Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

something is wrong with my pc

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

something is wrong with my pc

Unread postby rbg77 » May 31st, 2006, 3:55 pm

hey im pretty new here and thought that i would give the malware removal forums a try. my problem is that my icons and taskbar keep dissappearing and i can only see them again once i am in safe mode. can anyone help me with my problem?

here is my hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:58:36 AM, on 5/31/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\AlfaCleaner\ACServer.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\PROGRA~1\WINZIP\wzqkpick.exe
C:\Documents and Settings\P DiZzLe x19\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcps.k12.md.us/schools/churchillhs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {599BCB53-B55B-43A1-9465-8C327AB8DCFA} - C:\WINDOWS\system32\pmkhf.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135479603\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [intell321.exe] C:\WINDOWS\system32\intell321.exe
O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe
O4 - HKLM\..\Run: [Intec Service Drivers] winfix32.exe
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\PDIZZL~1\LOCALS~1\Temp\2006531103327_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunServices: [Intec Service Drivers] winfix32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [freestyle] rBot.exe
O4 - HKCU\..\Run: [Intec Service Drivers] winfix32.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\RunServices: [Intec Service Drivers] winfix32.exe
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesu ... .0.4.4.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Seekmo/ ... 54b810aed3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: pmkhf - C:\WINDOWS\system32\pmkhf.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AlfaCleanerService - AlfaCleaner.com - C:\Program Files\AlfaCleaner\ACServer.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GPSVC - Unknown owner - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe" "WUSB54GP.exe (file missing)
rbg77
Active Member
 
Posts: 3
Joined: May 31st, 2006, 3:50 pm
Advertisement
Register to Remove

Unread postby agrarianmonk » May 31st, 2006, 4:34 pm

It looks like you have been infected by variety of backdoor trojans.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found here

I suggest you do the following immediately:

1. Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.

2. From a clean computer, change *all* your online passwords -- for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.

Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.


If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can definitely help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

****************************

If you decide to clean your computer, please follow these instructions:

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc...processutil.htm

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Put a check next to Run VundoFix as a task.
  • You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
  • When VundoFix re-opens, click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.

in your next post, please include
  • smitfraudfix log
  • C:\vundofix.txt
  • uninstall list
  • new hijackthis log
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby rbg77 » June 5th, 2006, 5:23 pm

thank you for your help, and i have decided to just clean my pc rather than reformatting.

as requested, heres the smitfraudfix log:

SmitFraudFix v2.53

Scan done at 14:28:40.50, Mon 06/05/2006
Run from C:\Documents and Settings\P DiZzLe x19\Desktop\smitfraudfix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS

C:\WINDOWS\keyboard??.exe FOUND !
C:\WINDOWS\uninstDsk.exe FOUND !
C:\WINDOWS\warnhp.html FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\intell321.exe FOUND !
C:\WINDOWS\system32\oleext.dll FOUND !
C:\WINDOWS\system32\drivers\hesvc.sys FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\P DiZzLe x19\Application Data

C:\Documents and Settings\LocalService\Application Data\AlfaCleaner FOUND !
C:\Documents and Settings\P DiZzLe x19\Application Data\AlfaCleaner FOUND !
C:\Documents and Settings\P DiZzLe x19\Application Data\Skinux FOUND !
C:\Documents and Settings\P DiZzLe x19\Application Data\Microsoft\Internet Explorer\Quick Launch\AlfaCleaner.lnk FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Programs\AlfaCleaner FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\PDIZZL~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\AlfaCleaner\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\WINDOWS\\warnhp.html"
"SubscribedURL"=""
"FriendlyName"="Desktop Uninstall"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


heres the vundofix txt file:

VundoFix V4.2.76

Running as SYSTEM
from c:\windows\system32\VundoFix.exe

Checking Java version...

Java version is 1.4.2.3

Scan started at 2:35:38 PM 6/5/2006

Listing files found while scanning....


C:\WINDOWS\system32\fhkmp.bak1
C:\WINDOWS\system32\fhkmp.bak2
C:\WINDOWS\system32\fhkmp.tmp
C:\WINDOWS\system32\fhkmp.ini
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\fhkmp.bak2
C:\WINDOWS\system32\fhkmp.tmp
C:\WINDOWS\system32\fhkmp.ini
C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\pmkhf.dll
Attempting to delete C:\WINDOWS\system32\fhkmp.bak1
C:\WINDOWS\system32\fhkmp.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhkmp.bak2
C:\WINDOWS\system32\fhkmp.bak2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhkmp.tmp
C:\WINDOWS\system32\fhkmp.tmp Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhkmp.ini
C:\WINDOWS\system32\fhkmp.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\fhkmp.ini2
C:\WINDOWS\system32\fhkmp.ini2 Has been deleted!

Attempting to delete C:\WINDOWS\system32\pmkhf.dll
C:\WINDOWS\system32\pmkhf.dll Has been deleted!

Performing Repairs to the registry.
Done!

the uninstall list:

Adobe Acrobat - Reader 6.0.2 Update
Adobe Reader 6.0.1
AlfaCleaner.com
ALPS Touch Pad Driver
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Connectivity Services
AOL Instant Messenger
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
ATI Control Panel
ATI Display Driver
Broadcom Management Programs 2
Conexant D110 MDC V.9x Modem
CoreVorbis Audio Decoder (remove only)
Counter-Strike: Source
Dell Digital Jukebox Driver
Dell Photo Printer 720
Dell Photo Printer 720 Logger
Dell Support 3.1
Desktop Uninstall
Digital Content Portal
Digital Line Detect
EarthLink setup files
EducateU
ESPNMotion
GemMaster Mystic
HijackThis 1.99.1
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Intel(R) PROSet/Wireless Software
InterActual Player
Internal Network Card Power Management
Internet Explorer Default Page
iTunes
Java 2 Runtime Environment, SE v1.4.2_03
Learn2 Player (Uninstall Only)
Lecteur Windows Media 11
LimeWire 4.10.3
Macromedia Flash Player
Macromedia Flash Player 8
Macromedia Shockwave Player
McAfee Uninstaller
mCore
MCU
mDrWiFi
mHlpDell
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft Office Basic Edition 2003
Microsoft Office PowerPoint Viewer 2003
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)
mIWA
mIWCA
mLogView
mMHouse
Modem Helper
Mozilla Firefox (1.5.0.4)
mPfMgr
mPfWiz
mProSafe
MSN Messenger 7.5
mSSO
mToolkit
Musicmatch for Windows Media Player
Musicmatch® Jukebox
mWlsSafe
mXML
MyWay Search Assistant
mZConfig
NetWaiting
NetZeroInstallers
Otto
PowerDVD 5.5
QuickBooks Simple Start Special Edition
QuickSet
QuickTime
RealPlayer Basic
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Sonic DLA
Sonic Encoders
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SP2 Connection Patcher
Steam(TM)
The Weather Channel Desktop
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update Rollup 2 for Windows XP Media Center Edition 2005
Viewpoint Media Player
Weather Services
WebCyberCoach 3.2 Dell
WildTangent Web Driver
Windows Installer 3.1 (KB893803)
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 10
Windows Media Player 10 Hotfix - KB895316
Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information]
Windows Media Player 11
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890927
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB908250
WinZip
Wireless-G Portable USB Adapter
Yahoo! Toolbar for Internet Explorer

new hijack this log

Logfile of HijackThis v1.99.1
Scan saved at 4:15:05 PM, on 6/5/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\AlfaCleaner\ACServer.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\P DiZzLe x19\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mcps.k12.md.us/schools/churchillhs/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6ED948C2-486B-4FBC-997A-D649D6D8FEBB} - C:\WINDOWS\system32\pmkhf.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135479603\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [intell321.exe] C:\WINDOWS\system32\intell321.exe
O4 - HKLM\..\Run: [AlfaCleaner] C:\Program Files\AlfaCleaner\AlfaCleaner.exe
O4 - HKLM\..\Run: [Intec Service Drivers] winfix32.exe
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\PDIZZL~1\LOCALS~1\Temp\2006531103327_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunServices: [Intec Service Drivers] winfix32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [freestyle] rBot.exe
O4 - HKCU\..\Run: [Intec Service Drivers] winfix32.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\RunServices: [Intec Service Drivers] winfix32.exe
O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINDOWS\inf\unregmp2.exe /Fixups
O4 - Startup: LimeWire On Startup.lnk = C:\Program Files\LimeWire\LimeWire.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlmanager.akamaitools.com.edgesu ... .0.4.4.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Seekmo/ ... 54b810aed3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AlfaCleanerService - AlfaCleaner.com - C:\Program Files\AlfaCleaner\ACServer.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GPSVC - Unknown owner - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe" "WUSB54GP.exe (file missing)
rbg77
Active Member
 
Posts: 3
Joined: May 31st, 2006, 3:50 pm

Unread postby agrarianmonk » June 5th, 2006, 6:39 pm

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Please remove these entries from Add/Remove Programs in the Control Panel(if present):

Alfacleaner.com

Please note any other programs that you dont recognize in that list in your next response


Please download the trial version of Ewido anti-malware 3.5 from here:
http://www.ewido.net/en/download/
  • Install Ewido anti-malware.
  • When installing, under Additional Options uncheck Install background guard and Install scan via context menu.
  • When you run Ewido for the first time, you could get a warning "Database could not be found!". Click Ok.
  • The program will prompt you to update. Click the Ok button.
  • The program will now go to the main screen.
You will need to update Ewido to the latest definition files.
  • On the left-hand side of the main screen click the Update Button.
  • Click on Start.
The update will start and a progress bar will show the updates being installed.
Once finished updating, close Ewido.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates. Make sure to close Ewido before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Open the SmitfraudFix Folder, then double-click smitfraudfix.cmd file to start the tool.
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan.
  • Click on Scanner
  • Click on Settings
    • Under How to scan all boxes should be checked
    • Under Unwanted Software all boxes should be checked
    • Under What to scan select Scan every file
    • Click on Ok
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
If Ewido finds anything, it will pop up a notification. When it asks if you want to clean the first file, put a checkmark in the lower left corner of the box that says Perform action on all infections and put a checkmark in the box next to Create encrypted backup, then choose clean and click Ok.

Once the scan has completed, there will be a button located on the bottom of the screen named Save Report.
  • Click Save Report button
  • Save the report to your Desktop
Close Ewido and Reboot in Normal Mode.
______________________________

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter.
Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
______________________________


Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report


Please post:
  1. c:\rapport.txt
  2. Ewido log
  3. panda log
  4. A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

new logs

Unread postby rbg77 » June 12th, 2006, 10:32 pm

as requested, here is the rapport text:

SmitFraudFix v2.53

Scan done at 15:52:58.69, Tue 06/06/2006
Run from C:\Documents and Settings\P DiZzLe x19\Desktop\smitfraudfix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\keyboard??.exe Deleted
C:\WINDOWS\uninstDsk.exe Deleted
C:\WINDOWS\warnhp.html Deleted
C:\WINDOWS\system32\intell321.exe Deleted
C:\Documents and Settings\LocalService\Application Data\AlfaCleaner Deleted
C:\Documents and Settings\P DiZzLe x19\Application Data\AlfaCleaner\ Deleted
C:\Documents and Settings\P DiZzLe x19\Application Data\Skinux\ Deleted
C:\Program Files\AlfaCleaner\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri




»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End

the ewido log:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 4:37:16 PM, 6/6/2006
+ Report-Checksum: 5BA48069

+ Scan result:

:mozilla.6:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.7:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.8:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.10:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.13:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.14:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.21:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.92:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.94:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.95:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.96:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.97:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.103:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.104:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.105:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.106:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.107:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.108:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.109:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.110:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.112:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.113:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.114:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.115:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.116:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.117:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.118:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.119:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.122:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.123:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.124:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.126:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.127:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.128:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.130:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.131:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.132:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.133:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.134:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.135:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.136:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.137:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.153:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Estat : Cleaned with backup
:mozilla.181:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.183:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.184:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.185:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.186:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.187:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.188:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.189:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.190:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.209:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.210:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.211:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.213:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.214:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.215:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.216:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.217:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.218:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.219:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.220:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.229:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.230:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.234:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.238:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.239:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.240:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.249:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.250:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.251:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.252:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.253:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.272:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.273:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.274:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.275:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.278:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.279:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.284:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.285:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.286:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.291:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.292:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.293:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.294:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.300:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.301:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.302:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup
:mozilla.307:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.321:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.323:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Weborama : Cleaned with backup
:mozilla.330:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.331:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.332:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.333:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup
:mozilla.335:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.336:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.337:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.338:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.358:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.368:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.369:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.379:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup
:mozilla.393:C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@c5.zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@estat[1].txt -> TrackingCookie.Estat : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@trafic[1].txt -> TrackingCookie.Trafic : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\em3792\HbTools.mlpX -> Adware.HotBar : Cleaned with backup
C:\Documents and Settings\P DiZzLe x19\rose.out.exe -> Backdoor.Rbot : Cleaned with backup
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup
C:\WINDOWS\Temp\Cookies\p dizzle x19@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\WINDOWS\winfix32.exe -> Backdoor.Rbot : Cleaned with backup


::Report End


panda log
:


Incident Status Location

Hacktool:rootkit/fu.a Not disinfected hkey_local_machine\system\currentcontrolset\services\msdirectx
Adware:adware/dollarrevenue Not disinfected Windows Registry
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.xiti.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[as1.falkag.de/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Mozilla\Firefox\Profiles\quznjc4p.default\cookies.txt[.entrepreneur.com/]
Adware:Adware/PestTrap Not disinfected C:\Documents and Settings\P DiZzLe x19\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jar.jar-4732cb06-65b4f86f.zip[web.exe]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@247realmedia[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@2o7[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@2o7[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@ad.yieldmanager[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@ads.pointroll[1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@advertising[2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@as-us.falkag[2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@belnk[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@casalemedia[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@dist.belnk[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@doubleclick[1].txt
Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@entrepreneur[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@fastclick[1].txt
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@hitbox[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@media.fastclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@mediaplex[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@realmedia[2].txt
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@targetnet[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@tribalfusion[2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\P DiZzLe x19\Cookies\p dizzle x19@zedo[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@atwola[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@belnk[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\P DiZzLe x19\Local Settings\Temp\Cookies\p dizzle x19@dist.belnk[2].txt

new hijack this log
:

Logfile of HijackThis v1.99.1
Scan saved at 9:29:10 PM, on 6/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe
C:\Program Files\Wireless-G Portable USB Adapter\WUSB54GP.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\AIM\aim.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\P DiZzLe x19\Desktop\HijackThis.exe

R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6ED948C2-486B-4FBC-997A-D649D6D8FEBB} - C:\WINDOWS\system32\pmkhf.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135479603\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cleanup] C:\DOCUME~1\PDIZZL~1\LOCALS~1\Temp\2006531103327_mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [firewall32] C:\WINDOWS\firewall32.exe
O4 - HKLM\..\RunServices: [firewall32] C:\WINDOWS\firewall32.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\Common Files\AOL\Launch\AOLLaunch.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [freestyle] rBot.exe
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - HKCU\..\Run: [firewall32] C:\WINDOWS\firewall32.exe
O4 - HKCU\..\RunOnce: [MPlayer2_FixUp] C:\WINDOWS\inf\unregmp2.exe /Fixups
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) - http://miniclip.com/supergerball/miniclipGameLoader.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Seekmo/ ... 54b810aed3
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
O23 - Service: WUSB54GPSVC - Unknown owner - C:\Program Files\Wireless-G Portable USB Adapter\WLService.exe" "WUSB54GP.exe (file missing)
rbg77
Active Member
 
Posts: 3
Joined: May 31st, 2006, 3:50 pm

Unread postby agrarianmonk » June 15th, 2006, 1:03 pm

sorry for the delay:


Go to Start > Run
Type:
    regedit
Click OK.
  • On the leftside, click to highlight My Computer at the top.
  • Go up to "File > Export"
      Make sure in that window there is a tick next to "All" under Export Branch.
      Leave the "Save As Type" as "Registration Files".
      Under "Filename" put backup
  • Choose to save it to C:\ or somewhere else safe so that you will remember where you put it (don't put it on the desktop!)
  • Click save and then go to File > Exit.
This is so the registry can be restored to this point if we need it. It may take a minute. Just let it go until it's done.

**********************
  • Copy the contents of the Quote Box below to Notepad.
  • Name the file as fix.reg
  • Change the Save as Type to All Files
  • and Save it on the desktop


REGEDIT4

[-hkey_local_machine\system\currentcontrolset\services\msdirectx]



Make sure there are NO blank lines before REGEDIT4
Make sure there IS one blank line at the end of the file.

Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.

O2 - BHO: (no name) - {6ED948C2-486B-4FBC-997A-D649D6D8FEBB} - C:\WINDOWS\system32\pmkhf.dll (file missing)
O4 - HKLM\..\Run: [firewall32] C:\WINDOWS\firewall32.exe
O4 - HKLM\..\RunServices: [firewall32] C:\WINDOWS\firewall32.exe
O4 - HKCU\..\Run: [freestyle] rBot.exe
O4 - HKCU\..\Run: [firewall32] C:\WINDOWS\firewall32.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} (SAIX) - http://static.zangocash.com/cab/Seekmo/ ... 54b810aed3

Now close all windows other than HiJackThis, then click Fix Checked. close HijackThis.

Then double-click on the fix.reg file, and when it prompts to merge say yes, and this will clear some registry entries left behind by the process.

reboot.

***************************************

Next, we need to Reveal Hidden Files

1. Click Start.
2. Open My Computer.
3. Select Tools menu
4. Click Folder Options.
5. Select the View Tab.
6. Select Show hidden files and folders in the Hidden files and folders section.
7. Uncheck Hide protected operating system files (recommended) option.
8. Uncheck the Hide file extensions for known file types option.
9. Click Yes.
10. Click OK.

***************************************

Using Windows Explorer/My Computer, please delete the following files/folders if still present:

C:\WINDOWS\firewall32.exe

We need to do a search. Start | Search | For Files and Folders.
Expand Search Options, check Advanced Options, check Search system folders, Search hidden files and folders, and Search Subfolders.
Paste this into the Search for files and folders named box:

rBot.exe

If any of these files are found please delete them.

***************************************

reboot and post a new hijackthis log.

*Also please let me know how your computer is running at the moment and if any problems persist.
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby agrarianmonk » June 22nd, 2006, 7:45 pm

How are you doing with the instructions?
User avatar
agrarianmonk
MRU Teacher Emeritus
 
Posts: 5439
Joined: December 24th, 2005, 3:11 am

Unread postby NonSuch » July 1st, 2006, 2:21 pm

This topic is now closed due to inactivity. If you wish it reopened, please send us an email to 'admin at malwareremoval.com' with a link to your thread.

You can help support this site from this link :
Donations For Malware Removal

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
User avatar
NonSuch
Administrator
Administrator
 
Posts: 27226
Joined: February 23rd, 2005, 7:08 am
Location: California
Advertisement
Register to Remove


  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 70 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware