Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

my hijack this log file, thanks for your help

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 28th, 2009, 2:06 pm

Hi, thanks again, things seem a lot better! Google works OK now, instead of sending me to other sites.


It is my pleasure. We are almost done.


I am unsure which antivirus software I should have running when I am not running these logs and scans. Stopzilla comes on automatically and I have been turning it off.


You are doing a great job.



These files are infected and you need to to delete them:

D:\Documents and Settings\Caroline Dexter.049924520170\Desktop\HELLO E14\Fruitty Loops 4.5\Fruity Loops Studio 4.5.2 Producer Edition.iso
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Application Data\Microsoft\CD Burning\HELLO E14\Fruitty Loops 4.5\Fruity Loops Studio 4.5.2 Producer Edition.iso


Update Java Runtime and Run JavaRa


    Download Java Runtime
  • Go to HERE to download Java Runtime Environment Version 6 Update 13
  • Click on the link named Java Runtime Environment (JRE) 6 Update 13
  • Click on the radio button to Accept License Agreement
  • Click on Windows Offline Installation Multi-language and save the downloaded file to your desktop

    Run JavaRa
  • Please download JavaRa and unzip it to your desktop.
  • Double-click on JavaRa.exe to start the program.
  • From the drop-down menu, choose English and click on Select.
  • JavaRa will open; click on Remove Older Versions to remove the older versions of Java installed on your computer.
  • Click Yes when prompted. When JavaRa is done, a notice will appear that a logfile has been produced. Click OK.
  • A logfile will pop up. Please save it to a convenient location.

    Install Java
  • Install the new version of Java by running the newly-downloaded file ( jre-6u13-windows-i586-p.exe) with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer



Uninstall list

Make an uninstall list using HijackThis. To access the Uninstall Manager you would do the following:

  • Start HijackThis
  • Click on the Config button
  • Click on the Misc Tools button
  • Click on the Open Uninstall Manager button.
  • Click on the Save list... button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.


Logs/Information to Post in Next Reply

Please post the following logs/Information in your reply:
  • Javara Log
  • HijackThis Uninstall list
  • A fresh HijackThis Log ( after all the above has been done)
  • A description of how your computer is behaving
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK
Advertisement
Register to Remove

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 28th, 2009, 2:46 pm

I can't find local settings folder, it doesn't show up. Could it be somewhere else?

D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Application Data\Microsoft\CD Burning\HELLO E14\Fruitty Loops 4.5\Fruity Loops Studio 4.5.2 Producer Edition.iso
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 28th, 2009, 3:13 pm

JavaRa 1.14 Removal Log.

Report follows after line.

------------------------------------

The JavaRa removal process was started on Thu May 28 19:56:55 2009

Found and removed: Software\JavaSoft\Java2D\1.5.0_04

Found and removed: SOFTWARE\Classes\CLSID\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Classes\Installer\Features\8A0F842331866D117AB7000B0D510004

Found and removed: SOFTWARE\Classes\Installer\Products\8A0F842331866D117AB7000B0D510004

Found and removed: SOFTWARE\Classes\Installer\UpgradeCodes\7A0F842331866D117AB7000B0D510004

Found and removed: SOFTWARE\Classes\JavaPlugin.150_04

Found and removed: SOFTWARE\Classes\JavaWebStart.isInstalled.1.5.0.0

Found and removed: SOFTWARE\JavaSoft\Java Plug-in\1.5.0_04

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5

Found and removed: SOFTWARE\JavaSoft\Java Runtime Environment\1.5.0_04

Found and removed: SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\ACBB9B2318A96D117A58000B0D510004

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\8A0F842331866D117AB7000B0D510004

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{3248F0A8-6813-11D6-A77B-00B0D0150040}

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.5.0_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_02

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_03

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.0.1_04

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2

Found and removed: SOFTWARE\JavaSoft\Java Web Start\1.2.0_01

Found and removed: SOFTWARE\Microsoft\Active Setup\Installed Components\{08B0E5C0-4FCB-11CF-AAA5-00401C608500}

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\\C:\Program Files\Java\jre1.5.0_04\

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core1.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core2.zip

Found and removed: SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDlls\C:\Program Files\Common Files\Java\Update\Base Images\jre1.5.0.b64\core3.zip

------------------------------------

Finished reporting.


Hijack this uninstall list:
Ad-Aware
Ad-Aware
Adobe Flash Player 10 ActiveX
Adobe Reader 7.0
Apple Software Update
AVG Free 8.5
EndNote Web 2.6
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Player 10 (KB903157)
Hotfix for Windows XP (KB888795)
Hotfix for Windows XP (KB891593)
Hotfix for Windows XP (KB895961)
Hotfix for Windows XP (KB896256)
Hotfix for Windows XP (KB899337)
Hotfix for Windows XP (KB899510)
Hotfix for Windows XP (KB902841)
Hotfix for Windows XP (KB910728)
Hotfix for Windows XP (KB912024)
Hotfix for Windows XP (KB935448)
Hotfix for Windows XP (KB952287)
iTunes
Java(TM) 6 Update 13
LiveUpdate 3.0 (Symantec Corporation)
Macromedia Flash Player 8
Macromedia Shockwave Player
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft .NET Framework 2.0
Microsoft Office Professional Edition 2003
Microsoft Visual C++ 2005 Redistributable
Microsoft Works
Motorola SM56 Data Fax Modem
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB954430)
NETGEAR WG111v2 wireless USB 2.0 adapter
n-Track Studio 5
NVIDIA Drivers
PowerDVD
QuickTime
Realtek High Definition Audio Driver
ResearchSoft Direct Export Helper
Security Update for Microsoft .NET Framework 2.0 (KB928365)
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Encoder (KB954156)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901190)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB963027)
SM56Tester
SmartSound Quicktracks Plugin
Sonic Encoders
Sonic Express Labeler
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Spybot - Search & Destroy
STOPzilla
Symantec KB-DocID:2003093015493306
Ulead PhotoImpact 10 SE
Ulead VideoStudio 9.0 SE DVD
Update for Windows Media Player 10 (KB910393)
Update for Windows Media Player 10 (KB913800)
Update for Windows Media Player 10 (KB926251)
Update for Windows XP (KB894391)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB911280)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB936357)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
Update Rollup 2 for Windows XP Media Center Edition 2005
VIA Rhine-Family Fast Ethernet Adapter
Visual C++ 2008 x86 Runtime - (v9.0.30729)
Visual C++ 2008 x86 Runtime - v9.0.30729.01
Windows Defender
Windows Installer 3.1 (KB893803)
Windows Media Encoder 9 Series
Windows Media Format Runtime
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Media Center Edition 2005 KB908246
Windows XP Media Center Edition 2005 KB912067
Windows XP Media Center Edition 2005 KB914548


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:10:02, on 28/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Apps\Softex\OmniPass\Omniserv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Apps\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZScanner.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
C:\Apps\Softex\OmniPass\scureapp.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www2.arnes.si/~mmilut/BladeEnc.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: EndNote Web - {82D2E569-25A7-4E4D-9FA3-C5025B4B7912} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: EndNote Web - {945C8270-A848-11D5-A805-00B0D092F45B} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

--
End of file - 9131 bytes


Computer seems fine - amazing!
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 28th, 2009, 5:31 pm

Disable Teatimer

Please disable Teatimer as it may interfere with the fix.
  • If you have version 1.6, right click the Spybot Icon in the system tray near the clock (looks like a blue/white calendar with a padlock symbol).
  • Click once on Resident Protection, then right click the Spybot icon again and make sure Resident Protection is now Unchecked. The Spybot icon in the System tray should now be now colorless.
  • Go to Start > All Programs > Spybot - Search & Destroy > Spybot Search & Destroy.
  • Click on Mode > Advanced Mode. When it prompts you, click Yes.
  • On the left hand side, click on Tools.
  • Check this box if it is not yet ticked: Resident.
  • You will notice that Resident is now added under Tools. Click on Resident.
  • Uncheck this box: Resident "TeaTimer" (Protection of over-all system settings) active.
  • Exit Spybot Search & Destroy.
  • Reboot your machine for the changes to take effect.
Once your log is clean you can re-enable those settings in TeaTimer.



Disable Windows Defender

From your log i can see this that you are running a Windows Defender. This might interfere with fixes we are about to do so we need to disable it. To disable your Windows Defender Real-time Protection.

  • Open Windows Defender
  • Click Tools
  • Click General Settings
  • Scroll down to Real Time Protection Options
  • Uncheck Turn on Real Time Protection (recommended)
  • Close Windows Defender

Note: Once your log is clean you can re-enable Windows Defender Real Time Protection.


Disable Ad-Aware Ad-Watch

Please disable Ad-Aware Ad-Watch as it may interfere with the fix.
  • Right click on the Ad-Watch icon in the system tray (Image)
  • Select Goto Settings.
  • Click on Status on the left.
  • On your right hand side, click once on each of the section to turn the green tick into a red cross.
  • Click on RegShield on the left.
  • On your right hand side, click once on each of the section to turn the green tick into a red cross.
  • Click on Settings on the left.
  • Click once on Load Ad-Watch at startup to turn the green tick into a red cross.
  • Minimize Ad-Watch.
  • Right click on the Ad-Watch icon again and select Close Ad-Watch.
  • You will be prompted if you want to shut down Ad-Watch. Click Yes.
  • Reboot your machine for the changes to take effect.
Once your log is clean you can re-enable those settings in Ad-Aware Ad-Watch.



Remove HijackThis entries

  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -

  • Close all open windows and browsers/email etc...
  • Click on the Fix Checked button
  • When completed close the application.


OTM

Download OTM by Old Timer and save it to your Desktop.
  • Double-click OTM.exe to run it.
  • Copy the lines in the codebox below.
Code: Select all
:Processes
explorer.exe
:Files
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Application Data\Microsoft\CD Burning\HELLO E14\Fruitty Loops 4.5\Fruity Loops Studio 4.5.2 Producer Edition.iso
:Commands
[emptytemp]
[start explorer]
[Reboot]

  • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • OTM may ask to reboot the machine. Please do so if asked.
  • Copy everything in the Results window (under the green bar), and paste it in your next reply.
  • Close OTM

Logs/Information to Post in Next Reply

Please post the following logs/Information in your reply:
  • OTM log
  • A fresh HijackThis Log ( after all the above has been done)
  • A description of how your computer is behaving
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 29th, 2009, 5:16 am

Morning!

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
File/Folder D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Application Data\Microsoft\CD Burning\HELLO E14\Fruitty Loops 4.5\Fruity Loops Studio 4.5.2 Producer Edition.iso not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\CA0L2PR0.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\CA6FCL2N.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\md[1].htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\viewtopic[3].php scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\IC3Y6SAD\CAOL2ZO5.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\HIWENSQ4\viewtopic[1].php scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\HIWENSQ4\welcome[1].rand=4mcgcmkvt9f03 scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CA45IJ4P.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CA8IJXP8.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CAS547KR.htm scheduled to be deleted on reboot.
File delete failed. D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_230.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTM by OldTimer - Version 2.1.0.0 log created on 05292009_095313

Files moved on Reboot...
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\CA0L2PR0.htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\CA6FCL2N.htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\md[1].htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\N0LY3N9F\viewtopic[3].php moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\IC3Y6SAD\CAOL2ZO5.htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\HIWENSQ4\viewtopic[1].php moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\HIWENSQ4\welcome[1].rand=4mcgcmkvt9f03 moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CA45IJ4P.htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CA8IJXP8.htm moved successfully.
D:\Documents and Settings\Caroline Dexter.049924520170\Local Settings\Temporary Internet Files\Content.IE5\1SJM07YA\CAS547KR.htm moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_230.dat not found!

Registry entries deleted on Reboot...


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:22, on 29/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Apps\Softex\OmniPass\Omniserv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Apps\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\STOPzilla!\STOPzilla.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
C:\Apps\Softex\OmniPass\scureapp.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\QuickTime\qttask.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\STOPzilla!\SZOptions.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www2.arnes.si/~mmilut/BladeEnc.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EndNote Web - {82D2E569-25A7-4E4D-9FA3-C5025B4B7912} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: EndNote Web - {945C8270-A848-11D5-A805-00B0D092F45B} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

--
End of file - 8683 bytes


The computer is running fine. No popups, and internet explorer back to normal. Is it safe now?!

Thanks
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 29th, 2009, 6:40 am

oh one problem, now my googke works OK I decided to make it my homepage. I went through internet tools, set home page as current and then clicked apply - seemed fine. But in a new window the old homepage comes up. I've tried it a few times. Any ideas? Thanks
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 29th, 2009, 7:36 pm

The computer is running fine. No popups, and internet explorer back to normal. Is it safe now?!

oh one problem, now my googke works OK I decided to make it my homepage. I went through internet tools, set home page as current and then clicked apply - seemed fine. But in a new window the old homepage comes up. I've tried it a few times. Any ideas? Thanks


You are clean now but before i give you my final all clean speech we need to address this homepage issues.

It could be that change is protected by one of the security programs. Please Disable Ad-Aware Ad-Watch, Spybots Teatimer and Windows defender according to the instructions i gave you in my last post and then try to set the page again. Also would like to see a new HijackThis log.
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 30th, 2009, 9:03 am

Hey, I tried turned off all the anti virus software but the homepage issue is still the same. Here's the hijack this log

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:01:58, on 30/05/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Apps\Softex\OmniPass\Omniserv.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe
C:\Apps\Softex\OmniPass\OPXPApp.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\sm56hlpr.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
C:\Apps\Softex\OmniPass\scureapp.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www2.arnes.si/~mmilut/BladeEnc.html
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: EndNote Web - {82D2E569-25A7-4E4D-9FA3-C5025B4B7912} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: EndNote Web - {945C8270-A848-11D5-A805-00B0D092F45B} - C:\Program Files\EndNote Web\ENWIEPlug.dll
O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Vade Retro Outlook Express] "C:\PROGRA~1\GOTOSO~1\VADERE~1\Vaderetro_oe.exe"
O4 - HKLM\..\Run: [DetectorApp] C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\DetectorApp.exe
O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: NETGEAR WG111v2 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v2\WG111v2.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA} (Java Plug-in 1.5.0_04) -
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe
O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: USBDeviceService - Unknown owner - C:\Program Files\Sonic\DigitalMedia LE v7\MyDVD LE\USBDeviceService.exe

--
End of file - 8924 bytes


Thanks,

Caroline
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 30th, 2009, 2:51 pm

Hello Caroline!

I have done some digging around. I am fairly certain that Spybot is behind this so i would like you to uninstall it. After you have uninstalled try to change your homepage again.

Remove programs

  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present):

    Spybot - Search & Destroy

NOTE: Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

If it workde then you can download lates versionmof Spybot from here: Spybot - Search & Destroy 1.6.2
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 31st, 2009, 8:49 am

Hi,

I have uninstalled Spybot - no change though to the homepage issue. Also, when I start up, Stopzilla lists 64 infections, eg Vundo.F - should I remove them or not?

Thanks so much again for your time


Caroline
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 31st, 2009, 10:46 am

Hello!

I would like to see the log from Stopzilla before i can answer that question.

What is your old homepage?
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 31st, 2009, 11:53 am

Hi, I already complied with Stopzilla next time it opened, more to get it off the screen really! Sorry I hope that wasn't the wrong thing to do. Here's the log anyway:


Block/Extraction Pop-up blocker 2009-05-31 16:41:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243784460384576&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:41:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243784424763077&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:41:02 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243784460384576&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:41:02 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243784424763077&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:41:00 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243784459686605&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:41:00 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243784459686605&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:40:28 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243784424763077&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 16:40:28 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243784424763077&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 15:16:14 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&section=402087
Block/Extraction Pop-up blocker 2009-05-31 15:16:09 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&section=402087
Information General 2009-05-31 14:18:50 Exploit definition update (05/28/2009 03:38 PM GMT) successfully applied.
Information Home page protection 2009-05-31 14:05:35 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-31 14:05:08 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-31 14:05:07 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-31 14:04:56 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-31 14:04:55 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-31 14:04:54 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-31 14:04:53 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-31 14:03:06 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-31 14:03:06 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-31 14:02:58 Removed file d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction Pop-up blocker 2009-05-31 14:02:58 Removed file d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction Pop-up blocker 2009-05-31 14:02:58 Removed file d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction Pop-up blocker 2009-05-31 14:02:58 Removed file d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction Home page protection 2009-05-31 14:02:34 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 14:02:34 Detected homepage change to http://www.myspace.com/
Block/Extraction Pop-up blocker 2009-05-31 14:02:13 Extracted package System Policies.DisableRegistryTools
Block/Extraction Pop-up blocker 2009-05-31 14:02:13 Extracted package CatchMe
Block/Extraction Pop-up blocker 2009-05-31 14:02:11 Extracted package UACD
Block/Extraction Pop-up blocker 2009-05-31 14:02:11 Extracted package Vundo.F
Block/Extraction File enforcer 2009-05-31 14:02:10 Extracted files: path, c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp97\a0026644.sys
Block/Extraction File enforcer 2009-05-31 14:02:10 Deleted file: c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp97\a0026644.sys
Block/Extraction File enforcer 2009-05-31 14:02:10 Quarantined file: c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp97\a0026644.sys
Block/Extraction File enforcer 2009-05-31 14:02:10 Extracted files: path, c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp96\a0026355.sys
Block/Extraction File enforcer 2009-05-31 14:02:10 Deleted file: c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp96\a0026355.sys
Block/Extraction File enforcer 2009-05-31 14:02:08 Quarantined file: c:\system volume information\_restore{5fed904e-6e1e-4b49-8681-d5c017bb5784}\rp96\a0026355.sys
Block/Extraction Pop-up blocker 2009-05-31 13:50:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243774063903720&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:50:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243774044642287&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:50:11 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243774063903720&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:50:11 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243774044642287&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:47:52 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243774063903720&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:47:52 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243774044642287&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:47:46 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243774063903720&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:47:46 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243774044642287&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-31 13:47:26 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243774044642287&yrc=uk&ycg=f&yyob=1977
Block/Extraction Home page protection 2009-05-31 13:46:52 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:46:52 Detected homepage change to http://go.microsoft.com/fwlink/?LinkId=69157
Block/Extraction Home page protection 2009-05-31 13:46:44 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:46:44 Detected homepage change to about:blank
Block/Extraction Home page protection 2009-05-31 13:46:34 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:46:34 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-31 13:44:06 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:44:06 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-31 13:43:38 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:43:38 Detected homepage change to http://www.google.co.uk/
Information Home page protection 2009-05-31 13:42:10 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-31 13:41:14 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-31 13:41:14 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-31 13:41:08 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-31 13:41:05 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-31 13:41:04 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-31 13:41:03 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-31 13:39:04 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-31 13:39:04 Disabled service: messenger -
Block/Extraction Home page protection 2009-05-31 13:33:02 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 13:33:02 Detected homepage change to http://www.google.co.uk/
Warning/Detection Process enforcer 2009-05-31 13:29:31 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-31 13:28:57 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-31 12:36:34 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-31 12:36:34 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-31 12:36:15 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-31 12:36:14 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-31 12:36:12 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-31 12:36:11 Starting process watcher
Block/Extraction Pop-up blocker 2009-05-30 19:53:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243709387404371&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:53:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243709383930514&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:53:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243709387404371&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:53:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243709383930514&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:49:50 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243709387404371&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:49:50 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243709383930514&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:49:44 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243709387404371&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:49:44 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243709383930514&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 19:49:40 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243709383930514&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 18:36:03 Blocked Pop-up: view.atdmt.com/cwg/iview/125241196/direct;wi.300;hi.250/01?click=http://servedby.advertising.com/click/site=0000756360/mnum=0000650975/cstr=93142071=_4a216e88,1236127220,756360^650975^251^0,1_/xsxdata=$xsxdata/bnum=93142071/optn=64?trg=
Block/Extraction Pop-up blocker 2009-05-30 18:27:58 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1707.adcom/b3531773.38;sz=300x250;click=http://servedby.advertising.com/click/site=0000756360/mnum=0000690838/cstr=84938488=_4a216ca3,7117717860,756360^690838^250^0,1_/xsxdata=$xsxdata/bnum=84938488/optn=64?trg=;ord=7117717860?
Block/Extraction Pop-up blocker 2009-05-30 18:25:09 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1707.adcom/b3630610.3;sz=728x90;click=http://servedby.advertising.com/click/site=0000756361/mnum=0000624471/cstr=92534158=_4a216bf9,5268881177,756361^624471^250^0,1_/xsxdata=$xsxdata/bnum=92534158/optn=64?trg=;ord=5268881177?
Block/Extraction Pop-up blocker 2009-05-30 18:22:52 Blocked Pop-up: ad.uk.doubleclick.net/adi/n884.platforma/b3541116.16;sz=300x250;click=http://servedby.advertising.com/click/site=0000756360/mnum=0000691979/cstr=13511560=_4a216b70,8157406760,756360^691979^250^0,1_/xsxdata=$xsxdata/bnum=13511560/optn=64?trg=;ord=8157406760?
Block/Extraction Pop-up blocker 2009-05-30 18:22:51 Blocked Pop-up: ad.uk.doubleclick.net/adi/n884.platforma/b3541116.26;sz=728x90;click=http://servedby.advertising.com/click/site=0000756361/mnum=0000695336/cstr=99667431=_4a216b70,1426752626,756361^695336^250^0,1_/xsxdata=$xsxdata/bnum=99667431/optn=64?trg=;ord=1426752626?
Block/Extraction Pop-up blocker 2009-05-30 18:08:34 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1379.ad.com/b3646492.3;sz=728x90;click=http://servedby.advertising.com/click/site=0000765888/mnum=0000712784/cstr=6086490=_4a216816,8253401433,765888^712784^70^0,1_/bnum=6086490/optn=64?trg=http://oasn04.247realmedia.com/realmedia/ads/click_lx.ads/ad.com_ukb3/alfamsc/ron/728x90/8253401433/1234/x90/ukb3/alfamsc_ad.com_ukb3ron_728x90/alfamsc_728x90.html/1?;ord=8253401433?
Block/Extraction Pop-up blocker 2009-05-30 18:08:32 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1238.adcom.quantum/b3549733;sz=120x600;click=http://servedby.advertising.com/click/site=0000759362/mnum=0000693201/cstr=19633909=_4a216814,6066260775,759362^693201^250^0,1_/xsxdata=$xsxdata/bnum=19633909/optn=64?trg=;ord=6066260775?
Block/Extraction Pop-up blocker 2009-05-30 18:07:57 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1707.adcom/b3630610;sz=300x250;click=http://servedby.advertising.com/click/site=0000756351/mnum=0000624470/cstr=94453030=_4a2167f2,7035223380,756351^624470^250^0,1_/xsxdata=$xsxdata/bnum=94453030/optn=64?trg=;ord=7035223380?
Block/Extraction Pop-up blocker 2009-05-30 15:09:23 Blocked Pop-up: view.atdmt.com/zo2/iview/148815027/direct;wi.728;hi.90/01/1243692568?click=http://ad.yieldmanager.com/click,qqulab3xbwcqzyeacm8kaaiaaaaaap8aaaaheaiabgi-oqwaoumoaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaabg-iuoaaaaa,,http%3a%2f%2fdelb.opt.fimserve.com%2fadopt%2f%3fr%3dh%26l%3d11013005%26pos%3dleaderboard%26rnd%3d198752144%26fid%3d77205619%26acct%3d2%26ged%3d0%3a0%3aogjhodzhnmfizjgxntm2ooapyklr1ojlygwxeult2hgluve00m8ivdsxnyvakcguvx2i8swadruzxldzxarirjxrlanbn1rhpexzfdsnry6ttxi-62vmia_i7-2eveqv%3a%3a0%3a0%3aztuzztexyjzhntu1oti4yuifi4idg1k051zfads9ur0ai6xbsmvvwc_9ikgzh55ditfckfp11wln27eukkz2lq1i0ypwuxgaoo_ae75gr0ccdqvr2r3y2qunt_9jwt19,
Block/Extraction Pop-up blocker 2009-05-30 15:08:31 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243692503989768&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 15:08:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243692503989768&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 15:08:20 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243692503989768&yrc=uk&ycg=f&yyob=1977
Block/Extraction Home page protection 2009-05-30 13:58:12 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-30 13:58:12 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-30 13:54:39 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-30 13:54:39 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-30 13:53:41 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-30 13:53:41 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-30 13:52:28 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-30 13:52:28 Detected homepage change to http://www.google.co.uk/
Block/Extraction Pop-up blocker 2009-05-30 13:50:42 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243687835420080&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 13:50:36 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243687835420080&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 13:50:32 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243687835420080&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-30 10:18:01 Blocked Pop-up: c13.zedo.com/jsc//zpu.html?f=;z=2-107
Block/Extraction Pop-up blocker 2009-05-30 10:17:28 Blocked Pop-up: c13.zedo.com/jsc//zpu.html?f=;z=2-107
Block/Extraction Pop-up blocker 2009-05-30 10:10:29 Blocked Pop-up: espn.go.com//[no path]
Block/Extraction Pop-up blocker 2009-05-30 10:10:27 Blocked Pop-up: espn.go.com//[no path]
Warning/Detection Process enforcer 2009-05-30 09:54:47 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-30 09:53:58 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-30 09:53:42 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-30 09:53:42 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-30 09:53:24 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-30 09:53:22 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-30 09:53:21 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-30 09:53:19 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-29 18:51:30 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-29 18:51:29 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-29 17:58:22 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 17:01:11 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 17:00:06 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 16:59:26 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 16:59:20 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 16:59:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 16:59:08 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 16:59:08 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243612751081588&yrc=uk&ycg=f&yyob=1977
Block/Extraction Home page protection 2009-05-29 11:34:39 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-29 11:34:39 Detected homepage change to http://www.google.co.uk/
Block/Extraction Pop-up blocker 2009-05-29 11:30:35 Blocked Pop-up: ad.uk.doubleclick.net/adi/n884.platforma/b3541116.16;sz=300x250;click=http://servedby.advertising.com/click/site=0000756360/mnum=0000691979/cstr=40960358=_4a1fb94e,3463854303,756360^691979^250^0,1_/xsxdata=$xsxdata/bnum=40960358/optn=64?trg=;ord=3463854303?
Block/Extraction Pop-up blocker 2009-05-29 11:27:47 Blocked Pop-up: ad.uk.doubleclick.net/adi/n5449.platforma/b3634922.6;sz=300x250;click=http://servedby.advertising.com/click/site=0000756351/mnum=0000710889/cstr=26335120=_4a1fb8a7,7541875063,756351^710889^250^0,1_/xsxdata=$xsxdata/bnum=26335120/optn=64?trg=;ord=7541875063?
Block/Extraction Home page protection 2009-05-29 10:55:20 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-29 10:55:20 Detected homepage change to http://www.google.co.uk/
Block/Extraction Home page protection 2009-05-29 10:40:58 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-29 10:40:58 Detected homepage change to http://www.google.co.uk/
Block/Extraction Pop-up blocker 2009-05-29 10:14:49 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243588492464248&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:14:49 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243588492464248&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:30 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243588102252598&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:30 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243588097703470&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:20 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243588102252598&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:20 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243588097703470&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:15 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243588097703470&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 10:08:15 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243588097703470&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-29 10:06:41 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-29 10:06:02 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-29 09:56:48 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-29 09:56:47 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-29 09:56:36 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-29 09:56:34 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-29 09:56:33 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-29 09:56:32 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-29 09:54:44 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-29 09:54:44 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-29 09:43:47 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243586618483320&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:43:41 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243586618483320&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:43:36 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243586618483320&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:43:36 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243586618483320&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-29 09:42:03 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-29 09:41:39 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-29 09:40:54 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-29 09:40:53 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-29 09:40:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-29 09:40:41 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-29 09:40:38 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-29 09:40:34 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-29 09:39:12 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-29 09:39:11 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-29 09:33:02 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243585974778715&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:33:01 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243585969748012&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:32:53 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243585974778715&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:32:53 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243585969748012&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:32:48 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243585969748012&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-29 09:32:47 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243585969748012&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-29 09:30:36 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-29 09:29:45 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-29 09:28:41 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-29 09:28:41 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-29 09:28:28 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-29 09:28:22 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-29 09:28:21 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-29 09:28:16 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-28 20:37:43 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-28 20:37:40 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-28 20:06:57 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243537605055935&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 20:06:57 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243537594013096&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 20:06:47 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243537605055935&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 20:06:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243537594013096&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 20:06:36 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243537594013096&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 20:06:34 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243537594013096&yrc=uk&ycg=f&yyob=1977
Block/Extraction Registry enforcer 2009-05-28 20:03:41 Deleted registry value DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 20:03:41 Detected malicious registry entry DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Block/Extraction NT Service enforcer 2009-05-28 20:03:08 Removed Sys module: d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction NT Service enforcer 2009-05-28 20:03:08 Removed service: catchme - catchme
Information Home page protection 2009-05-28 20:02:34 Checking homepage... OK
Information General 2009-05-28 20:02:16 Started scheduled scan.
Information Internet ExplorerSiteguard 2009-05-28 20:02:07 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-28 20:02:07 Inspecting registered Explorer bars
Block/Extraction Registry enforcer 2009-05-28 20:01:56 Deleted registry value system in hklm\software\microsoft\windows nt\currentversion\winlogon
Information Registry enforcer 2009-05-28 20:01:52 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-28 20:01:50 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-28 20:01:49 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-28 20:01:48 Starting process watcher
Information Home page protection 2009-05-28 13:57:21 Checking homepage... OK
Block/Extraction Registry enforcer 2009-05-28 13:55:29 Deleted registry value DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 13:55:29 Detected malicious registry entry DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Block/Extraction NT Service enforcer 2009-05-28 13:55:14 Removed Sys module: d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction NT Service enforcer 2009-05-28 13:55:14 Removed service: catchme - catchme
Information Internet ExplorerSiteguard 2009-05-28 13:54:38 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-28 13:54:38 Inspecting registered Explorer bars
Block/Extraction Registry enforcer 2009-05-28 13:54:24 Deleted registry value system in hklm\software\microsoft\windows nt\currentversion\winlogon
Information Registry enforcer 2009-05-28 13:54:19 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-28 13:54:17 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-28 13:54:15 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-28 13:54:14 Starting process watcher
Block/Extraction Registry enforcer 2009-05-28 13:49:37 Deleted registry value disableregistrytools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 13:49:37 Detected malicious registry entry disableregistrytools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Block/Extraction Registry enforcer 2009-05-28 13:49:36 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 13:49:36 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Block/Extraction Pop-up blocker 2009-05-28 12:21:25 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:21:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:21:15 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:21:15 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:21:03 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:21:02 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:55 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:55 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:42 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:41 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:27 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243509625192412&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:25 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 12:20:17 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243509616993706&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:31:56 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&site=167876&section_code=201788847&cb=1243506719203655&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:31:31 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&site=167876&section_code=201788847&cb=1243506695055683&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:30:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243506530418393&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:30:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243506526437931&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:28:48 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243506530418393&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:28:48 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243506526437931&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 11:28:44 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243506526437931&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-28 11:22:15 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-28 11:21:50 Checking homepage... OK
Block/Extraction Registry enforcer 2009-05-28 11:19:40 Deleted registry value DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 11:19:40 Detected malicious registry entry DisableRegistryTools in hklm\software\microsoft\windows\currentversion\policies\system
Block/Extraction NT Service enforcer 2009-05-28 11:19:35 Removed Sys module: d:\documents and settings\caroline dexter.049924520170\local settings\temp\catchme.sys
Block/Extraction NT Service enforcer 2009-05-28 11:19:35 Removed service: catchme - catchme
Information Internet ExplorerSiteguard 2009-05-28 11:18:43 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-28 11:18:43 Inspecting registered Explorer bars
Block/Extraction Registry enforcer 2009-05-28 11:18:28 Deleted registry value system in hklm\software\microsoft\windows nt\currentversion\winlogon
Information Registry enforcer 2009-05-28 11:18:21 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-28 11:18:21 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-28 11:18:20 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-28 11:18:19 Starting process watcher
Block/Extraction Registry enforcer 2009-05-28 10:45:41 Extracted registry key HKLM\SYSTEM\CurrentControlSet\Services\UACd.sys
Block/Extraction Registry enforcer 2009-05-28 10:45:38 Extracted registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_BEEP
Information Home page protection 2009-05-28 10:45:14 Checking homepage... OK
Block/Extraction NT Service enforcer 2009-05-28 10:45:08 Removed service: catchme - catchme
Block/Extraction Registry enforcer 2009-05-28 10:44:44 Extracted registry key HKLM\SYSTEM\CurrentControlSet\Services\catchme
Information Internet ExplorerSiteguard 2009-05-28 10:44:32 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-28 10:44:32 Inspecting registered Explorer bars
Block/Extraction Registry enforcer 2009-05-28 10:44:32 Extracted registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CATCHME
Information Registry enforcer 2009-05-28 10:44:14 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-28 10:44:11 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-28 10:44:10 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-28 10:44:09 Starting process watcher
Block/Extraction Registry enforcer 2009-05-28 10:26:08 Deleted registry value DisableRegistryTools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Warning/Detection COM enforcer 2009-05-28 10:26:08 Detected malicious registry entry DisableRegistryTools in hkus\S-1-5-21-357337470-3576400413-644577365-1005\software\microsoft\windows\currentversion\policies\system
Block/Extraction Pop-up blocker 2009-05-28 10:20:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243502445316424&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 10:20:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243502441761025&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 10:20:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243502445316424&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 10:20:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243502441761025&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 10:20:40 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243502441761025&yrc=uk&ycg=f&yyob=1977
Information Home page protection 2009-05-28 10:16:52 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-28 09:59:58 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-28 09:59:58 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-28 09:59:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-28 09:59:41 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-28 09:59:40 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-28 09:59:38 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-28 00:55:46 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-28 00:55:46 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-28 00:32:25 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243467136840863&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 00:18:57 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243465709372589&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 00:08:41 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243465709372589&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 00:08:35 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243465709372589&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-28 00:08:29 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243465709372589&yrc=uk&ycg=f&yyob=1977
Information Home page protection 2009-05-27 23:50:33 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 23:49:22 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 23:49:22 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 23:49:04 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 23:48:56 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 23:48:55 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 23:48:54 Starting process watcher
Information Home page protection 2009-05-27 23:27:39 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 23:27:13 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 23:27:11 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 23:26:33 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 23:26:31 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 23:26:30 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 23:26:28 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-27 22:54:51 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-27 22:54:50 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-27 22:47:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243460632075353&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 22:44:11 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243460632075353&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 22:44:01 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243460632075353&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 22:43:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243460632075353&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 22:43:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243460632075353&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-27 22:38:12 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-27 22:37:38 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 22:28:50 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 22:28:50 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 22:28:35 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 22:28:34 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 22:28:33 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 22:28:30 Starting process watcher
Block/Extraction Pop-up blocker 2009-05-27 19:50:50 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243450219883584&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:50:23 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243450219883584&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:50:17 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243450219883584&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:46:31 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243449966656963&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:46:16 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243449966656963&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:46:09 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243449966656963&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:46:05 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243449966656963&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 19:46:04 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243449966656963&yrc=uk&ycg=f&yyob=1977
Information Home page protection 2009-05-27 19:44:39 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 19:36:20 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 19:36:20 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 19:36:04 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 19:36:02 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 19:36:01 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 19:35:59 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-27 16:20:32 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-27 16:20:30 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-27 16:07:05 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 16:06:58 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 16:03:59 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&site=167876&section_code=201788847&cb=1243436641477777&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 16:03:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Information General 2009-05-27 15:47:34 SITEguard definition update 5.0.42.6 successfully applied.
Information Registry enforcer 2009-05-27 15:47:23 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 15:47:22 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 15:47:22 Inspecting WinSock registry (LSP Chain)
Information Internet ExplorerSiteguard 2009-05-27 15:47:21 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 15:47:21 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 15:47:21 Inspecting registered Browser Helper Objects (BHOs)
Information General 2009-05-27 15:47:20 Request to update definitions completed successfully.
Information General 2009-05-27 15:47:07 Anti-Spyware Incremental definition update 5.0.42.6 successfully applied.
Block/Extraction Pop-up blocker 2009-05-27 15:46:44 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 15:46:36 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 15:46:19 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 15:46:10 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-27 15:46:01 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243435556179493&yrc=uk&ycg=f&yyob=1977
Information Home page protection 2009-05-27 15:43:16 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 15:42:41 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 15:42:41 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 15:42:29 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 15:42:27 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 15:42:26 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 15:42:25 Starting process watcher
Information Internet ExplorerSiteguard 2009-05-27 15:39:18 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 15:39:18 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 15:39:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 15:39:00 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 15:38:58 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 15:38:56 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-27 06:20:46 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-27 06:20:46 Disabled service: messenger -
Information Home page protection 2009-05-27 06:10:46 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-27 05:57:09 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-27 05:57:09 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-27 05:56:53 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-27 05:56:51 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-27 05:56:51 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-27 05:56:48 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-26 23:24:44 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-26 23:24:43 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-26 23:23:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243375539855023&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:23:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:08:25 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243375539855023&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:08:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:08:13 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243375539855023&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:08:12 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:05:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243375539855023&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:05:45 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:05:40 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243375539855023&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:05:40 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 23:05:34 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243375535939113&yrc=uk&ycg=f&yyob=1977
Information General 2009-05-26 19:17:01 Exploit definition update (05/26/2009 03:31 PM GMT) successfully applied.
Block/Extraction Pop-up blocker 2009-05-26 19:16:57 Removed file d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction Pop-up blocker 2009-05-26 19:16:03 Extracted package ExecVariant.C
Block/Extraction Pop-up blocker 2009-05-26 19:12:49 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1238.adcom.quantum/b3015474.52;sz=300x250;click=http://servedby.advertising.com/click/site=0000756360/mnum=0000713936/cstr=83617493=_4a1c3122,8618033755,756360^713936^250^0,1_/xsxdata=$xsxdata/bnum=83617493/optn=64?trg=;ord=8618033755?
Block/Extraction Pop-up blocker 2009-05-26 19:10:58 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1238.adcom.quantum/b3015474.57;sz=300x250;click=http://servedby.advertising.com/click/site=0000765890/mnum=0000713968/cstr=7280538=_4a1c30b3,3312142154,765890^713968^70^0,1_/xsxdata=$xsxdata/bnum=7280538/optn=64?trg=;ord=3312142154?
Block/Extraction Pop-up blocker 2009-05-26 19:09:19 Blocked Pop-up: ad.uk.doubleclick.net/adi/n1238.adcom.quantum/b3015474.52;sz=300x250;click=http://servedby.advertising.com/click/site=0000756360/mnum=0000713936/cstr=45670907=_4a1c3050,5030426200,756360^713936^250^0,1_/xsxdata=$xsxdata/bnum=45670907/optn=64?trg=;ord=5030426200?
Block/Extraction Pop-up blocker 2009-05-26 19:07:54 Blocked Pop-up: ad.uk.doubleclick.net/adi/n3434.ad.com/b3608060.3;sz=300x250;click=http://servedby.advertising.com/click/site=0000756351/mnum=0000704482/cstr=94570212=_4a1c2ffc,0157140044,756351^704482^250^0,1_/xsxdata=$xsxdata/bnum=94570212/optn=64?trg=;ord=0157140044?
Block/Extraction Pop-up blocker 2009-05-26 18:47:30 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:47:22 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:47:13 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:46:51 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:46:47 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction File enforcer 2009-05-26 18:37:29 Deleted file: d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction File enforcer 2009-05-26 18:37:29 Suppressed file: d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction Process enforcer 2009-05-26 18:37:29 Terminated process: (4408) d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction File enforcer 2009-05-26 18:36:21 Deleted file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\m1qpaz0d\rsit[1].exe
Block/Extraction File enforcer 2009-05-26 18:36:20 Quarantined file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\m1qpaz0d\rsit[1].exe
Block/Extraction Process enforcer 2009-05-26 18:36:20 Terminated process: (5828) d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\m1qpaz0d\rsit[1].exe
Block/Extraction Pop-up blocker 2009-05-26 18:35:29 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:35:22 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:35:16 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243359316873582&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 18:31:29 Extracted package ExecVariant.C
Warning/Detection Process enforcer 2009-05-26 18:29:15 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-26 18:28:27 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-26 18:27:16 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-26 18:27:15 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-26 18:27:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-26 18:27:01 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-26 18:27:01 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-26 18:27:00 Starting process watcher
Block/Extraction File enforcer 2009-05-26 17:52:48 Deleted file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\zg40hnvx\rsit[1].exe
Block/Extraction File enforcer 2009-05-26 17:52:47 Quarantined file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\zg40hnvx\rsit[1].exe
Block/Extraction Process enforcer 2009-05-26 17:52:47 Terminated process: (4436) d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\zg40hnvx\rsit[1].exe
Block/Extraction File enforcer 2009-05-26 17:52:21 Deleted file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\utzw8bcy\rsit[1].exe
Block/Extraction File enforcer 2009-05-26 17:52:20 Quarantined file: d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\utzw8bcy\rsit[1].exe
Block/Extraction Process enforcer 2009-05-26 17:52:20 Terminated process: (5672) d:\documents and settings\caroline dexter.049924520170\local settings\temporary internet files\content.ie5\utzw8bcy\rsit[1].exe
Block/Extraction File enforcer 2009-05-26 17:51:36 Deleted file: d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction File enforcer 2009-05-26 17:51:36 Quarantined file: d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction Process enforcer 2009-05-26 17:51:35 Terminated process: (6128) d:\documents and settings\caroline dexter.049924520170\desktop\rsit.exe
Block/Extraction Pop-up blocker 2009-05-26 17:50:33 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243356614133479&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 17:50:20 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243356614133479&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-26 17:50:14 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243356614133479&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-26 17:39:40 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-26 17:38:45 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-26 17:37:56 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-26 17:37:56 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-26 17:37:47 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-26 17:37:45 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-26 17:37:44 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-26 17:37:43 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-26 08:07:50 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-26 08:07:50 Disabled service: messenger -
Warning/Detection Process enforcer 2009-05-26 07:35:48 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-26 07:35:21 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-26 07:26:10 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-26 07:26:10 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-26 07:25:57 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-26 07:25:55 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-26 07:25:54 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-26 07:25:52 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-25 23:00:35 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-25 23:00:34 Disabled service: messenger -
Block/Extraction Pop-up blocker 2009-05-25 22:58:37 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243288705731219&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 22:58:31 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243288705731219&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 22:58:24 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243288705731219&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:53:17 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:53:16 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:29:53 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:29:53 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:26:22 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:26:22 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:19:39 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:19:39 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:19:34 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:19:34 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:50 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:50 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:43 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243282662242685&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:43 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:38 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=300x250&site=167876&section_code=201788811&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 21:17:38 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243282659084235&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:49:14 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:49:14 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:36:16 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:36:16 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:36:06 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:36:06 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:25:41 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:25:41 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:25:33 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=425x600&site=167876&section_code=201788847&cb=1243279535165943&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:52 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:52 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:46 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:46 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:29 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=728x90&site=167876&section_code=201788898&cb=1243279347748808&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:28 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Block/Extraction Pop-up blocker 2009-05-25 20:22:23 Blocked Pop-up: ad.yieldmanager.com/st?ad_type=iframe&ad_size=180x150&site=167876&section_code=201788619&cb=1243279343867220&yrc=uk&ycg=f&yyob=1977
Warning/Detection Process enforcer 2009-05-25 20:17:59 Monitoring process c:\program files\messenger\msmsgs.exe
Information Home page protection 2009-05-25 20:17:25 Checking homepage... OK
Information Internet ExplorerSiteguard 2009-05-25 20:16:31 Inspecting registered Internet Explorer toolbars
Information Registry enforcer 2009-05-25 20:16:31 Inspecting registered Explorer bars
Information Registry enforcer 2009-05-25 20:16:20 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 20:16:17 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-25 20:16:17 Inspecting registered Browser Helper Objects (BHOs)
Information Process enforcer 2009-05-25 20:16:15 Starting process watcher
Block/Extraction NT Service enforcer 2009-05-25 20:14:38 Disabled service: messenger -
Block/Extraction NT Service enforcer 2009-05-25 20:14:34 Disabled service: messenger -
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 19:10:42 Inspecting WinSock registry (LSP Chain)
Information Registry enforcer 2009-05-25 19:08:02 Inspecting WinLogon notification handlers and modules loaded by WinLogon
Information Registry enforcer 2009-05-25 19:07:58 Inspecting WinSock registry (LSP Chain)
Information General 2009-05-25 19:07:38 Completed system scan.


Thanks
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby Bio-Hazard » May 31st, 2009, 12:00 pm

Hello!

From that log i can see that it is protecting your homepage. Here are the entries:

Block/Extraction Home page protection 2009-05-31 14:02:34 Resetting Homepage back to http://www.youtube.com/watch?v=hZLchENhVVY&NR=1
Warning/Detection Home page protection 2009-05-31 14:02:34 Detected homepage change to http://www.myspace.com/


So you need to change it through Stopzilla. I am not familiar with it. Do you think you will be able to do it?

I am still going through the rest of the log.
User avatar
Bio-Hazard
MRU Master Emeritus
 
Posts: 4078
Joined: May 10th, 2007, 8:28 am
Location: Cornwall, UK

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 31st, 2009, 12:01 pm

oh yes! OK I'll have a go. Thanks
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm

Re: my hijack this log file, thanks for your help

Unread postby singanina » May 31st, 2009, 12:10 pm

yes, it was under realtime protection - network - configure. It works. Is it worth using Stopzilla? Also the resident shield of AVG now keeps alerting me to infections eg :

Found Tracking Cookie: Doubleclick
Process name: C:\Program Files\Internet Explorer\IEXPLORE.EXE
Process ID: 6108
Detected on Open

but when I say remove, it says some files cannot be healed. What's that about? Sorry, should I just disable it, or are they real infections?

Thanks again
singanina
Regular Member
 
Posts: 35
Joined: May 23rd, 2009, 2:20 pm
Advertisement
Register to Remove

PreviousNext

  • Similar Topics
    Replies
    Views
    Last post

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 132 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware