Steviebone
-
Content Count
31 -
Joined
-
Last visited
Content Type
Profiles
Forums
Calendar
Posts posted by Steviebone
-
-
Ok Im mad now... lol, I set spyware detector to run again every few hours for a while... the trojan zapchast resurfaced in a restore point file... to my knowledge I have not rebooted since the last scan... so this bugger is re-asserting itself somehow... in fact the only thing run inbetween scans was dss...
c:\system volume information\_restore{2201e7e1-07c6-42bd-9a3d-8ec03be3ea1a}\rp479\a0107864.dll#@#2DBB00F5E171FF1101C350516116DCBC
next to last one added.... this sucker was added minutes before dss was run while I was gone (I was not home at the time).
In all my years of computing I have never run across such a persistant SOB. HELP!
-
ok I ran the scan... can I upload this file to u rather than post the results to the world? There's some sensitive data there...
Steve
---- edit -----
ok you have a private message with instructions how to find the log...
-
thanks,,,
I will do as u instructed... one update... I ran an indepth scan using Spyware Detector... it found the Zapchast trojan and a keylogger again. I'm getting bounce backs from mail I havent sent so I'm pretty sure theres another dam mailbot on here again.
Funny, avast and nod32 dont pick any of this stuff up!
Will get back to u... shortly
Thanks again!
-
Hello again... thanks for your previous help... no more rootkits that I know of, however, I have discovered that since disinfection I am having problems with Windows Firewall. After each reboot, some important entries are lost and Remote Assistance is enabled again. I have always had Remote Assistance disabled. In fact, even in services I have all the Remote entries disabled. The services are not being re-enabled, but the Remote Assistance checkbox in Windows Firewall IS being reset each time I reboot as well as most of the other exceptions that had already been set are lost altogether. This seems very nefarious to me.
I ran combofix again, no rootkits found.
Below is a new hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 6:31:12 PM, on 6/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\XP\System32\smss.exe
C:\XP\system32\winlogon.exe
C:\XP\system32\services.exe
C:\XP\system32\lsass.exe
C:\XP\system32\svchost.exe
C:\XP\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\XP\system32\spoolsv.exe
C:\XP\Explorer.EXE
C:\Program Files\Acronis\BackupServer\backupserver.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\XP\system32\nvsvc32.exe
C:\XP\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Eset\nod32kui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\PTSync\PTSync.exe
C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE
c:\program files\vvengine\vvengine.exe
C:\Program Files\SpywareDetector\SDSystemTray.exe
C:\Program Files\SpywareDetector\SDService.exe
C:\Ascend\SCM\scm.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: QFX Software KeyScrambler - {2B9F5787-88A5-4945-90E7-C4B18563BC5E} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dll
O4 - HKLM\..\Run: [sDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO
O4 - HKLM\..\Run: [systemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe -AUTO
O4 - HKLM\..\RunOnce: [speedStartup] C:\Program Files\Speed Startup\speedstartup.exe runonce
O4 - HKCU\..\Run: [speedStartup] C:\Program Files\Speed Startup\speedstartup.exe bootup
O8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: (no name) - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O9 - Extra 'Tools' menuitem: &KeyScrambler... - {5C106A59-CC3C-4caa-81A4-6D909B5ACE23} - C:\Program Files\KeyScrambler\keyscramblerIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d...can_unicode.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.5.0_06) -
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} (Java Plug-in 1.5.0_09) -
O16 - DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} (Java Plug-in 1.5.0_10) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe
O23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
PS: I noticed the Windows messenger crap was back... I thought I had that removed... Id like to get rid of that... perhaps that is the culprit... only messaging installed is yahoo
PS2: http://www.myitforum.com/articles/15/view.asp?id=7033 shows how to remove W messenger
-
couldnt find a way to restrcit the scan to c: so I let it run until most of c & d were done and the stopped it. It found three threats, all of which were identifiable by me:
pskill - I use it to kill local process from a batch file before running games
ipscan - I use it to scan my network for open ports
lzx32 - quarantined by combofix (this was the culprit and is zipped up inside the combo quarantine folder)
couple of comments, couple of questions
first, I think I'll hold on to all the handy tools I have used during this process, don't see any need to to trash them... any reason I shouldn't run combofix once in a while? It seemed to find things nothing else did. Which brings me to my next question...
I have installed now on this computer: Avast, Nod32, AVG, Spyware Detector, SpybotS&D, Spysweeper, KeyScrambler, KeyloggerHunter. Avast and Nod32 have always worked together. So far, no problems running Spyware Detector at the same time either. The others I keep unloaded and run a scheduled scan with each of them periodically. When running scans from the others I have to disable everything else first (something I dont like to do since it requires me disconnecting the machine from the Internet for the duration).
I'm wondering why Nod32 and AVAST failed to pick up the rootkit even though in the case of AVAST I used a boot time scan. And, BTW... I could never find a way to to do a boot time scan with Nod32, making it next to useless IMO. Wish I could get my money back on that one.
So in your opinion, what is the best virus scanner to leave active? I really like avasts script scanner and the fact that u can turn on verbose display of real-time scans. This allowed me to spot a yahoo mail virus once that was running undetected by everything. Funny, Avast displayed the running script in the verbose window but failed to identify it as a virus. Nevertheless, has it not been for this feature of Avast I would never have spotted it so easily excepot through careful inspection of syslogs.
More importantly, in trying to understand how the infection got there in the first place... I am VERY careful NEVER to open any emails that I don't already know the origin of... even tho all the emails are scanned on inbound by at least three scanners... the ISP's, Nod32 and Avast. And I never browse the Internet at large and keep the IE settings pretty tight, following the server2003 model.
I use a hardware firewall which is set to reject EVERYTHING that is not explicitly allowed. And I regularly scan my network ports to make sure no holes open up. Of course, the Windows firewall, which also next to useless IMO, was left active. Should I run a software firewall in addition to the hardware one?
Recently, tho, I allowed someone to plug their laptop into my hub for a few minutes. Out of curiosity, I ran a virus check for them. Despite their assurances the system was clean, I found 42 viruses almost immediately (lol). I immediately disconnected the machine...
I had assumed that since the laptop was NOT configured to address my workgroup or domain and had no log on name and passwords that it could NOT communicate with the other computers on the network all of whom have guest access removed, etc. I know that none of the computers were visible to the laptops explorer, etc. However, I must now assume that I am overlooking something... could it be port 80? Could the laptop have infected the only XP machine on the subnet by channeling thru port 80? Seems unlikely since that computer had at least two virus scanners running at the time... As far as I can tell, all the other machines on the subnet are clean (they are all running 2003 server tho). Could the rootkit have proliferated to a neighboring machine without workgroup access and logon credientials?
My new rule: absolutely NO outside machines anywhere on my subnet even for a second.
The only other thing I can think of is that the infection was coincidental and resulted from something I loaded on to the machine that the virus scanners failed to pick up... after all they didn't see it when combofix did. This is the only machine I surf and get email from. That is an intentional design. All of the other computers on the subnet are used for specific purposes and are configured, in most cases, for little or no access to the outside world.
I know this is more security related dialogue, but any comments or suggestions?
Steve
-
lol, will do....
-
kapersky on-line was slower than dog... 1% complete after 6 hours... fook that... donwloaded the latest kaspesky but it wouldnt install as long as I had avast installed... sorry I already paid for avast and I like the script monitoring feature...
-
oops, forgot I had run avenger where I had already killed those files:
Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\fjobmayi
*******************
Script file located at: \??\C:\Program Files\kroancfe.txt
Script file opened successfully.
Script file read successfully
Backups directory opened successfully at C:\Avenger
*******************
Beginning to process script file:
File C:\XP\system32\71430B71.exe deleted successfully.
File C:\chdir.bat not found!
Deletion of file C:\chdir.bat failed!
Could not process line:
C:\chdir.bat
Status: 0xc0000034
File C:\XP\system32\drivers\k^nymapg.sys deleted successfully.
File C:\xqsjepbn.bat deleted successfully.
File C:\XP\system32\IE_Backup.reg deleted successfully.
File C:\XP\system32\Windows_Backup.reg deleted successfully.
File C:\XP\system32\startupBackup.reg deleted successfully.
File C:\XP\system\SysSD.dll deleted successfully.
File C:\XP\system32\CloseAll.exe deleted successfully.
File C:\XP\system32\CheckDll.dll deleted successfully.
File C:\XP\iun6002ev.exe deleted successfully.
Completed script processing.
*******************
Finished! Terminate.
-
ok, will do...
the newtasks I created... I was just trying to get the task scheduler to work... wanted to see if I deleted a task and recreated it... but no luck... i have those tasks backed up so I am prolly about to delete all of them... at present they keep trying to run but just generate 'could not start' messages...
will work the java over next...
get back to u later today...
and as always, thanks
-
lol, I just saw the vfp start thing in the registry report which u had me fix with the reg file... that should stop that bad boy from resurfacing, thanks. Can't believe I didnt think to scan the report for mentions of vfp...
--- On second look, Y is the CD drive and those files are only on the CD... so something else was running first...
-
************************* Rustock.b-fix v. 1.01 -- By ejvindh *************************
Tue 05/22/2007 13:56:46.09
No Rustock.b-rootkits found
******************************* End of Logfile ********************************
-
running the rustbfix thingy again next
-
ok, second combofix scan with all protective programs off did better (see below). Perhaps the combo was picking up on something in spydetector?
Anyway it found no lzx32 this time... curious....
As for the task manager thingy: 0x80090016: Keysey does not exist. I have googled the hell out of that one and tried every fix I could find including deletion of the RSA files, etc. There are no registry entries that MS talks about. I did find a few people complaining about this problem after applying updates.
"Staypuffer" - 2007-05-22 9:58:48 Service Pack 2
ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\"
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))
2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer
2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe
2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker
2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys
2007-05-21 01:20 <DIR> d-------- C:\avenger
2007-05-21 00:59 16 --a------ C:\chdir.bat
2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot
2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys
2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys
2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat
2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe
2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg
2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg
2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg
2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll
2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe
2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll
2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll
2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector
2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys
2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys
2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys
2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys
2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot
2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot
2007-05-19 18:08 164 --a------ C:\install.dat
2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot
2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy
2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker
2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker
2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google
2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy
2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry
2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap
2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap
2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss
2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules
2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google
2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug
2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace
2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD
2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll
2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys
2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys
2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP
2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe
2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys
2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys
2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys
2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr
2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 2
2007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster
2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll
2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll
2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys
2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll
2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup
2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll
2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll
2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace
2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft
2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys
2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO
2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr
2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr
2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr
2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr
2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon
2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software
2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software
2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!
2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat
2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll
2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker
2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch
2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe
2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive
2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!
2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys
2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn
2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor
2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone
2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch
2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe
2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon
2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE
2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL
2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]
{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]
C:\Program Files\SpywareDetector\SDNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]
AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"
Contents of the 'Scheduled Tasks' folder
2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job
2007-05-22 10:54:10 C:\XP\tasks\New Task.job
2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job
2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job
2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_Bills.job
2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job
2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job
2007-05-22 15:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job
2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job
2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job
2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job
2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job
2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job
2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job
2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job
2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job
2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job
2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job
2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job
2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job
2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-22 10:06:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-22 10:08:30
C:\ComboFix-quarantined-files.txt ... 2007-05-22 10:08
C:\ComboFix2.txt ... 2007-05-22 09:39
C:\ComboFix3.txt ... 2007-05-20 14:38
--- E O F ---
2006-04-26 00:31 775 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir
2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip
2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.log
Folder PATH listing for volume PrimaryC
Volume serial number is 747C-9F49
C:\QOOBOX
\---Quarantine
| catchme.log
| catchme2007-05-20_135445.26.zip
|
+---C
| +---DOCUME~1
| | \---STAYPU~1
| | \---Desktop
| | Internet Explorer.lnk.vir
| |
| \---Program Files
| INSTALL.LOG.vir
|
\---Registry_backups -
oh and btw, fwiw, somewhere in this whole process my task scheduler got broke... always gives me an 0x80090016 error... tried all the published fixes for it to no avail the taskscheduler can no longer see or set credentials...
-
well chit...
I ran combofix, but I forgot to turn off all my protective programs first. Immediately upon execution spydetector popped up window that said "Rustock.b successfully removed". Then towards the end of the scan another popup saying Trojan.Agent removed. Then combo said disinfecting and rebooting. After reboot, the following log was generated:
"Staypuffer" - 2007-05-22 9:18:29 Service Pack 2
ComboFix 07-05.20.9.V - Running from: "J:\Spywaredetector\"
Rootkit driver lzx32 is present. A rootkit scan is required
((((((((((((((((((((((((((((((( Files Created from 2007-04-05 to 2007-05-22 ))))))))))))))))))))))))))))))))))
2007-05-21 23:15 <DIR> d-------- C:\ProcessExplorer
2007-05-21 09:17 5,632 --a------ C:\XP\system32\71430B71.exe
2007-05-21 08:57 <DIR> d-------- C:\RkUnhooker
2007-05-21 01:33 3,968 --a------ C:\XP\system32\drivers\AvgArCln.sys
2007-05-21 01:20 <DIR> d-------- C:\avenger
2007-05-21 00:59 16 --a------ C:\chdir.bat
2007-05-20 17:30 <DIR> d-------- C:\DOCUME~1\NETWOR~1.NTA\APPLIC~1\Webroot
2007-05-20 17:18 3,968 --a------ C:\XP\system32\drivers\AvgAsCln.sys
2007-05-20 14:53 60,416 --a------ C:\XP\system32\drivers\k^nymapg.sys
2007-05-20 14:53 1,075 --a------ C:\xqsjepbn.bat
2007-05-20 14:04 49,152 --a------ C:\XP\nircmd.exe
2007-05-20 06:42 2,922 --a------ C:\XP\system32\IE_Backup.reg
2007-05-20 06:42 2,846,854 --a------ C:\XP\system32\Windows_Backup.reg
2007-05-20 06:42 2,588 --a------ C:\XP\system32\startupBackup.reg
2007-05-20 02:27 123 --a------ C:\XP\system\SysSD.dll
2007-05-20 02:26 63,192 --a------ C:\XP\system32\CloseAll.exe
2007-05-20 02:26 270,336 --a------ C:\XP\system32\CheckDll.dll
2007-05-20 02:26 1,019,904 --a------ C:\XP\system32\VchReg.dll
2007-05-20 02:25 <DIR> d-------- C:\Program Files\SpywareDetector
2007-05-19 18:15 22,080 --a------ C:\XP\system32\drivers\sshrmd.sys
2007-05-19 18:15 21,056 --a------ C:\XP\system32\drivers\sskbfd.sys
2007-05-19 18:15 20,544 --a------ C:\XP\system32\drivers\SSFS0509.sys
2007-05-19 18:15 144,960 --a------ C:\XP\system32\drivers\ssidrv.sys
2007-05-19 18:15 <DIR> d-------- C:\DOCUME~1\LOCALS~1.NTA\APPLIC~1\Webroot
2007-05-19 18:14 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Webroot
2007-05-19 18:08 164 --a------ C:\install.dat
2007-05-19 18:08 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Webroot
2007-05-18 11:43 <DIR> d--h----- C:\XP\system32\GroupPolicy
2007-05-17 22:04 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Texture Maker
2007-05-17 22:03 <DIR> d-------- C:\Program Files\Texture Maker
2007-05-17 17:39 <DIR> d-------- C:\DOCUME~1\STAYPU~1\APPLIC~1\Google
2007-05-15 13:43 <DIR> d-------- C:\DOCUME~1\ALLUSE~1.XP\APPLIC~1\Spybot - Search & Destroy
2007-05-08 01:29 <DIR> d-------- C:\Program Files\Network Chemistry
2007-05-08 01:17 <DIR> d-------- C:\Program Files\WinPcap
2007-05-08 01:17 <DIR> d-------- C:\Program Files\Nmap
2007-04-26 18:37 298,496 --a------ C:\XP\uninst.exe
(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))
2007-05-22 14:08:10 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\dvdcss
2007-05-21 05:50:19 -------- d-----w C:\Program Files\Common Files\Merge Modules
2007-05-17 22:39:02 -------- d-----w C:\Program Files\Google
2007-05-16 04:57:49 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\WeatherBug
2007-05-15 18:38:06 -------- d-----w C:\Program Files\MySpace
2007-05-07 17:28:32 -------- d-----w C:\Program Files\EPSON Print CD
2007-05-07 13:39:36 298,104 ----a-w C:\XP\system32\imon.dll
2007-05-07 13:39:34 512,096 ----a-w C:\XP\system32\drivers\amon.sys
2007-05-07 13:39:33 15,424 ----a-w C:\XP\system32\drivers\nod32drv.sys
2007-05-03 05:49:55 -------- d-----w C:\Program Files\LeapFTP
2007-04-30 15:46:10 745,600 ----a-w C:\XP\system32\aswBoot.exe
2007-04-30 15:41:55 85,952 ----a-w C:\XP\system32\drivers\aswmon.sys
2007-04-30 15:41:42 94,552 ----a-w C:\XP\system32\drivers\aswmon2.sys
2007-04-30 15:39:41 23,416 ----a-w C:\XP\system32\drivers\aswRdr.sys
2007-04-30 15:38:51 43,176 ----a-w C:\XP\system32\drivers\aswTdi.sys
2007-04-30 15:37:23 26,888 ----a-w C:\XP\system32\drivers\aavmker4.sys
2007-04-30 15:35:28 95,872 ----a-w C:\XP\system32\AVASTSS.scr
2007-04-30 08:55:32 -------- d-----w C:\Program Files\ViceVersa Pro 2
2007-04-26 23:09:43 -------- d-----w C:\Program Files\IsoBuster
2007-04-25 08:04:12 88,952 ----a-w C:\XP\system32\packet.dll
2007-04-25 08:04:12 68,480 ----a-w C:\XP\system32\wanpacket.dll
2007-04-25 08:04:12 42,000 ----a-w C:\XP\system32\drivers\npf.sys
2007-04-25 08:04:12 240,496 ----a-w C:\XP\system32\wpcap.dll
2007-04-21 03:30:35 -------- d-----w C:\Program Files\Speed Startup
2007-04-20 03:28:54 1,040,384 ----a-w C:\XP\system32\libeay32.dll
2007-04-20 03:27:57 196,608 ----a-w C:\XP\system32\ssleay32.dll
2007-04-16 06:45:33 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\MySpace
2007-04-09 04:37:55 -------- d-----w C:\Program Files\SlySoft
2007-04-09 03:42:45 29,392 ----a-w C:\XP\system32\drivers\secdrv.sys
2007-04-08 22:59:29 -------- d-----w C:\Program Files\PowerISO
2007-04-06 21:14:04 542 ----a-w C:\hrlist.scr
2007-04-06 20:32:08 371 ----a-w C:\getbilldirs.scr
2007-04-06 20:31:54 371 ----a-w C:\gethbdirs.scr
2007-04-06 20:28:28 139 ----a-w C:\tryftp.scr
2007-04-06 05:46:37 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\Zeon
2007-04-06 05:02:00 -------- d-----w C:\Program Files\G-Lock Software
2007-04-05 15:31:07 -------- d-----w C:\DOCUME~1\STAYPU~1\APPLIC~1\G-Lock Software
2007-04-04 10:33:04 -------- d-----w C:\Program Files\Yahoo!
2007-03-18 17:28:30 5,885 ----a-w C:\XP\mozver.dat
2007-03-17 13:43:01 292,864 ----a-w C:\XP\system32\winsrv.dll
2007-03-15 19:35:33 -------- d-----w C:\Program Files\Tracker
2007-03-15 10:52:51 -------- d-----w C:\Program Files\Registry Watch
2007-03-15 10:14:59 720,896 ----a-w C:\XP\iun6002ev.exe
2007-03-15 04:18:10 -------- d-----w C:\Program Files\Salive
2007-03-15 04:17:28 -------- d--h--r C:\DOCUME~1\STAYPU~1\APPLIC~1\yahoo!
2007-03-08 15:36:28 577,536 ----a-w C:\XP\system32\user32.dll
2007-03-08 15:36:28 40,960 ----a-w C:\XP\system32\mf3216.dll
2007-03-08 15:36:28 281,600 ----a-w C:\XP\system32\gdi32.dll
2007-03-08 13:47:48 1,843,584 ----a-w C:\XP\system32\win32k.sys
2007-03-08 04:59:59 -------- d-----w C:\Program Files\DirPrn
2007-03-07 09:16:28 -------- d-----w C:\Program Files\'Net Monitor
2007-03-07 09:13:15 -------- d-----w C:\Program Files\PTZone
2007-03-07 09:10:26 -------- d-----w C:\Program Files\WinWatch
2007-03-07 09:10:21 249,856 ------w C:\XP\Setup1.exe
2007-03-07 09:10:09 -------- d-----w C:\Program Files\LanMon
2007-03-07 09:09:11 73,216 ------w C:\XP\ST6UNST.EXE
2007-02-28 08:59:01 26,000 ----a-w C:\XP\system32\E3TL.DLL
2007-02-05 20:17:02 185,344 ----a-w C:\XP\system32\upnphost.dll
(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll [2006-11-09 16:21]
{AE7CD045-E861-484f-8273-0445EE161910}=D:\Acrobat7\Acrobat\AcroIEFavClient.dll [2005-09-24 00:41]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\XP\system32\NvCpl.dll" [2005-10-28 16:06]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SpeedStartup"="C:\Program Files\Speed Startup\speedstartup.exe" [2006-12-14 17:12]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonce]
"SpeedStartup"=C:\Program Files\Speed Startup\speedstartup.exe runonce
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"="D:\Internet\eudora\EuShlExt.dll" [2005-11-14 16:15]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll" [2006-09-28 09:13]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify]
C:\Program Files\SpywareDetector\SDNotify.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\WebrootSpySweeperService]
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost *netsvcs*
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\Y]
AutoRun\command- Y:\vfpstart.exe IE5="vfpstart.hta" IELess="vfpstart.htm"
Contents of the 'Scheduled Tasks' folder
2007-05-22 12:48:24 C:\XP\tasks\New Task 2.job
2007-05-22 10:54:10 C:\XP\tasks\New Task.job
2007-05-22 10:50:00 C:\XP\tasks\_viceversapr2_task_Bashful2Booby.job
2007-05-22 11:30:00 C:\XP\tasks\_viceversapr2_task_batch.job
2007-05-22 13:30:00 C:\XP\tasks\_viceversapr2_task_Bills.job
2007-03-26 09:40:18 C:\XP\tasks\_viceversapr2_task_documents_and_settings.job
2007-05-22 11:10:00 C:\XP\tasks\_viceversapr2_task_Eudora.job
2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_hits prg to Tweetie D.job
2007-05-22 06:00:00 C:\XP\tasks\_viceversapr2_task_HITSSOURCES.job
2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_HITSVEN.job
2007-05-22 13:15:00 C:\XP\tasks\_viceversapr2_task_Idisk.job
2007-05-22 13:00:00 C:\XP\tasks\_viceversapr2_task_Links.job
2007-03-26 09:33:37 C:\XP\tasks\_viceversapr2_task_madden.job
2007-05-22 09:59:49 C:\XP\tasks\_viceversapr2_task_newag.job
2007-05-22 10:30:00 C:\XP\tasks\_viceversapr2_task_OHITS.job
2007-05-22 11:34:00 C:\XP\tasks\_viceversapr2_task_personal.job
2007-05-22 14:00:00 C:\XP\tasks\_viceversapr2_task_ServersAlive.job
2007-05-22 12:00:53 C:\XP\tasks\_viceversapr2_task_Steviebone.job
2007-03-26 11:38:02 C:\XP\tasks\_viceversapr2_task_Torrents.job
2007-05-22 14:15:00 C:\XP\tasks\_viceversapr2_task_txdot.job
2007-05-22 11:20:00 C:\XP\tasks\_viceversapr2_task_visaversaprofiles.job
********************************************************************
catchme 0.3.660 W2K/XP/Vista - userland rootkit detector by Gmer, http://www.gmer.net
Rootkit scan 2007-05-22 09:31:21
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
********************************************************************
Completion time: 2007-05-22 9:39:30 - machine was rebooted
C:\ComboFix-quarantined-files.txt ... 2007-05-22 09:39
C:\ComboFix2.txt ... 2007-05-20 14:38
C:\ComboFix3.txt ... 2007-05-20 14:04
--- E O F ---
here is the quarantine log:
2006-04-26 00:31 775 --a------ C:\Qoobox\Quarantine\C\DOCUME~1\STAYPU~1\Desktop\Internet Explorer.lnk.vir
2006-05-05 03:30 300 --a------ C:\Qoobox\Quarantine\C\Program Files\INSTALL.LOG.vir
2007-05-20 10:22 77725 --a------ C:\Qoobox\Quarantine\catchme2007-05-20_135445.26.zip
2007-05-22 09:27 500 --a------ C:\Qoobox\Quarantine\catchme.log
Folder PATH listing for volume PrimaryC
Volume serial number is 747C-9F49
C:\QOOBOX
\---Quarantine
| catchme.log
| catchme2007-05-20_135445.26.zip
|
+---C
| +---DOCUME~1
| | \---STAYPU~1
| | \---Desktop
| | Internet Explorer.lnk.vir
| |
| \---Program Files
| INSTALL.LOG.vir
|
\---Registry_backupsI'm guessing I need to run another scan with the HIPS off?
-
file uploaded... will post combofix log shortly...
sysinternals yes... great replacement for task manager... still wondering why the USB interuupts were triggering with no disk access but then I think USB drives are polled... one reason why they stink...
btw, u been plenty of help, thanks
You been (at least) a half a step ahead of me the whole way....Process Explorer (the one from SysInternals ??) was my next recommendation to you.All of your scan look good w/ possibly one exception. I'd like you to upload one file or me to look at please.
Please go here to upload a suspicious file for analysis.
- Enter your username from this forum
- Copy and paste the link to this thread
- Browse for this filename: C:\XP\system32\DRIVERS\EXPORTIT.SYS
- In the comments, please mention that I asked you to upload this file
- Click on Send File
The ONLY other references I find to it are a Kodak file and it's allways in a Kodak sub folder..Just like to look at it and make sure.
Jst keep an eye on your resources (Doesn't really seem I need to tell YOU that tho )
If you would give one final (?) Combofix log and let me have a look at that file hopefully we can put an end to this..
Sorry I wasn't timely enough to be of more assistance to you in this..but it seems you REALLY had it pretty well handled all along.
- Enter your username from this forum
-
ok I think I fugured it out... I downloaded a program called process explorer which is more detailed than task manager (of course everything Windows has built in sucks compared to third party alternatives!). This program broke the activity down much better. The spikes were coming from hardware interrupts. Hardware interrupts? Yep. It was all the USB drives. I disconnected the USB drives and wahla... the interrupt load went down as did the overall activity which now hovers between 0-4%... acceptable if not perfect.
I'm hoping the system is now clean. Let me know if you see anything else in the logs that appears suspicous... I never liked USB drives anyway...
I suppose there's still the small possibility that the rogue program resided on one of the drives and was running from there which was causing the interrupts....
-
Backlight didn't find anything.
BTW, I have 8 other machines in here including some servers. Even with apps running on them most of them idle at 0-2% only spiking when an app does something (such as a web hit). Even then the spike is small and non-repetitive.
The activity here is repetitive and continuous... I'm pretty sure there's still a rogue process running somewhere....
-
ok thanks for all ur help..
a couple of notes, I finally let the installer go... whatever it did it did and has not come back the last few reboots
the rootkit program runs the hidden file scan but crashes near the end every time... Ive checked the disk for errors but nada... at the point only one file is listed in the window... to the best of my knowledege no log is ever written for that function, the other three logs are copied below..
As for resource useage, in safe mode of course the task manager looks right. I disabled ALL of the programs however for these tests, following the instructions in the page you referenced AND going to startup controller and disabling all of them... I then checked on reboot and none of the programs had loaded. Even still, with NONE of those programs loaded the activity remains... including constant memory allocation changes... again task manager only indicates system idle at 98-99% even though no applications are opne there doesnt appear to be anything else running.
I will download backlight next and post the results.
Here are the other logs:
RkUnhooker report generator v0.6
==============================================
Rootkit Unhooker kernel version: 3.31.150.420
==============================================
Windows Major Version: 5
Windows Minor Version: 1
Windows Build Number: 2600
==============================================
Process: System
Process Id: 4
EPROCESS Address: 0x82FCA490
Process: C:\XP\system32\nvsvc32.exe
Process Id: 288
EPROCESS Address: 0x82487890
Process: C:\XP\system32\smss.exe
Process Id: 532
EPROCESS Address: 0x82494020
Process: C:\XP\system32\csrss.exe
Process Id: 648
EPROCESS Address: 0x8217A360
Process: C:\XP\system32\winlogon.exe
Process Id: 676
EPROCESS Address: 0x822EEBC8
Process: C:\XP\system32\services.exe
Process Id: 720
EPROCESS Address: 0x8213CC88
Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE
Process Id: 724
EPROCESS Address: 0x81E6ADA0
Process: C:\XP\system32\lsass.exe
Process Id: 732
EPROCESS Address: 0x82169A18
Process: C:\XP\system32\svchost.exe
Process Id: 884
EPROCESS Address: 0x82113460
Process: C:\XP\system32\svchost.exe
Process Id: 972
EPROCESS Address: 0x820E1020
Process: C:\XP\system32\svchost.exe
Process Id: 1028
EPROCESS Address: 0x820CE300
Process: C:\Program Files\SpywareDetector\SDService.exe
Process Id: 1076
EPROCESS Address: 0x824D5AC8
Process: C:\XP\system32\svchost.exe
Process Id: 1088
EPROCESS Address: 0x820DBB50
Process: C:\XP\system32\svchost.exe
Process Id: 1132
EPROCESS Address: 0x82492980
Process: C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
Process Id: 1148
EPROCESS Address: 0x820DC8E0
Process: C:\Program Files\Alwil Software\Avast4\ashServ.exe
Process Id: 1204
EPROCESS Address: 0x820CB8E0
Process: C:\XP\system32\spoolsv.exe
Process Id: 1408
EPROCESS Address: 0x82054B30
Process: C:\Program Files\Common Files\Acronis\Agent\agent.exe
Process Id: 1524
EPROCESS Address: 0x8202BDA0
Process: C:\Program Files\Acronis\BackupServer\backupserver.exe
Process Id: 1540
EPROCESS Address: 0x82017DA0
Process: C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
Process Id: 1572
EPROCESS Address: 0x82060350
Process: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
Process Id: 1608
EPROCESS Address: 0x8208C020
Process: C:\Program Files\PTSync\PTSync.exe
Process Id: 1616
EPROCESS Address: 0x81EAB020
Process: C:\XP\system32\svchost.exe
Process Id: 1620
EPROCESS Address: 0x8204CDA0
Process: C:\Program Files\Acronis\GroupServer\GroupServer.exe
Process Id: 1704
EPROCESS Address: 0x81FEE5B0
Process: C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
Process Id: 1780
EPROCESS Address: 0x81F9DDA0
Process: C:\XP\system32\wdfmgr.exe
Process Id: 1996
EPROCESS Address: 0x81FE6890
Process: C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Process Id: 2120
EPROCESS Address: 0x821B0890
Process: C:\XP\system32\taskmgr.exe
Process Id: 2412
EPROCESS Address: 0xFE03F608
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
Process Id: 2436
EPROCESS Address: 0x8214C930
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
Process Id: 2468
EPROCESS Address: 0x82E68020
Process: C:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXE
Process Id: 2484
EPROCESS Address: 0xFDA9B890
Process: C:\XP\system32\alg.exe
Process Id: 2712
EPROCESS Address: 0x81EC7890
Process: C:\XP\system32\wuauclt.exe
Process Id: 2888
EPROCESS Address: 0x82E54020
Process: C:\RkUnhooker\oAi7c8OoI7xio.exe
Process Id: 3028
EPROCESS Address: 0xFCFC95B0
Process: C:\XP\explorer.exe
Process Id: 3852
EPROCESS Address: 0x81E27DA0
---------------------
RkUnhooker report generator v0.6
==============================================
Rootkit Unhooker kernel version: 3.31.150.420
==============================================
Windows Major Version: 5
Windows Minor Version: 1
Windows Build Number: 2600
==============================================
Driver:
Address: 0xF853D000
Size: 98304 bytes
Driver: ?_unknown_code_page_?
Address: 0x82F6F278
Size: 3464 bytes
Driver: ?_unknown_code_page_?
Address: 0x82DC1B78
Size: 1160 bytes
Driver: ?_unknown_code_page_?
Address: 0x82D49008
Size: 4088 bytes
Driver: ?_unknown_code_page_?
Address: 0x82E775C8
Size: 2616 bytes
Driver: ?_unknown_code_page_?
Address: 0x82985D68
Size: 664 bytes
Driver: ?_unknown_code_page_?
Address: 0x82985C40
Size: 960 bytes
Driver: ?_unknown_code_page_?
Address: 0x82985B18
Size: 1256 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C387B0
Size: 2128 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C38688
Size: 2424 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C38560
Size: 2720 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C38438
Size: 3016 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C38310
Size: 3312 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C381E8
Size: 3608 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C379A0
Size: 1632 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C37888
Size: 1912 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C37760
Size: 2208 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C37638
Size: 2504 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C37510
Size: 2800 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C373E8
Size: 3096 bytes
Driver: ?_unknown_code_page_?
Address: 0x82C372C0
Size: 3392 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC810
Size: 2032 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC6E8
Size: 2328 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC5C0
Size: 2624 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC498
Size: 2920 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC370
Size: 3216 bytes
Driver: ?_unknown_code_page_?
Address: 0x829AC248
Size: 3512 bytes
Driver: ?_unknown_code_page_?
Address: 0x829ABDA0
Size: 608 bytes
Driver: ?_unknown_code_page_?
Address: 0x82AE81A0
Size: 3680 bytes
Driver: ?_unknown_code_page_?
Address: 0x824D0820
Size: 2016 bytes
Driver: ?_unknown_code_page_?
Address: 0x824F52E8
Size: 3352 bytes
Driver: ?_unknown_code_page_?
Address: 0x82B9EFA8
Size: 88 bytes
Driver: ?_unknown_code_page_?
Address: 0x82B9EF30
Size: 208 bytes
Driver: ?_unknown_code_page_?
Address: 0x8245C750
Size: 2224 bytes
Driver: ?_unknown_code_page_?
Address: 0x820AEBD0
Size: 1072 bytes
Driver: ?_unknown_code_page_?
Address: 0x824D4370
Size: 3216 bytes
Driver: ?_unknown_code_page_?
Address: 0x829929E8
Size: 1560 bytes
Driver: ?_unknown_code_page_?
Address: 0x82DB3430
Size: 3024 bytes
Driver: ?_unknown_code_page_?
Address: 0x82AF17E0
Size: 2080 bytes
Driver: ?_unknown_code_page_?
Address: 0x8245E1A0
Size: 3680 bytes
Driver: a347bus.sys
Address: 0xF862D000
Size: 163840 bytes
Driver: a347scsi.sys
Address: 0xF8B80000
Size: 8192 bytes
Driver: C:\XP\System32\Drivers\Aavmker4.SYS
Address: 0xF8A76000
Size: 20480 bytes
Driver: ACPI.sys
Address: 0xF85FF000
Size: 188416 bytes
Driver: ACPI_HAL
Address: 0x806EC000
Size: 81280 bytes
Driver: C:\XP\system32\drivers\aec.sys
Address: 0xB92B8000
Size: 143360 bytes
Driver: C:\XP\system32\drivers\Afc.sys
Address: 0xF8A5E000
Size: 32768 bytes
Driver: C:\XP\System32\drivers\afd.sys
Address: 0xF67B8000
Size: 139264 bytes
Driver: C:\XP\System32\DRIVERS\amdk7.sys
Address: 0xF8726000
Size: 40960 bytes
Driver: C:\XP\system32\drivers\amon.sys
Address: 0xB9892000
Size: 503808 bytes
Driver: C:\XP\System32\Drivers\AnyDVD.sys
Address: 0xF8786000
Size: 36864 bytes
Driver: C:\XP\System32\Drivers\Asapi.SYS
Address: 0xF8936000
Size: 32768 bytes
Driver: C:\XP\System32\drivers\aspi32.sys
Address: 0xF669E000
Size: 20480 bytes
Driver: C:\XP\System32\Drivers\aswMon2.SYS
Address: 0xB9B92000
Size: 90112 bytes
Driver: C:\XP\System32\Drivers\aswRdr.SYS
Address: 0xB9564000
Size: 16384 bytes
Driver: C:\XP\System32\Drivers\aswTdi.SYS
Address: 0xF8886000
Size: 36864 bytes
Driver: C:\XP\System32\DRIVERS\audstub.sys
Address: 0xF8CBB000
Size: 4096 bytes
Driver: C:\XP\System32\DRIVERS\AvgArCln.sys
Address: 0xF8D0F000
Size: 4096 bytes
Driver: avgarkt.sys
Address: 0xF8B7A000
Size: 8192 bytes
Driver: C:\XP\System32\DRIVERS\AvgAsCln.sys
Address: 0xF8D19000
Size: 4096 bytes
Driver: C:\XP\System32\Drivers\Beep.SYS
Address: 0xF8B9C000
Size: 8192 bytes
Driver: C:\XP\system32\BOOTVID.dll
Address: 0xF8A86000
Size: 12288 bytes
Driver: C:\XP\System32\Drivers\Cdfs.SYS
Address: 0xF7BC8000
Size: 65536 bytes
Driver: C:\XP\System32\DRIVERS\cdrom.sys
Address: 0xF8796000
Size: 53248 bytes
Driver: C:\XP\System32\DRIVERS\CLASSPNP.SYS
Address: 0xF86E6000
Size: 53248 bytes
Driver: C:\XP\system32\drivers\cmaudio.sys
Address: 0xF7F05000
Size: 380928 bytes
Driver: C:\XP\system32\DRIVERS\ctoss2k.sys
Address: 0xF7D17000
Size: 196608 bytes
Driver: C:\XP\system32\DRIVERS\ctsfm2k.sys
Address: 0xF7C2D000
Size: 155648 bytes
Driver: C:\XP\system32\DRIVERS\DcCam.sys
Address: 0xF8846000
Size: 36864 bytes
Driver: C:\XP\system32\drivers\dcfs2k.sys
Address: 0xF6168000
Size: 40960 bytes
Driver: disk.sys
Address: 0xF86D6000
Size: 36864 bytes
Driver: C:\XP\System32\drivers\dmboot.sys
Address: 0xF7C53000
Size: 802816 bytes
Driver: dmio.sys
Address: 0xF8555000
Size: 155648 bytes
Driver: dmload.sys
Address: 0xF8B7E000
Size: 8192 bytes
Driver: C:\XP\system32\drivers\DMusic.sys
Address: 0xB9648000
Size: 53248 bytes
Driver: C:\XP\system32\drivers\drmk.sys
Address: 0xF8736000
Size: 61440 bytes
Driver: C:\XP\system32\drivers\drmkaud.sys
Address: 0xF8D88000
Size: 4096 bytes
Driver: C:\XP\System32\Drivers\dump_atapi.sys
Address: 0xF60C8000
Size: 98304 bytes
Driver: C:\XP\System32\Drivers\dump_WMILIB.SYS
Address: 0xF8BC4000
Size: 8192 bytes
Driver: C:\XP\System32\drivers\Dxapi.sys
Address: 0xF66F2000
Size: 12288 bytes
Driver: C:\XP\System32\drivers\dxg.sys
Address: 0xBF000000
Size: 73728 bytes
Driver: C:\XP\System32\drivers\dxgthk.sys
Address: 0xF8CD1000
Size: 4096 bytes
Driver: C:\XP\System32\DRIVERS\el90xbc5.sys
Address: 0xF7C1C000
Size: 69632 bytes
Driver: C:\XP\System32\Drivers\ElbyCDFL.sys
Address: 0xF8A56000
Size: 28672 bytes
Driver: C:\XP\System32\Drivers\ElbyCDIO.sys
Address: 0xF8BC2000
Size: 8192 bytes
Driver: C:\XP\System32\Drivers\ElbyDelay.sys
Address: 0xF8B84000
Size: 8192 bytes
Driver: C:\XP\system32\DRIVERS\EXPORTIT.SYS
Address: 0xF6976000
Size: 155648 bytes
Driver: C:\XP\System32\DRIVERS\fdc.sys
Address: 0xF8A36000
Size: 28672 bytes
Driver: C:\XP\System32\Drivers\Fips.SYS
Address: 0xF88C6000
Size: 36864 bytes
Driver: C:\XP\System32\DRIVERS\flpydisk.sys
Address: 0xF89A6000
Size: 20480 bytes
Driver: fltmgr.sys
Address: 0xF8505000
Size: 131072 bytes
Driver: C:\XP\System32\Drivers\Fs_Rec.SYS
Address: 0xF8B96000
Size: 8192 bytes
Driver: ftdisk.sys
Address: 0xF857B000
Size: 126976 bytes
Driver: C:\XP\system32\DRIVERS\gameenum.sys
Address: 0xF8365000
Size: 12288 bytes
Driver: C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys
Address: 0xF8D80000
Size: 4096 bytes
Driver: C:\XP\system32\hal.dll
Address: 0x806EC000
Size: 81280 bytes
Driver: C:\XP\System32\Drivers\HIDCLASS.SYS
Address: 0xF8866000
Size: 36864 bytes
Driver: C:\XP\system32\DRIVERS\HIDPARSE.SYS
Address: 0xF89DE000
Size: 28672 bytes
Driver: hpt3xx.sys
Address: 0xF86C6000
Size: 45056 bytes
Driver: C:\XP\System32\Drivers\HTTP.sys
Address: 0xB9014000
Size: 266240 bytes
Driver: C:\XP\System32\DRIVERS\i8042prt.sys
Address: 0xF8756000
Size: 53248 bytes
Driver: C:\XP\system32\DRIVERS\imapi.sys
Address: 0xF8776000
Size: 45056 bytes
Driver: C:\XP\System32\DRIVERS\ipnat.sys
Address: 0xF6802000
Size: 135168 bytes
Driver: C:\XP\System32\DRIVERS\ipsec.sys
Address: 0xF687B000
Size: 77824 bytes
Driver: isapnp.sys
Address: 0xF8676000
Size: 36864 bytes
Driver: C:\XP\system32\drivers\iviaspi.sys
Address: 0xF8A6E000
Size: 24576 bytes
Driver: C:\XP\System32\DRIVERS\kbdclass.sys
Address: 0xF8A4E000
Size: 24576 bytes
Driver: C:\XP\system32\KDCOM.DLL
Address: 0xF8B76000
Size: 8192 bytes
Driver: C:\XP\system32\drivers\kmixer.sys
Address: 0xB928D000
Size: 176128 bytes
Driver: C:\XP\system32\drivers\ks.sys
Address: 0xF7EBE000
Size: 143360 bytes
Driver: KSecDD.sys
Address: 0xF84DC000
Size: 94208 bytes
Driver: C:\XP\system32\DRIVERS\L8042Kbd.sys
Address: 0xF8345000
Size: 12288 bytes
Driver: C:\XP\system32\DRIVERS\LHidKE.Sys
Address: 0xF89AE000
Size: 24576 bytes
Driver: C:\XP\System32\Drivers\LHidUsbK.Sys
Address: 0xF8856000
Size: 36864 bytes
Driver: C:\XP\system32\DRIVERS\LMouKE.Sys
Address: 0xF7BD8000
Size: 65536 bytes
Driver: C:\XP\system32\DRIVERS\lv302af.sys
Address: 0xF8BB0000
Size: 8192 bytes
Driver: C:\XP\system32\DRIVERS\LV302AV.SYS
Address: 0xF63C3000
Size: 913408 bytes
Driver: C:\XP\system32\DRIVERS\lvsvf2.sys
Address: 0xF61A8000
Size: 2207744 bytes
Driver: C:\XP\System32\Drivers\mnmdd.SYS
Address: 0xF8BA0000
Size: 8192 bytes
Driver: C:\XP\System32\DRIVERS\mouclass.sys
Address: 0xF8986000
Size: 24576 bytes
Driver: C:\XP\System32\DRIVERS\mouhid.sys
Address: 0xF696A000
Size: 12288 bytes
Driver: MountMgr.sys
Address: 0xF86A6000
Size: 45056 bytes
Driver: C:\XP\System32\DRIVERS\mrxdav.sys
Address: 0xB99FD000
Size: 184320 bytes
Driver: C:\XP\System32\DRIVERS\mrxsmb.sys
Address: 0xF66F6000
Size: 454656 bytes
Driver: C:\XP\System32\Drivers\Msfs.SYS
Address: 0xF89F6000
Size: 20480 bytes
Driver: C:\XP\System32\DRIVERS\msgpc.sys
Address: 0xF8876000
Size: 36864 bytes
Driver: C:\XP\System32\DRIVERS\mssmbios.sys
Address: 0xF8309000
Size: 16384 bytes
Driver: Mup.sys
Address: 0xF83BD000
Size: 110592 bytes
Driver: C:\XP\SYSTEM32\Drivers\NDIS.SYS
Address: 0xF859A000
Size: 184320 bytes
Driver: C:\XP\System32\DRIVERS\ndistapi.sys
Address: 0xF8325000
Size: 12288 bytes
Driver: C:\XP\System32\DRIVERS\ndiswan.sys
Address: 0xF7B51000
Size: 94208 bytes
Driver: C:\XP\System32\Drivers\NDProxy.SYS
Address: 0xF8826000
Size: 40960 bytes
Driver: C:\XP\System32\DRIVERS\netbios.sys
Address: 0xF88A6000
Size: 36864 bytes
Driver: C:\XP\System32\DRIVERS\netbt.sys
Address: 0xF67DA000
Size: 163840 bytes
Driver: C:\XP\system32\drivers\nod32drv.sys
Address: 0xF8BAA000
Size: 8192 bytes
Driver: C:\XP\system32\drivers\npf.sys
Address: 0xB97B8000
Size: 36864 bytes
Driver: C:\XP\System32\Drivers\Npfs.SYS
Address: 0xF8A06000
Size: 32768 bytes
Driver: Ntfs.sys
Address: 0xF844F000
Size: 577536 bytes
Driver: C:\XP\system32\ntoskrnl.exe
Address: 0x804D7000
Size: 2180352 bytes
Driver: C:\XP\System32\Drivers\Null.SYS
Address: 0xF8D0B000
Size: 4096 bytes
Driver: C:\XP\System32\nv4_disp.dll
Address: 0xBF012000
Size: 3928064 bytes
Driver: C:\XP\System32\DRIVERS\nv4_mini.sys
Address: 0xF7F9E000
Size: 3534848 bytes
Driver: C:\XP\system32\DRIVERS\nvcap.sys
Address: 0xF6022000
Size: 110592 bytes
Driver: C:\XP\system32\DRIVERS\nvtunep.sys
Address: 0xF66DA000
Size: 16384 bytes
Driver: C:\XP\system32\DRIVERS\nvtvsnd.sys
Address: 0xF7B78000
Size: 45056 bytes
Driver: C:\XP\system32\DRIVERS\NVxbar.sys
Address: 0xF66E2000
Size: 12288 bytes
Driver: C:\XP\system32\drivers\P17.sys
Address: 0xF7D47000
Size: 1392640 bytes
Driver: C:\XP\System32\DRIVERS\parport.sys
Address: 0xF7C08000
Size: 81920 bytes
Driver: PartMgr.sys
Address: 0xF8906000
Size: 20480 bytes
Driver: C:\XP\System32\Drivers\ParVdm.SYS
Address: 0xF8BA6000
Size: 8192 bytes
Driver: pci.sys
Address: 0xF85EE000
Size: 69632 bytes
Driver: C:\XP\System32\DRIVERS\PCIIDEX.SYS
Address: 0xF88FE000
Size: 28672 bytes
Driver: C:\XP\System32\Drivers\Pcouffin.sys
Address: 0xF87E6000
Size: 40960 bytes
Driver: C:\XP\system32\drivers\pfc.sys
Address: 0xF8335000
Size: 12288 bytes
Driver: PnpManager
Address: 0x804D7000
Size: 2180352 bytes
Driver: C:\XP\system32\drivers\portcls.sys
Address: 0xF7EE1000
Size: 147456 bytes
Driver: C:\XP\System32\DRIVERS\ptilink.sys
Address: 0xF896E000
Size: 20480 bytes
Driver: PxHelp20.sys
Address: 0xF890E000
Size: 20480 bytes
Driver: C:\XP\System32\DRIVERS\rasacd.sys
Address: 0xF8329000
Size: 12288 bytes
Driver: C:\XP\System32\DRIVERS\rasl2tp.sys
Address: 0xF87B6000
Size: 53248 bytes
Driver: C:\XP\System32\DRIVERS\raspppoe.sys
Address: 0xF87C6000
Size: 45056 bytes
Driver: C:\XP\System32\DRIVERS\raspptp.sys
Address: 0xF87D6000
Size: 49152 bytes
Driver: C:\XP\System32\DRIVERS\raspti.sys
Address: 0xF897E000
Size: 20480 bytes
Driver: RAW
Address: 0x804D7000
Size: 2180352 bytes
Driver: C:\XP\System32\DRIVERS\rdbss.sys
Address: 0xF678D000
Size: 176128 bytes
Driver: C:\XP\System32\DRIVERS\RDPCDD.sys
Address: 0xF8BA4000
Size: 8192 bytes
Driver: C:\XP\System32\DRIVERS\rdpdr.sys
Address: 0xF7AF8000
Size: 200704 bytes
Driver: C:\XP\System32\DRIVERS\redbook.sys
Address: 0xF87A6000
Size: 61440 bytes
Driver: C:\XP\System32\Drivers\rkhdrv31.SYS
Address: 0xF8976000
Size: 20480 bytes
Driver: C:\XP\System32\Drivers\SCDEmu.SYS
Address: 0xF8A3E000
Size: 32768 bytes
Driver: C:\XP\system32\DRIVERS\SCSIPORT.SYS
Address: 0xF8525000
Size: 98304 bytes
Driver: C:\XP\System32\DRIVERS\secdrv.sys
Address: 0xF8956000
Size: 28672 bytes
Driver: C:\XP\System32\DRIVERS\serenum.sys
Address: 0xF834D000
Size: 16384 bytes
Driver: C:\XP\System32\DRIVERS\serial.sys
Address: 0xF8746000
Size: 65536 bytes
Driver: snapman.sys
Address: 0xF83D8000
Size: 102400 bytes
Driver: C:\XP\system32\drivers\splitter.sys
Address: 0xF8BF4000
Size: 8192 bytes
Driver: sr.sys
Address: 0xF84F3000
Size: 73728 bytes
Driver: C:\XP\System32\DRIVERS\srv.sys
Address: 0xB97F0000
Size: 335872 bytes
Driver: SSFS0509.SYS
Address: 0xF8696000
Size: 36864 bytes
Driver: SSHRMD.SYS
Address: 0xF8686000
Size: 36864 bytes
Driver: SSIDRV.SYS
Address: 0xF85C7000
Size: 159744 bytes
Driver: C:\XP\System32\Drivers\sskbfd.sys
Address: 0xF8766000
Size: 49152 bytes
Driver: C:\XP\system32\DRIVERS\STREAM.SYS
Address: 0xF88E6000
Size: 49152 bytes
Driver: C:\XP\System32\DRIVERS\swenum.sys
Address: 0xF8B8C000
Size: 8192 bytes
Driver: C:\XP\system32\drivers\swmidi.sys
Address: 0xB9AE2000
Size: 57344 bytes
Driver: C:\XP\system32\drivers\sysaudio.sys
Address: 0xB9368000
Size: 61440 bytes
Driver: C:\XP\System32\DRIVERS\tcpip.sys
Address: 0xF6823000
Size: 360448 bytes
Driver: C:\XP\SYSTEM32\Drivers\TDI.SYS
Address: 0xF88F6000
Size: 20480 bytes
Driver: C:\XP\System32\DRIVERS\termdd.sys
Address: 0xF87F6000
Size: 40960 bytes
Driver: C:\XP\system32\DRIVERS\tifsfilt.sys
Address: 0xF899E000
Size: 32768 bytes
Driver: timntr.sys
Address: 0xF83F1000
Size: 385024 bytes
Driver: C:\XP\System32\DRIVERS\update.sys
Address: 0xF7AC4000
Size: 212992 bytes
Driver: C:\XP\system32\drivers\usbaudio.sys
Address: 0xF7BE8000
Size: 61440 bytes
Driver: C:\XP\System32\DRIVERS\usbccgp.sys
Address: 0xF89CE000
Size: 32768 bytes
Driver: C:\XP\System32\DRIVERS\USBD.SYS
Address: 0xF8B90000
Size: 8192 bytes
Driver: C:\XP\system32\DRIVERS\usbehci.sys
Address: 0xF8966000
Size: 28672 bytes
Driver: C:\XP\System32\DRIVERS\usbhub.sys
Address: 0xF8816000
Size: 61440 bytes
Driver: C:\XP\System32\DRIVERS\usbohci.sys
Address: 0xF895E000
Size: 20480 bytes
Driver: C:\XP\System32\DRIVERS\USBPORT.SYS
Address: 0xF7E9B000
Size: 143360 bytes
Driver: C:\XP\System32\DRIVERS\usbprint.sys
Address: 0xF8946000
Size: 28672 bytes
Driver: C:\XP\system32\DRIVERS\USBSTOR.SYS
Address: 0xF8A26000
Size: 28672 bytes
Driver: C:\XP\System32\DRIVERS\usbuhci.sys
Address: 0xF893E000
Size: 20480 bytes
Driver: D:\Virtual CD\VCdRom.sys
Address: 0xF7B31000
Size: 12288 bytes
Driver: C:\XP\System32\drivers\vga.sys
Address: 0xF89E6000
Size: 24576 bytes
Driver: viaagp.sys
Address: 0xF86F6000
Size: 45056 bytes
Driver: viaide.sys
Address: 0xF8B7C000
Size: 8192 bytes
Driver: C:\XP\System32\DRIVERS\VIDEOPRT.SYS
Address: 0xF7F8A000
Size: 81920 bytes
Driver: VolSnap.sys
Address: 0xF86B6000
Size: 53248 bytes
Driver: C:\XP\System32\DRIVERS\wanarp.sys
Address: 0xF8896000
Size: 36864 bytes
Driver: C:\XP\System32\watchdog.sys
Address: 0xF89D6000
Size: 20480 bytes
Driver: C:\XP\system32\drivers\wdmaud.sys
Address: 0xB92DB000
Size: 86016 bytes
Driver: Win32k
Address: 0xBF800000
Size: 1847296 bytes
Driver: C:\XP\System32\win32k.sys
Address: 0xBF800000
Size: 1847296 bytes
Driver: C:\XP\system32\drivers\WmBEnum.sys
Address: 0xF8301000
Size: 12288 bytes
Driver: C:\XP\System32\DRIVERS\WMILIB.SYS
Address: 0xF8B78000
Size: 8192 bytes
Driver: WMIxWDM
Address: 0x804D7000
Size: 2180352 bytes
Driver: C:\XP\system32\drivers\WmXlCore.sys
Address: 0xF8806000
Size: 45056 bytes
Driver: C:\XP\System32\drivers\ws2ifsl.sys
Address: 0xF7B3D000
Size: 12288 bytes
----
RkUnhooker report generator v0.6
==============================================
Rootkit Unhooker kernel version: 3.31.150.420
==============================================
Windows Major Version: 5
Windows Minor Version: 1
Windows Build Number: 2600
==============================================
[2120]SpySweeper.exe-->kernel32.dll-->CreateThread, Type: Inline - PushRet at address 0x7C810651 hook handler located in [unknown_code_page]
ntoskrnl.exe+0x0000B9A8, Type: Inline - RelativeCall at address 0x804E29A8 hook handler located in [unknown_code_page]
tcpip.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF6861F60 hook handler located in [unknown_code_page]
wanarp.sys-->ndis.sys-->NdisDeregisterProtocol, Type: IAT modification at address 0xF889BB1C hook handler located in [unknown_code_page]
wanarp.sys-->ndis.sys-->NdisRegisterProtocol, Type: IAT modification at address 0xF889BB28 hook handler located in [unknown_code_page]
As always, thanks a million for your assistance!
-
btw, whats an HIP program? (sorry for the dummie question)
-
using the one found here: http://www.antirootkit.com/software/RootKit-Unhooker.htm
hope this is the same
-
I cannot reach the server where the unhooker program is located... got another link for it? How about an IP address (perhaps its a DNS issue?).
-
below is the log u asked for:
Rustock.b-ADS attached to the System32-folder:
Attempting to remove ADS...
Looking for Rustock.b-files in the System32-folder:
ECHO is off.
******************* Post-run Status of system *******************
Rustock.b-driver on the system:
YOU NEED TO CONSULT MORE ADVANCED TOOLS!!
The Gmer-rootkitscanner may be a good place to start.
Gmer rootkit-scanner may be found here: http://www.gmer.net
Rustock.b-ADS attached to the System32-folder:
ECHO is off.
You should either run the tool again or consult more advanced tools
The Gmer-rootkitscanner may be a good place to start.
Gmer rootkit-scanner may be found here: http://www.gmer.net
Looking for Rustock.b-files in the System32-folder:
ECHO is off.
You should either run the tool again or consult more advanced tools
Swandog46's Avenger or Gmer's-rootkitscanner may be a good place to start.
Swandog46's Avenger may be found here: http://swandog46.geekstogo.com/avengernotes.htm
Gmer rootkit-scanner may be found here: http://www.gmer.net
----------------
I then ran gmer, the log is in an above post... I had no idea what to do with the information it presented.
No matter what I did, whenever I rebooted, early in the log on process I got a Windows installer trying to re-install vIsual Foxpro 9, a program which was already on my computer and running fine. No matter how many times I clicked cancel, the installer would close and immediately reopen itself. I would have to click cancel at least 12-15 times (the installer would close and then restart each time) to make the window go away for good. I fear this may have been the vehicle used to infect the machine. I could find no registry entries anywhere that where telling it to run on startup. I have several starup monitors and none of them showed an entry for it either... very suspiscious IMO. I finally got tired of hovering over the mouse all the way thru each 5 minute boot and let it do its thing to see what would happen. I said it was preparing to instal VFP9, would gather a bunch of data and then finally close without ever installing anything near as I could tell.
Subsequent scans did not turn up any rootkit, however, spydetector said that rustock backdoor had been successfully removed whenever I tried to run the rust checker. So I am now assuming from reading your post that I need to close all protection programs but my firewall while performing these checks.. this may invalidate much of previous information as I have avast pro, nod32, spybot S&D, spysweeper, spydetector and now avg all loaded on the system now. So before running combofix, etc, I should have all other protection programs disabled?
Running the rust checker now just returns an error after reboot saying it can't find files.
I DID run the avgantirootkit in depth scan last night and it found no rootkits. However, several of the protection programs were also running at the time...
current status: tho I can see no outbound in the syslogs, task manager shows continuous memory useage and constant cpu useage from 2 up to 86% even tho no applications are open. Average is probably about 12%. However, on all my other computer systems when nothing is running tactual useage hovers near zero with NO spikes. Over night, my available memory has been reduced to almost zero as well. CLosing all the protection programs only freed a small portion oif the memory and had no effect on the task manager reported cpu activity. ALl of it always gets lumped under system idle even tho the computer doesnt seem to be doing anything.
I noticed there didnt seem to be anyway to unload the nod32krn from task manager, it and its memory allocation seemed to hang around no matter how I closed the app. Sam thing with Spy Sweeper... even tho it has been unloaded using its own menu the app remains in the task manager list sucking up resources even tho it is not doing anything. BTW, Spy Sweper seems to be a huge resource hog. With all of its protections enabled CPU is at near 100% all the time even with no other applications open.
Maybe Im obsessing too much over the CPU activity, but having anything spiking resources when u are running some applications, especially those with real time graphics (like games for example) are adverserly noticeably affected.
(sigh)... I will now try your latest suggestion and then post the results in a while.
Thanks for your help, I really appreciate it.
-
I ran avg in safe mode, reran combofix, and for a brief period it looked as tho this might have done it... but alas... the windows installer for vfp9 persisted popping up continuously on every reboot until I let it run... here is the avg and another current hijack log:
Logfile of HijackThis v1.99.1
Scan saved at 1:24:51 AM, on 5/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\XP\System32\smss.exe
C:\XP\system32\winlogon.exe
C:\XP\system32\services.exe
C:\XP\system32\lsass.exe
C:\XP\system32\svchost.exe
C:\XP\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\XP\system32\spoolsv.exe
C:\Program Files\Acronis\BackupServer\backupserver.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Eset\nod32krn.exe
C:\XP\system32\nvsvc32.exe
C:\Program Files\SpywareDetector\SDService.exe
C:\XP\System32\svchost.exe
C:\XP\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\XP\system32\wuauclt.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\SpywareDetector\SDSystemTray.exe
C:\Program Files\PTSync\PTSync.exe
C:\Program Files\Acronis\TrueImageEnterpriseServer\TRUEIM~3.EXE
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Acronis\TrueImageEnterpriseServer\TIMOUN~1.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.americansingles.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Acrobat7\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Cooxie - {DC99E960-6594-45e3-9D5D-141D825B8096} - C:\Program Files\Cooxie Toolbar\PrvcBand.dll
O4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunOnce: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" runonce
O4 - HKCU\..\Run: [speedStartup] "C:\Program Files\Speed Startup\speedstartup.exe" bootup
O8 - Extra context menu item: Add to &Teleport - D:\TeleportUltra\teleport.htm
O8 - Extra context menu item: Convert link target to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://D:\Acrobat7\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\MsOffice\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with Scansoft PDF Converter 3.0 - res://D:\OmniPage15\PDFConverter3\IEShellExt.dll /100
O9 - Extra button: Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra 'Tools' menuitem: VisualRoute Trace - {04849C74-016E-4a43-8AA5-1F01DE57F4A1} - C:\Program Files\VisualRoute\vrie.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Program Files\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\MsOffice\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1145986548799
O17 - HKLM\System\CCS\Services\Tcpip\..\{90F742E6-14BD-42BD-B353-7487933899E6}: NameServer = 66.254.6.2,66.254.1.2
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O20 - Winlogon Notify: SDNotify - C:\Program Files\SpywareDetector\SDNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\XP\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\XP\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Remote Agent (AcronisAgent) - Acronis - C:\Program Files\Common Files\Acronis\Agent\agent.exe
O23 - Service: Acronis Backup Server Service (AcronisBackupServerService) - Acronis - C:\Program Files\Acronis\BackupServer\backupserver.exe
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Arcana Notification Agent (adnotify) - Unknown owner - C:\Program Files\Arcana Development\Notification Agent\ADNotify.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Arcana Scheduler - Arcana Development - C:\Program Files\Arcana Development\Arcana Scheduler\adscheduler.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Acronis Group Server (GroupServer) - Acronis - C:\Program Files\Acronis\GroupServer\GroupServer.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\XP\system32\drivers\KodakCCS.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\XP\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\XP\system32\oodag.exe
O23 - Service: ProgramCheckerPro (sassvc) - Unknown owner - C:\Program Files\Zenturi\ProgramChecker\sassvc.exe
O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
avg:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:32:38 PM 5/20/2007
+ Scan result:
F:\Audio Programs and Plugins\Holding\CyberlinkPower2go\CyberLink.Power2Go.Deluxe.v5.50.2614.Multilingual.Incl.Keymaker\keygen.exe -> Logger.Banker : Cleaned.
F:\Audio Programs and Plugins\Holding\XPGenuine\Make Windows XP Genuine\3) Genuine.rar/Port_RockXP_v4.exe/RockXP4.exe -> Not-A-Virus.PSWTool.Win32.RAS.a : Cleaned.
:mozilla.355:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.356:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.357:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.358:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.359:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.360:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.361:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.362:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.363:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.364:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.365:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.366:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.367:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.368:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.369:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.370:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.371:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.372:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.373:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.374:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.375:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.376:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.377:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.378:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.379:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.380:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.381:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.382:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.383:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.384:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.385:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.386:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.387:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.388:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.389:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.390:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.391:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.392:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.393:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.394:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.395:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.396:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.397:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.398:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.399:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.400:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.401:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.402:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.403:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.404:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.405:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.510:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.559:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.676:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.695:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.730:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.761:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.820:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.839:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.450:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.451:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.452:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.453:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.241:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.242:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.243:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.245:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.250:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.251:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.252:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.253:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.254:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.179:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.180:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.182:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.183:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.184:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.186:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.87:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.420:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.892:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.416:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.417:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.418:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.419:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.192:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.193:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.194:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.195:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.196:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.197:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.198:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.200:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.201:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.694:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.869:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.870:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.871:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.872:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.503:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.504:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.505:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.506:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.142:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.143:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.261:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.262:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.263:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.264:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.265:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.244:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.246:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.247:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.248:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.249:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.110:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.447:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.464:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.556:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.574:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.585:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.650:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.655:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.660:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.224:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.225:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.227:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.228:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.231:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.232:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.704:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.705:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.706:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.707:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.708:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.709:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.896:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.115:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.927:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.786:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.787:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.539:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.540:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.541:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.283:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.284:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.331:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.332:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.335:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Msn : Cleaned.
:mozilla.7:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.8:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.9:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.931:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.932:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.727:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.728:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.729:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.428:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.255:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.256:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.257:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.258:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.259:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.260:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.285:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.286:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.287:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.288:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.289:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.290:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.291:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.602:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.603:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.604:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.605:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.606:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.607:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.608:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.609:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.610:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.629:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.205:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.206:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.207:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.208:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.209:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.210:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.211:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.212:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.213:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.214:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.215:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.216:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.217:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.218:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.219:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.220:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.221:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.222:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.223:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.149:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.150:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.151:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.152:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.153:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.154:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.731:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.732:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.733:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.734:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.735:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.736:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.737:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.738:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.21:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.22:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.23:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.24:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.25:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.26:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.27:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.28:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.29:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.30:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.31:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.32:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.33:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.34:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.35:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.36:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.37:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.38:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.39:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.40:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.41:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.46:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.47:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.48:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.49:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.50:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.51:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.52:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.53:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.54:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.55:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.56:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.57:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.58:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.59:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.60:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.61:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.62:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.63:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.64:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.65:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.66:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.67:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.68:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.69:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.421:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.422:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.423:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.424:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.920:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.899:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.266:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.267:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.268:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.269:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.270:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.271:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.272:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.273:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.274:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.444:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.148:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.89:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.128:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.79:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.944:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.135:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.136:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.137:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.138:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.139:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.140:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.141:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.485:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.486:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.487:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.488:C:\Documents and Settings\Staypuffer\Application Data\Mozilla\Firefox\Profiles\c1capmv4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Teleport Ultra\scheduler.exe -> Trojan.Agent.iu : Cleaned.
D:\TeleportUltra\scheduler.exe -> Trojan.Agent.iu : Cleaned.
F:\Audio Programs and Plugins\Audio Programs\Vegas\SONY.Vegas.6.0c.FULL.Include.Keymaker-PDX.zip/KEYGEN/SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.
F:\Audio Programs and Plugins\Audio Programs\Vegas\install\KEYGEN\SONYkeygen.exe -> Trojan.Pakes.edg : Cleaned.
D:\Acronis Complete Suite\Acronis Complete\WinRAR.v3.51.WinALL.Cracked-CORE\cr-wr351.zip/crack.exe -> Trojan.Small : Cleaned.
F:\Audio Programs and Plugins\Holding\SpiderWriter\Spider_Writer_v5-20-00610\Spider_Writer_v5[1].20.0610Patch.zip/crack.exe -> Trojan.Small : Cleaned.
::Report end
New Problem...
in Malware Removal
Posted
got ur pm reply... thank you... I await ur latest words of wisdom... and as always thanks a million!