1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Solved: Ultimate Defender Problem

Discussion in 'Virus & Other Malware Removal' started by EHCCenjin, Jul 7, 2007.

Thread Status:
Not open for further replies.
Advertisement
  1. EHCCenjin

    EHCCenjin Thread Starter

    Joined:
    Jul 7, 2007
    Messages:
    5
    The whole deal started yesterday.......It was worst when I first got it being that windows opened like every minute or so or some "warning" popped up saying to click ok to install the program of course I hit cancel or X.....It even kept putting up a Webpage on my desktop which I deleted many times but It kept popping back up........Well I toned the problems down but it still keeps coming up with the fake warnings and opening a internet explorer window everyonce in a while and my computer has these little 1 to 2 second freezes.....I installed SPyware Doctor and SpyHunter......Both of these were reccomended on a Removal site......I ran a virus scan and used a registry cleaner yet it keeps showing up with the warning......Can anyone tell me what I can do to get rid of this annoyance
     
  2. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, EHCCenjin.:)

    Welcome to TSG.

    Click here to download HJTInstall.exe
    • Save HJTInstall.exe to your desktop.
    • Doubleclick on the HJTInstall.exe icon on your desktop.
    • By default it will install to C:\Program Files\Trend Micro\HijackThis .
    • Click on Install.
    • It will create a HijackThis icon on the desktop.
    • Once installed, it will launch Hijackthis.
    • Click on the Do a system scan and save a logfile button. It will scan and the log should open in notepad.
    • Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log.
    • Come back here to this thread and Paste the log in your next reply.
    • DO NOT have Hijackthis fix anything yet. Most of what it finds will be harmless or even required.
     
  3. EHCCenjin

    EHCCenjin Thread Starter

    Joined:
    Jul 7, 2007
    Messages:
    5
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 12:56:09 AM, on 7/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\WINDOWS\arservice.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
    C:\Program Files\Spyware Doctor\svcntaux.exe
    C:\Program Files\Spyware Doctor\swdsvc.exe
    C:\Program Files\Spyware Doctor\SDTrayApp.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\ehome\mcrdsvc.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\System32\alg.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Common Files\AOL\1164250849\ee\AOLSoftware.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
    C:\Program Files\Trillian\trillian.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\WINDOWS\system32\cidaemon.exe
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    C:\WINDOWS\system32\wbem\wmiprvse.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q106&bd=presario&pf=desktop
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q106&bd=presario&pf=desktop
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1164250849\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [SDTray] "C:\Program Files\Spyware Doctor\SDTrayApp.exe"
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKCU\..\RunOnce: [gi883907214] "C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\giS7HTB3.exe" /resume:"C:\DOCUME~1\COMPAQ~1\LOCALS~1\Temp\2LS7HO37" /exename:"C:\Documents and Settings\Compaq_Administrator\My Documents\spyhunterS.exe"
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Startup: .protected
    O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
    O4 - Global Startup: .protected
    O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZS
    O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/Coupons.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O21 - SSODL: msdde - {C73EA7AF-A3B6-45CE-B1B4-EA039D08FFB1} - C:\WINDOWS\msdde.dll
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 9820 bytes
     
  4. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, EHCCenjin. :)

    Please download SmitfraudFix (by S!Ri) to your Desktop.

    Note: In the event you already have SmitfraudFix, this is a new version that I need you to download.

    [​IMG]Please download ATF Cleaner by Atribune.
    This program is for XP and Windows 2000 only

    • Double-click ATF-Cleaner.exe to run the program.
      Under Main choose: Select All
      Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
      Click the Empty Selected button.
      NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main menu to close the program.
    For Technical Support, double-click the e-mail address located at the bottom of each menu.

    [​IMG] Download AVG Anti-Spyware from HERE and save that file to your desktop.
    This is a 30 day trial of the program
    1. Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
    2. Once the setup is complete you will need run AVG Anti-Spyware and update the definition files.
    3. On the main screen select the icon "Update" then select the "Update now" link.
      • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
    4. Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
    5. Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
    6. Under "Reports"
      • Select "Automatically generate report after every scan"
      • Un-Select "Only if threats were found"
    Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly


    Now copy these instructions to notepad and save them to your desktop. You will need them to refer to in safe mode.

    Boot into Safe Mode:

    Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

    Perform the following steps in safe mode:


    1. IMPORTANT: Do not open any other windows or programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
    2. Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
    3. Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
    4. AVG Anti-Spyware will now begin the scanning process, be patient this may take a little time.
      Once the scan is complete do the following:
    5. If you have any infections you will prompted, then select "Apply all actions"
    6. Next select the "Reports" icon at the top.
    7. Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your system (make sure to remember where you saved that file, this is important).
    8. Close AVG Anti-Spyware .
    While in Safe Mode, double-click on SmitfraudFix.exe

    **If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

    Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

    You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

    The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

    The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
    A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
    The report can also be found at the root of the system drive, usually at C:\rapport.txt

    * Go to Control Panel > Internet Options. Click on the Programs tab, then click the "Reset Web Settings" button. Click Apply then OK.

    * Next go to Control Panel > Display. Click on the "Desktop" tab then click the "Customize Desktop" button. Click on the "Web" tab. Under "Web Pages" Delete everything except for "My Current Home Page". Click OK then Apply and OK.

    Please go HERE to run Panda's ActiveScan
    • Once you are on the Panda site click the Scan your PC button
    • A new window will open...click the Check Now button
    • Enter your Country
    • Enter your State/Province
    • Enter your e-mail address and click send
    • Select either Home User or Company
    • Click the big Scan Now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • When download is complete, click on My Computer to start the scan
    • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
    Post a fresh Hijackthis log along with the AVG Anti-spyware report, ActiveScan report and contents of C:\rapport.txt produced by Smitfraudfix.
     
  5. EHCCenjin

    EHCCenjin Thread Starter

    Joined:
    Jul 7, 2007
    Messages:
    5
    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:45:23 PM, on 7/7/2007
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16473)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\Ati2evxx.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    C:\WINDOWS\arservice.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\eHome\ehRecvr.exe
    C:\WINDOWS\eHome\ehSched.exe
    C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
    C:\Program Files\Common Files\AOL\1164250849\ee\AOLSoftware.exe
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\MySpace\IM\MySpaceIM.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
    C:\Program Files\Trillian\trillian.exe
    C:\WINDOWS\eHome\ehmsas.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\NOTEPAD.EXE
    C:\Program Files\Windows Media Player\wmplayer.exe
    C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
    O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: PBlockHelper Class - {4115122B-85FF-4DD3-9515-F075BEDE5EB5} - C:\PROGRA~1\NETSCA~1\NETSCA~1\pbhelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1164250849\ee\AOLSoftware.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [IMEKRMIG6.1] C:\WINDOWS\ime\imkr6_1\IMEKRMIG.EXE
    O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKLM\..\Run: [SpyHunter] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
    O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
    O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
    O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
    O4 - Global Startup: WG111v2 Smart Wizard Wireless Setting.lnk = ?
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZS
    O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_05\bin\npjpi150_05.dll
    O9 - Extra button: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra 'Tools' menuitem: AOL Toolbar - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra 'Tools' menuitem: Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4056/ftp.coupons.com/r3302/Coupons.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
    O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
    O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
    O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Netscape Update Service (NCUpdateSvc) - Netscape Communications Corporation - C:\Program Files\Netscape Internet Service\ncupdatesvc.exe
    O23 - Service: Spyware Doctor Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\svcntaux.exe
    O23 - Service: Spyware Doctor Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

    --
    End of file - 8478 bytes

    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 5:28:54 PM 7/7/2007

    + Scan result:



    C:\WINDOWS\main_uninstaller.exe -> Adware.Agent : Cleaned.
    C:\WINDOWS\system32\1164240731.exe -> Adware.BHO : Cleaned.
    C:\Program Files\Enigma Software Group\SpyHunter\Backup\cpbrkpie.ocx.dat/WINDOWS/cpbrkpie.ocx -> Adware.Coupons : Cleaned.
    C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP416\A0132959.ocx -> Adware.Coupons : Cleaned.
    C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned.
    C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter.exe.BAK -> Adware.SpyHunter : Cleaned.
    :mozilla.129:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.130:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.131:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.132:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.256:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
    :mozilla.64:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.65:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.66:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.67:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.68:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.69:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.70:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.50:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.51:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.52:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.53:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.54:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.55:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.56:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.57:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.58:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.118:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    :mozilla.284:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.285:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.286:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.72:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
    :mozilla.291:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
    :mozilla.25:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.26:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.27:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.28:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.32:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.33:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.34:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.35:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.36:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.37:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.38:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.39:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.40:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.41:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
    :mozilla.217:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.218:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.219:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.220:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.221:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.222:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.223:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.258:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
    :mozilla.142:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.238:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.239:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.240:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.241:C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    C:\WINDOWS\NETVISION.exe -> Trojan.Dialer.rh : Cleaned.
    C:\WINDOWS\system32\1164871061.exe -> Trojan.VB.an : Cleaned.


    ::Report end


    Incident Status Location

    Adware:adware/24-7-search Not disinfected c:\windows\system32\unPPC.exe
    Adware:adware/oemji Not disinfected Windows Registry
    Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{9AFB8248-617F-460d-9366-D71CDEDA3179}
    Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt[.casalemedia.com/]
    Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Compaq_Administrator\Application Data\Mozilla\Firefox\Profiles\ygru5jcc.default\cookies.txt[.toplist.cz/]
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Administrator\Desktop\SmitfraudFix\Process.exe
    Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Compaq_Administrator\Desktop\SmitfraudFix\restart.exe
    Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Compaq_Administrator\SmitfraudFix\Process.exe
    Virus:Trj/Shutdown.Z Disinfected C:\Documents and Settings\Compaq_Administrator\SmitfraudFix\restart.exe
    Virus:Generic Malware Disinfected C:\Documents and Settings\Compaq_Administrator\SpyHunter.2.9\Patch After Upgarding\spyhunter.2.9_Patch2.exe
    Virus:Generic Malware Disinfected C:\Documents and Settings\Compaq_Administrator\SpyHunter.2.9\SpyHunter.2.9_Patch1.exe
    Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
    Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
     
  6. EHCCenjin

    EHCCenjin Thread Starter

    Joined:
    Jul 7, 2007
    Messages:
    5
    SmitFraudFix v2.200

    Scan done at 17:30:15.43, Sat 07/07/2007
    Run from C:\Documents and Settings\Compaq_Administrator\Desktop\SmitfraudFix
    OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
    The filesystem type is NTFS
    Fix run in safe mode

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll

    »»»»»»»»»»»»»»»»»»»»»»»» Killing process


    »»»»»»»»»»»»»»»»»»»»»»»» hosts

    127.0.0.1 localhost #***Inserted By STOPzilla***
    127.0.0.1 0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 2005-search.com # ***Inserted By STOPzilla***
    127.0.0.1 600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 83.149.105.142 # ***Inserted By STOPzilla***
    127.0.0.1 83.149.105.225 # ***Inserted By STOPzilla***
    127.0.0.1 85.255.117.170 # ***Inserted By STOPzilla***
    127.0.0.1 a1.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 absolutepics.net # ***Inserted By STOPzilla***
    127.0.0.1 ad.yieldmanager.com # ***Inserted By STOPzilla***
    127.0.0.1 alex.fileburst.com # ***Inserted By STOPzilla***
    127.0.0.1 all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 apps.deskwizz.com # ***Inserted By STOPzilla***
    127.0.0.1 awmdabest.com # ***Inserted By STOPzilla***
    127.0.0.1 bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 barteros.net # ***Inserted By STOPzilla***
    127.0.0.1 best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 best-targeted-traffic.com # ***Inserted By STOPzilla***
    127.0.0.1 bins.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 bn.i-ru.net # ***Inserted By STOPzilla***
    127.0.0.1 brazauskas.info # ***Inserted By STOPzilla***
    127.0.0.1 bundleware.com # ***Inserted By STOPzilla***
    127.0.0.1 burnsrecyclinginc.com # ***Inserted By STOPzilla***
    127.0.0.1 campaigns.interclick.com # ***Inserted By STOPzilla***
    127.0.0.1 centralgate.biz # ***Inserted By STOPzilla***
    127.0.0.1 clickfast.biz # ***Inserted By STOPzilla***
    127.0.0.1 code.jcash.biz # ***Inserted By STOPzilla***
    127.0.0.1 code.trasferimento.biz # ***Inserted By STOPzilla***
    127.0.0.1 command.adservs.com # ***Inserted By STOPzilla***
    127.0.0.1 content.dollarrevenue.com # ***Inserted By STOPzilla***
    127.0.0.1 content.exetraffic.com # ***Inserted By STOPzilla***
    127.0.0.1 content2.dollarrevenue.com # ***Inserted By STOPzilla***
    127.0.0.1 coolwebsearch.com # ***Inserted By STOPzilla***
    127.0.0.1 cumhereteens.com # ***Inserted By STOPzilla***
    127.0.0.1 cyber-search.biz # ***Inserted By STOPzilla***
    127.0.0.1 ddh24.com # ***Inserted By STOPzilla***
    127.0.0.1 dedmazai.com # ***Inserted By STOPzilla***
    127.0.0.1 dnv-counter.com # ***Inserted By STOPzilla***
    127.0.0.1 download.abetterinternet.com # ***Inserted By STOPzilla***
    127.0.0.1 download.accessmedia.tv # ***Inserted By STOPzilla***
    127.0.0.1 download.jupitersatellites.biz # ***Inserted By STOPzilla***
    127.0.0.1 exeloads.info # ***Inserted By STOPzilla***
    127.0.0.1 faccesborrate.com # ***Inserted By STOPzilla***
    127.0.0.1 flavinha.com # ***Inserted By STOPzilla***
    127.0.0.1 forlink.biz # ***Inserted By STOPzilla***
    127.0.0.1 freevideo24.com # ***Inserted By STOPzilla***
    127.0.0.1 fullbizzone.com # ***Inserted By STOPzilla***
    127.0.0.1 game4all.biz # ***Inserted By STOPzilla***
    127.0.0.1 get-access.host.sk # ***Inserted By STOPzilla***
    127.0.0.1 go-pic.com # ***Inserted By STOPzilla***
    127.0.0.1 granjerascachondas.com # ***Inserted By STOPzilla***
    127.0.0.1 greatgoodsex.com # ***Inserted By STOPzilla***
    127.0.0.1 heretofind.com # ***Inserted By STOPzilla***
    127.0.0.1 hqthumbz.com # ***Inserted By STOPzilla***
    127.0.0.1 it.online-more.com # ***Inserted By STOPzilla***
    127.0.0.1 its.justcount.net # ***Inserted By STOPzilla***
    127.0.0.1 krovalidajop.com # ***Inserted By STOPzilla***
    127.0.0.1 l.mezzicodec.net # ***Inserted By STOPzilla***
    127.0.0.1 lust-mature.com # ***Inserted By STOPzilla***
    127.0.0.1 mikos.paraisoasiatico.com # ***Inserted By STOPzilla***
    127.0.0.1 mmm.elitemediagroup.net # ***Inserted By STOPzilla***
    127.0.0.1 more-pages.com # ***Inserted By STOPzilla***
    127.0.0.1 morteen.net # ***Inserted By STOPzilla***
    127.0.0.1 moviecsodecs.com # ***Inserted By STOPzilla***
    127.0.0.1 ms-counter.com # ***Inserted By STOPzilla***
    127.0.0.1 msmn.com # ***Inserted By STOPzilla***
    127.0.0.1 musah.info # ***Inserted By STOPzilla***
    127.0.0.1 netincap.com # ***Inserted By STOPzilla***
    127.0.0.1 newsh.com # ***Inserted By STOPzilla***
    127.0.0.1 niuqennaois.com # ***Inserted By STOPzilla***
    127.0.0.1 nnew-adult.info # ***Inserted By STOPzilla***
    127.0.0.1 nude-teen-bodies.com # ***Inserted By STOPzilla***
    127.0.0.1 onlyhotlinks.com # ***Inserted By STOPzilla***
    127.0.0.1 on-search.com # ***Inserted By STOPzilla***
    127.0.0.1 picshunter.us # ***Inserted By STOPzilla***
    127.0.0.1 picslab.com # ***Inserted By STOPzilla***
    127.0.0.1 prevedtraf.biz # ***Inserted By STOPzilla***
    127.0.0.1 promo.dollarrevenue.com # ***Inserted By STOPzilla***
    127.0.0.1 redirect.msupdate.net # ***Inserted By STOPzilla***
    127.0.0.1 rogalik.net # ***Inserted By STOPzilla***
    127.0.0.1 search4www.com # ***Inserted By STOPzilla***
    127.0.0.1 search-biz.biz # ***Inserted By STOPzilla***
    127.0.0.1 searchforit.com # ***Inserted By STOPzilla***
    127.0.0.1 searchx.cc # ***Inserted By STOPzilla***
    127.0.0.1 sex-pics.biz # ***Inserted By STOPzilla***
    127.0.0.1 sexyfaceplace.com # ***Inserted By STOPzilla***
    127.0.0.1 snow410.info # ***Inserted By STOPzilla***
    127.0.0.1 software.topinstalls.com # ***Inserted By STOPzilla***
    127.0.0.1 sp2admin.biz # ***Inserted By STOPzilla***
    127.0.0.1 surubanet.com # ***Inserted By STOPzilla***
    127.0.0.1 teadis.net # ***Inserted By STOPzilla***
    127.0.0.1 teen-biz.com # ***Inserted By STOPzilla***
    127.0.0.1 teen-fantazi.com # ***Inserted By STOPzilla***
    127.0.0.1 teenygirlshome.com # ***Inserted By STOPzilla***
    127.0.0.1 traff5all.biz # ***Inserted By STOPzilla***
    127.0.0.1 traffbest.biz # ***Inserted By STOPzilla***
    127.0.0.1 traffbucks.biz # ***Inserted By STOPzilla***
    127.0.0.1 traffmoney.biz # ***Inserted By STOPzilla***
    127.0.0.1 ukstories.net # ***Inserted By STOPzilla***
    127.0.0.1 ultra-search.biz # ***Inserted By STOPzilla***
    127.0.0.1 uniq-soft.com # ***Inserted By STOPzilla***
    127.0.0.1 vivisexy.com # ***Inserted By STOPzilla***
    127.0.0.1 wearehosters.com # ***Inserted By STOPzilla***
    127.0.0.1 www.0websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 www.600pics.com # ***Inserted By STOPzilla***
    127.0.0.1 www.abetterstart.com # ***Inserted By STOPzilla***
    127.0.0.1 www.all-tgp.org # ***Inserted By STOPzilla***
    127.0.0.1 www.all-websearch.com # ***Inserted By STOPzilla***
    127.0.0.1 www.axmediaproject.com # ***Inserted By STOPzilla***
    127.0.0.1 www.bailefunk.com # ***Inserted By STOPzilla***
    127.0.0.1 www.best4all.net # ***Inserted By STOPzilla***
    127.0.0.1 www.besthardcore.net # ***Inserted By STOPzilla***
    127.0.0.1 www.bundleware.com # ***Inserted By STOPzilla***
    127.0.0.1 www.burnsrecyclinginc.com # ***Inserted By STOPzilla***
    127.0.0.1 www.coolwebsearch.com # ***Inserted By STOPzilla***
    127.0.0.1 www.dedmazai.com # ***Inserted By STOPzilla***
    127.0.0.1 www.flavinha.com # ***Inserted By STOPzilla***
    127.0.0.1 www.granjerascachondas.com # ***Inserted By STOPzilla***
    127.0.0.1 www.heretofind.com # ***Inserted By STOPzilla***
    127.0.0.1 www.hqthumbz.com # ***Inserted By STOPzilla***
    127.0.0.1 www.jtreeproperties.com # ***Inserted By STOPzilla***
    127.0.0.1 www.lattefresco.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.lust-mature.com # ***Inserted By STOPzilla***
    127.0.0.1 www.mikos.paraisoasiatico.com # ***Inserted By STOPzilla***
    127.0.0.1 www.more-pages.com # ***Inserted By STOPzilla***
    127.0.0.1 www.msmn.com # ***Inserted By STOPzilla***
    127.0.0.1 www.msnwm.com # ***Inserted By STOPzilla***
    127.0.0.1 www.newsh.com # ***Inserted By STOPzilla***
    127.0.0.1 www.nude-teens-bodies.com # ***Inserted By STOPzilla***
    127.0.0.1 www.onli-ne.com # ***Inserted By STOPzilla***
    127.0.0.1 www.onlyhotlinks.com # ***Inserted By STOPzilla***
    127.0.0.1 www.on-search.com # ***Inserted By STOPzilla***
    127.0.0.1 www.picshunter.us # ***Inserted By STOPzilla***
    127.0.0.1 www.picslab.com # ***Inserted By STOPzilla***
    127.0.0.1 www.procounter.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.search4www.com # ***Inserted By STOPzilla***
    127.0.0.1 www.searchforit.com # ***Inserted By STOPzilla***
    127.0.0.1 www.searchx.cc # ***Inserted By STOPzilla***
    127.0.0.1 www.sex-pics.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.sp2admin.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.spamcatchero.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.surubanet.com # ***Inserted By STOPzilla***
    127.0.0.1 www.teen-biz.com # ***Inserted By STOPzilla***
    127.0.0.1 www.teen-fantazi.com # ***Inserted By STOPzilla***
    127.0.0.1 www.teenygirlshome.com # ***Inserted By STOPzilla***
    127.0.0.1 www.traff4ppc.biz # ***Inserted By STOPzilla***
    127.0.0.1 www.ufixer.com # ***Inserted By STOPzilla***
    127.0.0.1 www.vivisexy.com # ***Inserted By STOPzilla***
    127.0.0.1 www.voghp.com # ***Inserted By STOPzilla***
    127.0.0.1 www.wearehosters.com # ***Inserted By STOPzilla***
    127.0.0.1 www.ysbweb.com # ***Inserted By STOPzilla***
    127.0.0.1 www.zgallery.us # ***Inserted By STOPzilla***
    127.0.0.1 www.zonebest.com # ***Inserted By STOPzilla***
    127.0.0.1 ybbwxlxytz.biz # ***Inserted By STOPzilla***
    127.0.0.1 yepjnddqpq.biz # ***Inserted By STOPzilla***
    127.0.0.1 yhvoo.eseconsult.info # ***Inserted By STOPzilla***
    127.0.0.1 yougoodheer.com # ***Inserted By STOPzilla***
    127.0.0.1 ysbweb.com # ***Inserted By STOPzilla***
    127.0.0.1 z-advertise.com # ***Inserted By STOPzilla***
    127.0.0.1 zchxsikpgz.biz # ***Inserted By STOPzilla***
    127.0.0.1 zgallery.us # ***Inserted By STOPzilla***
    127.0.0.1 zonebest.com # ***Inserted By STOPzilla***

    »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

    GenericRenosFix by S!Ri


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

    C:\WINDOWS\.protected Deleted
    C:\WINDOWS\msdde.dll Deleted
    C:\WINDOWS\privacy_danger\ Deleted
    C:\DOCUME~1\COMPAQ~1\STARTM~1\Programs\Startup\.protected Deleted
    C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\Startup\.protected Deleted
    C:\DOCUME~1\COMPAQ~1\Desktop\Error Cleaner.url Deleted
    C:\DOCUME~1\COMPAQ~1\Desktop\Privacy Protector.url Deleted
    C:\DOCUME~1\COMPAQ~1\Desktop\Spyware?Malware Protection.url Deleted

    »»»»»»»»»»»»»»»»»»»»»»»» DNS

    HKLM\SYSTEM\CCS\Services\Tcpip\..\{81C18F8D-3810-4B03-9EA2-8D9A59B0A526}: DhcpNameServer=24.93.41.125 24.93.41.126
    HKLM\SYSTEM\CS1\Services\Tcpip\..\{81C18F8D-3810-4B03-9EA2-8D9A59B0A526}: DhcpNameServer=24.93.41.125 24.93.41.126
    HKLM\SYSTEM\CS3\Services\Tcpip\..\{81C18F8D-3810-4B03-9EA2-8D9A59B0A526}: DhcpNameServer=24.93.41.125 24.93.41.126
    HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=24.93.41.125 24.93.41.126
    HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=24.93.41.125 24.93.41.126
    HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=24.93.41.125 24.93.41.126


    »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


    »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
    !!!Attention, following keys are not inevitably infected!!!

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


    »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

    Registry Cleaning done.

    »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
    !!!Attention, following keys are not inevitably infected!!!

    SrchSTS.exe by S!Ri
    Search SharedTaskScheduler's .dll


    »»»»»»»»»»»»»»»»»»»»»»»» End
     
  7. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, EHCCenjin :)

    Please download the OTMoveIt by OldTimer.
    • Save it to your desktop.

    Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...rch.jhtml?p=ZS
    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/40...02/Coupons.cab


    Now close all windows and browsers, other than HiJackThis, then click Fix Checked.

    Close Hijackthis.
    • Please double-click OTMoveIt.exe to run it.
    • Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

      c:\windows\system32\unPPC.exe

    • Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
    • Click the red Moveit! button.
      • If able, copy everything on the Results window to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it on a note pad document. Save it on the desktop and post its contents in your next reply.
    • Close OTMoveIt
    If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

    The rest looks clear. How is the computer doing?
     
  8. EHCCenjin

    EHCCenjin Thread Starter

    Joined:
    Jul 7, 2007
    Messages:
    5
    c:\windows\system32\unPPC.exe moved successfully.

    Created on 07/09/2007 10:37:25

    Its doing much better......Theres no more warning windows.......Everything seems clearer and it doesnt freeze up anymore
     
  9. JSntgRvr

    JSntgRvr Retired Moderator and Malware Specialist

    Joined:
    Jul 1, 2003
    Messages:
    18,552
    First Name:
    José
    Hi, EHCCenjin. :)

    Congratulations.[​IMG]

    Since the tools we used to scan the computer, as well as tools to delete files and folders, are no longer needed, they should be removed, as well as the folders created by these tools.

    Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programmes changing them. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

    To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account.

    (Windows XP)

    1. Turn off System Restore.
    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    Check Turn off System Restore.
    Click Apply, and then click OK.

    2. Reboot.

    3. Turn ON System Restore.

    On the Desktop, right-click My Computer.
    Click Properties.
    Click the System Restore tab.
    UN-Check *Turn off System Restore*.
    Click Apply, and then click OK..

    Create a Restore point:
    1. Click Start, point to All Programs, point to Accessories, point to System Tools, and then click System Restore.
    2. In the System Restore dialog box, click Create a restore point, and then click Next.
    3. Type a description for your restore point, such as "After Cleanup", then click Create.

    The following is a list of tools and utilities that I like to suggest to people. This list is full of great tools and utilities to help you understand how you got infected and how to keep from getting infected again.
    1. Spybot Search & Destroy - Uber powerful tool which can search and annhilate nasties that make it onto your system. Now with an Immunize section that will help prevent future infections.
    2. AdAware - Another very powerful tool which searches and kills nasties that infect your system. AdAware and Spybot Search & Destroy compliment each other very well.
    3. SpywareBlaster - Great prevention tool to keep nasties from installing on your system.
    4. IE-SpyAd - puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
    5. CleanUP! - Cleans temporary files from IE and Windows, empties the recycle bin and more. Great tool to help speed up your computer and knock out those nasties that like to reside in the temp folders.
    6. Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
    7. Google Toolbar - Free google toolbar that allows you to use the powerful Google search engine from the bar, but also blocks pop up windows.
    8. Trillian or Miranda-IM - These are Malware free Instant Messenger programs which allow you to connect to multiple IM services in one program! (AOL, Yahoo, ICQ, IRC, MSN)

    To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

    Click Here for some advise from our security Experts.

    Please use the thread's Tools and mark this thread as "Solved".

    Best wishes! [​IMG]
     
  10. Sponsor

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/592717

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice