User User name Password  
   
Wednesday 22.1.2025 / 18:27
Search AfterDawn Forums:        In English   Suomeksi   På svenska
afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > hijack this log
Show topics
 
Forums
Forums
Hijack This Log
  Jump to:
 
Posted Message
chayne04
Member
_
27. August 2006 @ 17:21 _ Link to this message    Send private message to this user   
can someone take a look at this HiJack This Log and see if you can find anything wrong with this log. Thanks.

Logfile of HijackThis v1.99.1
Scan saved at 8:12:13 PM, on 8/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\REGIST~1\RegClean.exe
C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
C:\Program Files\Yahoo!\Messenger\YPAGER.EXE
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\Program Files\Common Files\WinTools\WSup.exe
C:\Program Files\Yahoo!\browser\ybrowser.exe
C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\K9X1KMEH\HijackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl_...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl_...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl_...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl_...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl_...
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: ATLDistrib Object - {3FE36807-69ED-45D1-B9BE-85C0E3F75B6A} - C:\WINDOWS\system32\hgdcc.dll (file missing)
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [OSS] c:\windows\system32\ossproxy.exe -boot
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\RunOnce: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe /boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Registry Cleaner] C:\PROGRA~1\REGIST~1\RegClean.exe
O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http:/_/*.billingnow.com
O15 - Trusted Zone: http:/_/*.reliablestats.com
O15 - Trusted Zone: http:/_/*.winantispyware.com
O15 - Trusted Zone: http:/_/*.winantivirus.com
O15 - Trusted Zone: http:/_/*.winantiviruspro.com
O15 - Trusted Zone: http:/_/*.winfixer.com
O15 - Trusted Zone: http:/_/*.winnanny.com
O15 - Trusted Zone: http:/_/*.winsoftware.com
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
O16 - DPF: {94837F90-A2CA-4A8A-9DA0-B5438EC563EA} (WildTangent Active Launcher) - http://install.wildtangent.com/cda/islandrally/ActiveLauncher/Act...
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O20 - Winlogon Notify: hgdcc - C:\WINDOWS\system32\hgdcc.dll (file missing)
O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
Advertisement
_
__
maca1
Senior Member
_
27. August 2006 @ 17:28 _ Link to this message    Send private message to this user   
go to add/remove programs and remove Win Tools if there.

Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
· Install ewido.
· Run the application
· Clickon scanner
· then select the "Settings" tab.
· Once in the Settings screen click on "Recommended actions" and then select "Delete".
· Select "Automatically generate report after every scan"
· Un-Select "Only if threats were found"
· Click Complete System Scan and the scan will begin.
· When the scan is finished, Set all items to delete
· Apply all actions
· look at the bottom of the screen and click the Save report button.
· Save the report to your C: Drive
This will take some time to run!
RE-Boot


In normal mode
Run ActiveScan online virus scan:
http://www.pandasoftware.com/products/activescan.htm
When the scan is finished, save the results from the scan!

Come back here and post a new Hijack This log along with the logs from the Ewido and Panda scans.

This message has been edited since posting. Last time this message was edited on 27. August 2006 @ 17:29

chayne04
Member
_
28. August 2006 @ 14:49 _ Link to this message    Send private message to this user   
ok, i have just finished the Ewido Scan. Here is the log. i will post the other two later on this evening. Thank YOu for your help.

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

e w i d o a n t i - s p y w a r e - S c a n R e p o r t

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -



+ C r e a t e d a t : 5 : 4 2 : 2 4 P M 8 / 2 8 / 2 0 0 6



+ S c a n r e s u l t :







H K L M \ S O F T W A R E \ C l a s s e s \ A p p I D \ A l t n e t S i g n i n g M o d u l e . E X E - > A d w a r e . A l t n e t : C l e a n e d .

H K L M \ S O F T W A R E \ C l a s s e s \ A p p I D \ a d m . E X E - > A d w a r e . A l t n e t : C l e a n e d .

C : \ W I N D O W S \ s y s t e m 3 2 \ S H A g e n t N e w . d l l - > A d w a r e . B a r g a i n B u d d y : C l e a n e d .

H K L M \ S O F T W A R E \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ U n i n s t a l l \ R e l e v a n t K n o w l e d g e - > A d w a r e . B r o a d C a s t P C : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 3 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 4 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 5 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 6 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

H K L M \ S O F T W A R E \ C l a s s e s \ I E x p l o r r 2 4 . c l s D W - > A d w a r e . I n e t S p e a k : C l e a n e d .

H K L M \ S O F T W A R E \ C l a s s e s \ I E x p l o r r 2 4 . c l s D W \ C l s i d - > A d w a r e . I n e t S p e a k : C l e a n e d .

C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ 9 8 C 4 0 0 6 8 - 5 9 4 C - 4 E 4 1 - A 6 C 4 - 5 9 1 2 9 E \ 5 D B 1 3 B 5 C - F 0 5 E - 4 9 1 9 - B 6 2 6 - A D 2 9 C 7 - > A d w a r e . N e w D o t N e t : C l e a n e d .

H K L M \ S O F T W A R E \ C l a s s e s \ C L S I D \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

H K L M \ S O F T W A R E \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ E x p l o r e r \ B r o w s e r H e l p e r O b j e c t s \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

H K U \ S - 1 - 5 - 2 1 - 1 4 0 9 0 8 2 2 3 3 - 1 5 2 0 4 9 1 7 1 - 1 3 4 3 0 2 4 0 9 1 - 1 0 0 3 \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ E x t \ S t a t s \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 6 5 . e x e - > A d w a r e . W e b R e b a t e s : C l e a n e d .

C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 7 8 . E X E - > A d w a r e . W e b R e b a t e s : C l e a n e d .

C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 7 9 . E X E - > A d w a r e . W e b R e b a t e s : C l e a n e d .

C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 3 8 7 3 . e x e - > A d w a r e . W e b S e a r c h : C l e a n e d .

C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 3 8 7 4 . d l l - > A d w a r e . W e b S e a r c h : C l e a n e d .

H K L M \ S O F T W A R E \ C l a s s e s \ P R O T O C O L S \ N a m e - S p a c e H a n d l e r \ r e s - > A d w a r e . W e b S e a r c h : C l e a n e d .

H K L M \ S O F T W A R E \ T o o l b a r - > A d w a r e . W e b S e a r c h : C l e a n e d .

H K L M \ S O F T W A R E \ T o o l b a r \ P l u g I n s - > A d w a r e . W e b S e a r c h : C l e a n e d .

H K L M \ S O F T W A R E \ T o o l b a r \ P l u g I n s \ C O M M O N - > A d w a r e . W e b S e a r c h : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 7 A . t m p \ F C r X M L . d l l - > A d w a r e . W i n f i x e r : C l e a n e d .

C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p \ d n y y z i c . t m p - > A d w a r e . W i n t o l : C l e a n e d .

C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p \ d n y y z i l . t m p - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s A . e x e - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ _ _ d e l e t e _ o n _ r e b o o t _ _ W _ T _ o _ o _ l _ s _ B _ . _ d _ l _ l _ - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ A 6 E B 4 3 6 4 - 1 F 1 A - 4 3 7 B - 8 4 5 0 - 0 A 2 F 1 E \ 8 7 0 8 0 F 6 7 - C 9 9 4 - 4 4 B 0 - 8 2 2 F - 5 3 9 4 B A - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W S u p . e x e - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s A . e x e - > A d w a r e . W i n t o l : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s B . d l l - > A d w a r e . W i n t o l : C l e a n e d .

C : \ W I N D O W S \ T e m p \ W T u n i n s t . e x e - > A d w a r e . W i n t o l : C l e a n e d .

C : \ W I N D O W S \ T e m p \ ~ 7 5 2 3 2 2 . t m p - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

[ 1 0 7 6 ] C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s B . d l l - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

[ 3 1 5 6 ] C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s B . d l l - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

C : \ W I N D O W S \ T e m p \ ~ 5 6 1 9 2 5 . t m p - > D o w n l o a d e r . W i n t o o l . a : E r r o r d u r i n g c l e a n i n g .

C : \ W I N D O W S \ T e m p \ ~ 9 7 5 9 7 1 . t m p - > D o w n l o a d e r . W i n t o o l . a : E r r o r d u r i n g c l e a n i n g .

C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p o r a r y I n t e r n e t F i l e s \ C o n t e n t . I E 5 \ 0 D Y 9 8 J O J \ W i n T S [ 1 ] . c a b / W T o o l s S . e x e - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ A 6 E B 4 3 6 4 - 1 F 1 A - 4 3 7 B - 8 4 5 0 - 0 A 2 F 1 E \ E 2 A 5 2 B E C - 3 0 6 2 - 4 4 2 2 - A 3 2 7 - 2 8 C 7 6 1 - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s S . e x e - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 C . t m p - > T r a c k i n g C o o k i e . 2 o 7 : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 7 . t m p - > T r a c k i n g C o o k i e . A d s e r v e r : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 E . t m p - > T r a c k i n g C o o k i e . A d v e r t i s i n g : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 F . t m p - > T r a c k i n g C o o k i e . A t d m t : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 0 . t m p - > T r a c k i n g C o o k i e . B f a s t : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 2 . t m p - > T r a c k i n g C o o k i e . B u r s t n e t : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 3 . t m p - > T r a c k i n g C o o k i e . C a s a l e m e d i a : C l e a n e d .

C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ C o o k i e s \ t e s t @ c o m [ 1 ] . t x t - > T r a c k i n g C o o k i e . C o m : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 5 . t m p - > T r a c k i n g C o o k i e . D o u b l e c l i c k : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 8 . t m p - > T r a c k i n g C o o k i e . F a s t c l i c k : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 9 . t m p - > T r a c k i n g C o o k i e . H i t b o x : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A A . t m p - > T r a c k i n g C o o k i e . H i t b o x : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A B . t m p - > T r a c k i n g C o o k i e . H i t s l i n k : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A D . t m p - > T r a c k i n g C o o k i e . M e d i a p l e x : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A E . t m p - > T r a c k i n g C o o k i e . Q k s r v : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A F . t m p - > T r a c k i n g C o o k i e . Q u e s t i o n m a r k e t : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 6 . t m p - > T r a c k i n g C o o k i e . R u 4 : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 1 . t m p - > T r a c k i n g C o o k i e . S p y l o g : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 2 . t m p - > T r a c k i n g C o o k i e . T r a f f i c m p : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 3 . t m p - > T r a c k i n g C o o k i e . T r i b a l f u s i o n : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 5 . t m p - > T r a c k i n g C o o k i e . V a l u e c l i c k : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 6 . t m p - > T r a c k i n g C o o k i e . W e b t r e n d s l i v e : C l e a n e d .

C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 8 . t m p - > T r a c k i n g C o o k i e . Z e d o : C l e a n e d .





: : R e p o r t e n d
Senior Member
_
29. August 2006 @ 18:40 _ Link to this message    Send private message to this user   
Post a fresh HijackThis log.

Advertisement
_
__
 
_
maca1
Senior Member
_
30. August 2006 @ 07:45 _ Link to this message    Send private message to this user   
@Niobis

and I'm also looking for a panda log.

This message has been edited since posting. Last time this message was edited on 30. August 2006 @ 09:07

afterdawn.com > forums > software, operating systems and more > windows - virus and spyware problems > hijack this log
 

Digital video: AfterDawn.com | AfterDawn Forums
Music: MP3Lizard.com
Gaming: Blasteroids.com | Blasteroids Forums | Compare game prices
Software: Software downloads
Blogs: User profile pages
RSS feeds: AfterDawn.com News | Software updates | AfterDawn Forums
International: AfterDawn in Finnish | AfterDawn in Swedish | AfterDawn in Norwegian | download.fi
Navigate: Search | Site map
About us: About AfterDawn Ltd | Advertise on our sites | Rules, Restrictions, Legal disclaimer & Privacy policy
Contact us: Send feedback | Contact our media sales team
 
  © 1999-2025 by AfterDawn Ltd.

  IDG TechNetwork