-8CE5-4A00-B71E-011D35709AC6}
    Potentially unwanted tool:application/funweb Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlSearchHooks\{00a6faf6-072e-44cf-8957-5838f569a31d}
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN\DefaultThat.exe
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN\PLANDRV.exe
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\Andrea Quintal\Application Data\Trust first site\bjqisofd.exe
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\Andrea Quintal\Application Data\Trust first site\dpjqdqig.exe
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\Andrea Quintal\Application Data\Trust first site\OptionRegs.exe
    Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt
    Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt
    Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][2].txt
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\andrea [email protected][1].txt
    Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][2].txt
    Spyware:Cookie/Admotion Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/fe.lea.lycos Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Andrea Quintal\Cookies\[email protected][1].txt
    Potentially unwanted tool:Application/FunWeb Not disinfected C:\Documents and Settings\Andrea Quintal\Desktop\backups\backup-20070217-093711-938.inf
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\Andrea Quintal\Local Settings\Temp\bisCD.exe
    Adware:Adware/Lop Not disinfected C:\Documents and Settings\Andrea Quintal\Local Settings\Temp\sta17C.exe
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt
    Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\claudia [email protected][1].txt
    Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][1].txt
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected]nder[1].txt
    Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Claudia Rodriguez\Cookies\[email protected][2].txt
    Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Raùl Quintal\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-501a5588-2f88883a.zip[Gummy.class]
    Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Raùl Quintal\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-501a5588-2f88883a.zip[Counter.class]
    Hacktool:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Raùl Quintal\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\arr3.jar-501a5588-2f88883a.zip[VerifierBug.class]
    Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt
    Spyware:Cookie/Cgi-bin Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt
    Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][2].txt
    Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt
    Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raùl [email protected][1].txt
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt
    Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][2].txt
    Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt
    Spyware:Cookie/MetriWeb Not disinfected C:\Documents and Settings\Raùl Quintal\Cookies\raù[email protected][1].txt
    Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt
    Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt
    Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt
    Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\rulo [email protected][1].txt
    Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt
    Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt
    Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][1].txt
    Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Rulo Quintal\Cookies\[email protected][2].txt
    Thanks in advance for any help.

    Rulito
     
  6. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Click Start | Settings | Control Panel
    Click the Java Plugin Icon
    Click the Cache tab
    Click the Clear button and click OK to confirm
    Note: Please repeat this procedure for each "Java Plugin" button in your Control Panel.

    or

    Control Panel > Java > General tab
    Temporary Internet Files > Delete Files
    Checkmark all 3 options and click OK.

    1. Please download The Avenger by Swandog46 to your Desktop.
    • Click on Avenger.zip to open the file
    • Extract avenger.exe to your desktop

    2. Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):


    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


    3. Now, start The Avenger program by clicking on its icon on your desktop.
    • Under "Script file to execute" choose "Input Script Manually".
    • Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
    • Paste the text copied to clipboard into this window by pressing (Ctrl+V).
    • Click Done
    • Now click on the Green Light to begin execution of the script
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please copy/paste the content of c:\avenger.txt into your reply.


    Rescan with Hijack This, close all browser windows except Hijack This, put a checkmark beside these entries and click fix checked.

    R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)

    O4 - HKLM\..\Run: [nurbnounsettingsaxis] C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN\PLANDRV.exe

    O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

    O4 - HKCU\..\Run: [BAITLOG] C:\DOCUME~1\ANDREA~1\APPLIC~1\TRUSTF~1\OptionRegs.exe

    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...p=ZNxmk895YYMX


    Reboot and post another Hijack This log please.
     
  7. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
    Here are the results.

    First the avenger.txt

    Logfile of The Avenger version 1, by Swandog46
    Running from registry key:
    \Registry\Machine\System\CurrentControlSet\Services\lnfygmbv

    *******************

    Script file located at: \??\C:\Program Files\ltoiimjt.txt
    Script file opened successfully.

    Script file read successfully

    Backups directory opened successfully at C:\Avenger

    *******************

    Beginning to process script file:

    Folder C:\Documents and Settings\All Users\Application Data\DUMB WINDOW NURB NOUN deleted successfully.
    Folder C:\Documents and Settings\Andrea Quintal\Application Data\Trust first site deleted successfully.


    Folder C:\Program Files\MyWebSearch not found!
    Deletion of folder C:\Program Files\MyWebSearch failed!

    Could not process line:
    C:\Program Files\MyWebSearch
    Status: 0xc0000034

    File C:\Documents and Settings\Andrea Quintal\Local Settings\Temp\bisCD.exe deleted successfully.
    File C:\Documents and Settings\Andrea Quintal\Local Settings\Temp\sta17C.exe deleted successfully.

    Completed script processing.

    *******************

    Finished! Terminate.

    Then, the Hijack This log:


    Logfile of HijackThis v1.99.1
    Scan saved at 12:20:17 PM, on 2/23/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16414)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
    C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\parentalcontrol\parentalcontrol.exe
    C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\MsnMsgr.Exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    C:\Program Files\LimeWire\LimeWire.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\HPQ\SHARED\HPQWMI.exe
    C:\Documents and Settings\Andrea Quintal\Desktop\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Parental Control Toolbar - {4E7BD74F-2B8D-469E-9FA5-A33DE8DBE931} - C:\PROGRA~1\PARENT~1\PARENT~1.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
    O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
    O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
    O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
    O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
    O4 - HKLM\..\Run: [EPSON Stylus CX3500 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9BL.EXE /P26 "EPSON Stylus CX3500 Series" /O6 "USB001" /M "Stylus CX3500"
    O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [parentalcontrol] "C:\Program Files\parentalcontrol\parentalcontrol.exe" "C:\Program Files\parentalcontrol\parentalcontrol.dll" "parentalcontrol"
    O4 - HKLM\..\Run: [EPSON Stylus C67 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIAAL.EXE /P23 "EPSON Stylus C67 Series" /O6 "USB002" /M "Stylus C67"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
    O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
    O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
    O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O11 - Options group: [INTERNATIONAL] International*
    O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q405&bd=pavilion&pf=laptop
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab31267.cab
    O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://andreamonitaa-z.spaces.msn.com//PhotoUpload/MsnPUpld.cab
    O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
    O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
    O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Unknown owner - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe (file missing)
    O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe

    Thanks again.

    Rulito
     
  8. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    You're welcome. How are things now?
     
  9. rulito

    rulito Thread Starter

    Joined:
    Feb 17, 2007
    Messages:
    11
  10. Cheeseball81

    Cheeseball81 Retired Moderator

    Joined:
    Mar 3, 2004
    Messages:
    84,315
    Now turn off System Restore:

    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    Restart your computer.

    Turn System Restore back on and create a restore point.

    To create a restore point:

    Single-click Start and point to All Programs.
    Mouse over Accessories, then System Tools, and select System Restore.
    In the System Restore wizard, select the box next the text labeled "Create a restore point" and click the Next button.
    Type a description for your new restore point. Something like "After trojan/spyware cleanup". Click Create and you're done.

    You can mark your thread "Solved" from the Thread Tools drop down menu.
     
  11. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/544836

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice