Computing.Net > Forums > Security and Virus > monstermarketplace-need help removi

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

monstermarketplace-need help removi

Reply to Message Icon

Original Message
Name: Carnage
Date: March 17, 2007 at 08:20:09 Pacific
Subject: monstermarketplace-need help removi
OS: XP
CPU/Ram: dunno
Manufacturer/Model: dunno
Comment:

Every time I use google.com I am redirected to places like monstermarketplace.com or some other search website. I checked thru all of the sites and it seems i have some unremovable Trojan. Somebody help!!! I want to get rid of it but I also don't want to brake the computer.


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: March 17, 2007 at 15:00:20 Pacific
Reply:


Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

Please download SmitFraudFix from this link http://siri.urz.free.fr/Fix/Smitfra... Then extract the contents to your desktop.

!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!


Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user. Please download Comboscan from this link:

Comboscan


Close all applications and windows.
Double-click on comboscan.exe to run it, and follow the prompts.
When the scan is complete, a text file will open - ComboScan.txt
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of ComboScan.txt in your next post.
A folder, C:\ComboScan, will also open. In it will be another text file, Supplementary.txt.
Please attach Supplementary.txt to your post.

Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.


Report Offensive Follow Up For Removal

Response Number 2
Name: Carnage
Date: March 18, 2007 at 10:20:07 Pacific
Reply:

Here is my Hijack Log:
Logfile of HijackThis v1.99.1
Scan saved at 17:17:14, on 18/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\cisvc.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\locator.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\APPS\SMP\SmpSys.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - C:\Program Files\IEForge\Inline Search\InlineSearch.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PViever] "C:\Program Files\PViever\pviever.exe" hide
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\CARNAGE\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://symantec.atgnow.com/sdccommo...
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by118w.bay118.mail.live.com/...
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://www.zorpia.com/ImageUploader...
O16 - DPF: {AF2E62B6-F9E1-4D4F-A10A-9DC8E6DCBCC0} (VideoEgg ActiveX Loader) - http://update.videoegg.com/Install/...
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/M...
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/s...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binar...
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.co...
O16 - DPF: {CD995117-98E5-4169-9920-6C12D4C0B548} (HGPlugin9USA Class) - http://gamedownload.ijjimax.com/gam...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/g...
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gam...
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zan...
O17 - HKLM\System\CCS\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\..\{91B9C3F1-3941-47E5-BBA9-F83DF975F3AB}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\..\{C29E58B1-1CDC-436B-B309-160F0EA3C764}: NameServer = 85.255.116.100 85.255.112.169
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169
O17 - HKLM\System\CS1\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe


Report Offensive Follow Up For Removal

Response Number 3
Name: Carnage
Date: March 18, 2007 at 10:29:12 Pacific
Reply:

Here is my SmitfraudFix report:

SmitFraudFix v2.148

Scan done at 17:27:41.43, 18/03/2007
Run from D:\Documents and Settings\CARNAGE\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» D:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\CARNAGE


»»»»»»»»»»»»»»»»»»»»»»»» D:\Documents and Settings\CARNAGE\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» D:\DOCUME~1\CARNAGE\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files

C:\Program Files\Video ActiveX Object\ FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"="kdnxb.exe"

kdnxb.exe detected !


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End



Report Offensive Follow Up For Removal

Response Number 4
Name: Carnage
Date: March 18, 2007 at 10:37:33 Pacific
Reply:

So what do I do next?


Report Offensive Follow Up For Removal

Response Number 5
Name: jabuck
Date: March 18, 2007 at 20:45:05 Pacific
Reply:

Please download Fixwareout from this link

http://swandog46.geekstogo.com/Fixwareout.exe

or

http://downloads.subratam.org/Fixwareout.exe

Save it to your desktop and run it. Click next, then Install, then make sure "Run fixit" is checked and click finish. The fix will begin; follow the prompts. You will be asked to reboot your computer; please do so. Your system may take longer than usual to load; this is normal.Post a copy at the log located at C:\fixwareout\report.txt

After restart and ***only*** if you have any connection problems, do this:

Please go to Start -> Control Panel, and choose Network Connections. Then right click on your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on properties. Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice, and restart your computer.

Before you restart the computer.
Go to Start > Run and type in cmd
Click OK.
This will open a commad prompt.
Type or copy and paste the following line in the command window:


ipconfig /flushdns


Hit Enter
Exit the command window

Next, please reboot your computer in Safe Mode by doing the following :

Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Once in Safe Mode, open the "SmitfraudFix" folder again and double-click "smitfraudfix.cmd"
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing " Y " and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if "wininet.dll " is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing "Y" and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Also post back with a new Hijack This log.


Report Offensive Follow Up For Removal


Response Number 6
Name: Carnage
Date: March 19, 2007 at 12:25:31 Pacific
Reply:

Here is the fixwareout report:


Fixwareout Last edited 2/11/2007
Post this report in the forums please
...
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdnxb.exe"

»»»»» System restarted


Report Offensive Follow Up For Removal

Response Number 7
Name: Carnage
Date: March 19, 2007 at 14:21:28 Pacific
Reply:

Here is my second fixwareout report:
SmitFraudFix v2.148

Scan done at 21:02:10.96, 19/03/2007
Run from D:\Documents and Settings\CARNAGE\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\Program Files\Video ActiveX Object\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



Report Offensive Follow Up For Removal

Response Number 8
Name: Carnage
Date: March 19, 2007 at 14:23:00 Pacific
Reply:

Here is my second Hijack this report:
Logfile of HijackThis v1.99.1
Scan saved at 21:22:05, on 19/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\cisvc.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Apps\Powercinema\PCMService.exe
C:\WINDOWS\system32\rundll32.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\apps\ABoard\AOSD.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\APPS\SMP\SmpSys.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: InlineSearchHandleHotKey - {B6FFE2AE-4D12-451F-B457-FE6125FFB1CF} - C:\Program Files\IEForge\Inline Search\InlineSearch.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [PViever] "C:\Program Files\PViever\pviever.exe" hide
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\CARNAGE\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/s...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binar...
O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gam...
O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zan...
O17 - HKLM\System\CCS\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\..\{91B9C3F1-3941-47E5-BBA9-F83DF975F3AB}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\..\{C29E58B1-1CDC-436B-B309-160F0EA3C764}: NameServer = 85.255.116.100 85.255.112.169
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169
O17 - HKLM\System\CS1\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe



Report Offensive Follow Up For Removal

Response Number 9
Name: Carnage
Date: March 19, 2007 at 14:24:34 Pacific
Reply:

I checked google and everything seems to be back to normal. Do I do anything else?


Report Offensive Follow Up For Removal

Response Number 10
Name: jabuck
Date: March 19, 2007 at 14:55:00 Pacific
Reply:

Go to start> control panel>add/remove programs and uninstall these programs if found:

Zango

Zenosearch

Zeno Search Assistant removal

MyWebSearch

Anything with "myweb" in it

PartyGaming

RXToolBar

Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ We will need it later in safe mode

Download and install AVG Anti-Spyware We will need this later in safe mode

Be sure to update AVG Anti- Spyware

Next, please reboot your computer in Safe Mode by doing the following :

Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Run Hijack This from safe mode, close all windows except Hijack This, place a check to the left of the following items and press "fix checked":

O2 - BHO: RXResultTracker Class - {59879FA4-4790-461c-A1CC-4EC4DE4CA483} - C:\Program Files\RXToolBar\sfcont.dll (file missing)

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O4 - HKLM\..\Run: [PViever] "C:\Program Files\PViever\pviever.exe" hide

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolba...

O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)

O16 - DPF: {DD583921-A9E9-4FBF-9266-8DC2AB5EA0AF} (HGPlugin10USA Class) - http://gamedownload.ijjimax.com/gam...

O16 - DPF: {DECEAAA2-370A-49BB-9362-68C3A58DDC62} - http://static.zangocash.com/cab/Zan...

O17 - HKLM\System\CCS\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169

O17 - HKLM\System\CCS\Services\Tcpip\..\{91B9C3F1-3941-47E5-BBA9-F83DF975F3AB}: NameServer = 85.255.116.100,85.255.112.169

O17 - HKLM\System\CCS\Services\Tcpip\..\{C29E58B1-1CDC-436B-B309-160F0EA3C764}: NameServer = 85.255.116.100 85.255.112.169

O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169

O17 - HKLM\System\CS1\Services\Tcpip\..\{062C9B56-8BBC-4E16-B2D3-40529A21CDDD}: NameServer = 85.255.116.100,85.255.112.169

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.116.100 85.255.112.169

O18 - Filter: text/html - {2AB289AE-4B90-4281-B2AE-1F4BB034B647} - C:\Program Files\RXToolBar\sfcont.dll

Exit Hijack this but remain in safe mode.

Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.

Navigate to and delete these files if found:

C:\Program Files\RXToolBar\sfcont.dll

C:\Program Files\PViever\pviever.exe

Then navigate to and delete this folder if found:

C:\Program Files\RXToolBar

C:\Program Files\PViever


Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.

In Safe Mode, run AVG Anti-spyware and click on the Scanner tab at the top. Click the "Settings" tab and then change the recommended action to Quarantine and click Automatically generate report after every scan. Click back to the "Scan" tab and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.

AVG Anti-Spyware will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG Anti-Spyware will display "All actions have been applied" on the right hand side.

Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop). Post the AVG AntiSpyware report please and post a new Hijack this log.

You java is out of date. Download the latest version of http://java.sun.com/javase/downloads/index.jsp

Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".

Click the "Download" button to the right.

Check the box that says: "Accept License Agreement". The page will refresh.

Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.

Close any programs you may have running - especially your web browser.

Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java. Check any item with Java Runtime Environment (JRE or J2SE) in the name. It should have the "coffee cup" icon next to it.

Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions.

Reboot your computer once all Java components are removed

. Then from your desktop double-click on jre-1_6_0-windowsi586-p.exe to install the newest version.


Report Offensive Follow Up For Removal

Response Number 11
Name: Carnage
Date: March 25, 2007 at 09:52:04 Pacific
Reply:

Here is my AVG report:


AVG Anti-Spyware - Scan Report


+ Created at: 16:33:42 25/03/2007

+ Scan result:

HKU\S-1-5-21-2488947662-6215608-3527998805-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56F1D444-11BF-4879-A12B-79CF0177F038} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKU\S-1-5-21-2488947662-6215608-3527998805-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA0D26BD-9029-431A-86E0-83152D67828A} -> Adware.180Solutions : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TopSearch.TSLink -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TopSearch.TSLink.1 -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CLSID -> Adware.Altnet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\TopSearch.TSLink\CurVer -> Adware.Altnet : Cleaned with backup (quarantined).
C:\Program Files\INSTAFINK -> Adware.Gator : Cleaned with backup (quarantined).
HKU\S-1-5-21-2488947662-6215608-3527998805-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C2EEB4FA-B6D6-41B9-9CFA-ABA87F862BCB} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-2488947662-6215608-3527998805-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{59879FA4-4790-461C-A1CC-4EC4DE4CA483} -> Adware.RXToolbar : Cleaned with backup (quarantined).
C:\Program Files\DAEMON Tools\SetupDTSB.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
D:\Documents and Settings\CARNAGE\Desktop\SmitfraudFix.zip/SmitfraudFix/SmiUpdate.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
D:\Documents and Settings\CARNAGE\Desktop\SmitfraudFix\SmiUpdate.exe -> Adware.SmiUpdate : Cleaned with backup (quarantined).
C:\Program Files\Mozilla Firefox\plugins\npclntax.dll -> Adware.Zango : Cleaned with backup (quarantined).
D:\Documents and Settings\CARNAGE\My Documents\My Games\Emulation\NeoGeo\NeoRageX v4.8.exe -> Backdoor.Sdbot : Cleaned with backup (quarantined).
D:\Documents and Settings\CARNAGE\My Documents\My Games\Emulation\NeoGeo\neoragex48.zip/NeoRageX v4.8.exe -> Backdoor.Sdbot : Cleaned with backup (quarantined).
:mozilla.152:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.258:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.589:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@bulldog.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.757:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.758:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.762:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.763:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.764:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.767:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.768:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.769:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.72:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.73:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.134:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.135:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.136:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.51:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.52:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.53:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.54:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.56:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.293:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.295:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.85:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.86:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.65:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.68:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.35:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.160:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.195:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.199:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.231:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.744:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.745:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.774:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.820:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.137:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.138:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Com : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.88:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.89:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.549:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.7:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.233:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.81:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.802:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.803:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Fortunecity : Cleaned.
:mozilla.670:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.665:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.682:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.818:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.819:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.843:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.844:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.848:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.252:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.539:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.40:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.41:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.557:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.558:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.559:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.560:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.561:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.562:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.729:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.730:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.638:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Need2find : Cleaned.
:mozilla.645:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Need2find : Cleaned.
:mozilla.526:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.527:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.528:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.529:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.530:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.173:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.129:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.165:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.60:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.61:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.151:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.153:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.154:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.155:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.156:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.579:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.580:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.83:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.84:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.833:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.42:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.43:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.44:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.45:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.46:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.47:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.105:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.106:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.107:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.108:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.109:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.110:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.111:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.112:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.113:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.114:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.115:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.116:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.117:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.118:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.119:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.120:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.121:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.122:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.123:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.124:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.100:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.101:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.102:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.103:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.104:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.95:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.96:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.97:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.98:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
:mozilla.99:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@counter8.sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.515:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.585:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.354:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.429:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.727:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.728:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Starware : Cleaned.
:mozilla.189:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.190:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.191:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.192:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.193:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.194:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.196:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.197:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.198:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.200:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.201:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.202:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.203:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.204:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.205:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.206:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.207:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.208:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.507:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.508:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.482:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.55:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.492:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.172:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.274:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.479:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.480:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.687:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.537:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.775:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : Cleaned.
:mozilla.185:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.79:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.80:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.82:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
D:\Documents and Settings\CARNAGE\Cookies\carnage@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.279:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.298:D:\Documents and Settings\CARNAGE\Application Data\Mozilla\Firefox\Profiles\2lvult1e.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end



Report Offensive Follow Up For Removal

Response Number 12
Name: Carnage
Date: March 25, 2007 at 09:53:33 Pacific
Reply:

Here is a new HijackThis report:

Logfile of HijackThis v1.99.1
Scan saved at 17:52:42, on 25/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\cisvc.exe
c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\UAService7.exe
c:\APPS\Powercinema\Kernel\TV\CLSched.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
C:\Apps\Powercinema\PCMService.exe
C:\apps\ABoard\ABoard.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\apps\ABoard\AOSD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE
C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
C:\APPS\SMP\SmpSys.exe
C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell
R3 - URLSearchHook: &Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
R3 - URLSearchHook: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SWEETIE - {1A0AADCD-3A72-4b5f-900F-E3BB5A838E2A} - C:\PROGRA~1\MACROG~1\SWEETI~1\toolbar.dll
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O3 - Toolbar: SweetIM For Internet Explorer - {BC4FFE41-DE9F-46fa-B455-AAD49B9F9938} - C:\Program Files\Macrogaming\SweetIMBarForIE\toolbar.dll
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [Ulead AutoDetector v2] C:\Program Files\Common Files\Ulead Systems\AutoDetector\monitor.exe
O4 - HKLM\..\Run: [PCMService] "c:\Apps\Powercinema\PCMService.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32"
O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SemanticInsight] C:\Program Files\RXToolBar\Semantic Insight\SemanticInsight.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -onlytray
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program Files\Thomson\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [kav] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe
O4 - HKCU\..\Run: [STManager] "C:\Program Files\SpeedTouch\Dr SpeedTouch\drst.exe" -b
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [SweetIM] C:\Program Files\Macrogaming\SweetIM\SweetIM.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: wkcalrem.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM
O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - D:\Documents and Settings\CARNAGE\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\uk.htm
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/no...
O16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binar...
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/s...
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binar...
O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.12) - http://www.yougamers.com/systeminfo...
O17 - HKLM\System\CCS\Services\Tcpip\..\{C29E58B1-1CDC-436B-B309-160F0EA3C764}: NameServer = 85.255.116.100 85.255.112.169
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\APPS\Powercinema\Kernel\TV\CLSched.exe
O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Program Files\CyberLink\Shared Files\CLML_NTService\CLMLServer.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe



Report Offensive Follow Up For Removal

Response Number 13
Name: Carnage
Date: March 25, 2007 at 09:55:03 Pacific
Reply:

Whats next?


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: monstermarketplace-need help removi

I need help please!
    Summary: ... further to #4. Seems the current title is "a-squared Free". For the future - try to think of an informative subject line, helps attract the people most likely to know about your problem (everyone...
www.computing.net/answers/security/i-need-help-please/18487.html

hacked by find4u.net, need help
    Summary: I saw recent post but I still need help. I tried the safemode search option looking to remove winlogin.exe file. however, only one winlogin.exe file was found with the accepted 505kb size range. Spy...
www.computing.net/answers/security/hacked-by-find4unet-need-help/11676.html

Registry Cleaner 2.5 Need Help
    Summary: I have the same problem: was infected and I cannot access gmail.com and orkut.com I need help, please ...
www.computing.net/answers/security/registry-cleaner-25-need-help/20258.html