I am having problems with new icons that appeared today that say there are mailware threats, and a critical system error. I figured it was spyware, but cannot seem to get rid of it. Virus scan says that 3 files cannot be deleted, system32\odbc.exe, winser.exe, and wintrust32.exe. Is there a way of deleting these off my computer so that my system can function normally? Also, when I tried turning off my computer earlier, I got multiple messages saying that there were errors in shutting programs down, is this linked to my first problem?
Logfile of HijackThis v1.99.1
Scan saved at 4:42:20 AM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Hello rfoster2, let's see if we can get this log cleaned up a bit.
Download SmitfraudFix.zip to the desktop from here * Extract the files to the desktop.
Download Killbox from here.
* Do not run it yet, will later in safe mode.
Disable SpySweepers Shield because it may interfere with our fixes. Please leave them off until the very end.
Open SpySweeper.
Click Shield Settings on the right
(or Shields on the left, depending what screen you're on).
Click Internet Explorer and uncheck all items.
Click Windows System and uncheck all items.
Click Hosts File and uncheck all items.
Click Startup Programs and uncheck all items.
Close SpySweeper.
Press Ctrl+Alt+Del > Processes tab > End these:
odbc.exe
winser.exe
wintrust32.exe Close Task Manager.
Go to Start > Run > type services.msc > click OK.
Find the each of the following and double click to open.
ODBC service
Neth
Win PPPe
WinTrust32 Beside "Startup Type" click the drop down menu and select "Disabled" for each.
Close Services.
Open HijackThis.
Click "Open the misc tools section".
Click "Delete an NT service".
Copy/Paste these one at a time and click OK.
O23 - Service: ODBC service - Unknown owner - C:\WINDOWS\system32\odbc.exe
O23 - Service: Neth - Unknown owner - C:\WINDOWS\system32\netid.exe (file missing)
O23 - Service: Win PPPe - Unknown owner - C:\WINDOWS\system32\winser.exe
O23 - Service: WinTrust32 - Unknown owner - C:\WINDOWS\system32\wintrust32.exe A prompt may say that it was not found in registry. Do not worry about it, just continue to next one.
You will be prompted to restart after each one. Do so after the last one and restart in safe mode(press F8 upon boot, select "Safe Mode" from menu and press Enter).
Note:Print or copy these instructions to Notepad and save them. You will be in safe mode and can't access the internet.
* Once in safe mode open the SmitfraudFix folder.
* Double-click smitfraudfix.cmd
* Select 2 and hit Enter to delete infect files.
* You will be prompted: Do you want to clean the registry ? answer Y (yes) and hit Enter in order to remove the Desktop background and clean registry keys associated with the infection.
* The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found): Replace infected file ? answer Y (yes) and hit Enter to restore a clean file.
* A reboot may be needed to finish the cleaning process. Do not restart yet. The report can be found at the root of the system drive, usually at C:\rapport.txt.
* Exit SmitfraudFix.
Open Killbox.exe.
Check "Standard File Kill".
In the "Full Path of File to Delete" box, copy and paste each of the following lines below one at a time. Then click the red button with a white X after you enter each file.
You will be prompted to confirm, click Yes.
C:\WINDOWS\system32\odbc.exe
C:\WINDOWS\system32\winser.exe
C:\WINDOWS\system32\wintrust32.exe Note: KillBox may prompt "File does not seem to exist". If so, continue with next file, but do not miss any.
Exit KillBox.
Restart in normal mode.
Post back with the contents of rapport.txt and a new HijackThis log.
I did what you said. The problem seems to be fixed, no more popups and no mor "mail" popup problem. Here are the two things you asked for, letr me know if it is truely fixed. Thanks
SmitFraudFix v2.113
Scan done at 20:11:25.04, Mon 10/23/2006
Run from C:\Documents and Settings\HP_Administrator\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix run in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
and
Logfile of HijackThis v1.99.1
Scan saved at 8:26:39 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
O2 - BHO: Viewpoint Toolbar BHO - {A7327C09-B521-4EDB-8509-7D2660C9EC98} - C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBarBHO.dll <--Only if you uninstalled Viewpoint Toolbar.
O4 - HKLM\..\Run: [winupdates] C:\Program Files\winupdates\winupdates.exe /auto
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k <--Not bad, but not needed on startup.
O4 - HKLM\..\Run: [ViewMgr] "C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe" <--Only if you uninstalled Viewpoint Manager.
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar\ViewBar.dll/CXTSEARCH.HTML
Close all windows except HijackThis, then click "Fix checked".
Note: Print or copy these instructions to Notepad and save them.
Restart your computer in safe mode(press F8 upon boot, select "Safe Mode" from menu and press Enter).
Open AVG AS and click "Scanner".
Click "Complete System Scan".
When it finishes scanning, set all items to "Quarantine".
Click "Apply All Actions".
Click "Save Report".
Click "Save report as" and save it to the desktop.
Close AVGAS.
Delete this with KillBox.
C:\Program Files\winupdates\winupdates.exe Close KillBox.
Show hidden files and folders.
Control Panel > Folder Options > View tab > check "Show hidden files and folders".
Locate and delete this folder.
C:\Program Files\winupdates
Restart in normal mode.
Delete the KillBox backups located at C:\!KillBox\backups Empty the Recycle Bin.
Open ATF Cleaner.
Check "Select All".
Click "Empty Selected".
Go here and run Kaspersky Online Scanner.
Accept the terms.
After downloading, click "My Computer".
After scanning, click "Save report as" and save it.
Post back with the AVGAS report, the Kaspersky log, and a new HijackThis log.
After you post the AVGAS log, you may uninstall AVGAS if you don't want to keep it. If you do keep it, turn off the real-time protections since you already have one anti-spyware program.
I did what you said but I could not get the kaspersky log because the program would not download onto my computer, it said it failed and I had to be the admin and IE settings had to be at medium, I did this and it would still not load up. Let me know these look, and what I need to do next. Thanks
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP423\A0033126.exe -> Backdoor.Small.bh : Cleaned with backup (quarantined).
C:\avtemp\setup.exe -> Backdoor.Small.bh : Cleaned with backup (quarantined).
C:\temp\VirusScan\UIUC_VirusScan_80i.exe/avtemp/setup.exe -> Backdoor.Small.bh : Cleaned with backup (quarantined).
:mozilla.709:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.736:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.737:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.254:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.255:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.256:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.257:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.258:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.946:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.868:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adocean : Cleaned.
:mozilla.715:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.716:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.717:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.906:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.458:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.459:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.25:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.26:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.27:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.28:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.30:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.32:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.815:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.49:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.395:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.499:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.500:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.598:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.599:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.312:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.313:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.314:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.315:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.250:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.279:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.280:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.29:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\HP_Administrator\Cookies\hp_administrator@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.597:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.54:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.55:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.56:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.57:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.58:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.244:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.245:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.246:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.247:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.248:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.249:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.358:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.434:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.435:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.634:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.635:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.646:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.727:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.728:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.84:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.85:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.91:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.92:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.93:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.390:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.391:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.392:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.393:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.394:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.226:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.228:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.229:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.259:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.385:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.386:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.316:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.317:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.318:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.319:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.320:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.321:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.322:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.720:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.266:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.267:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.268:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.269:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.399:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.400:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.401:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.119:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.121:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.127:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.140:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.141:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.142:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.146:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.150:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.237:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.238:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.239:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.240:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.241:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.242:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.289:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.776:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.831:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.832:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.833:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.834:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.843:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.155:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.156:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.157:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.158:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.159:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.160:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.474:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.475:C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\ewtsmwkk.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\!KillBox\odbc.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
C:\!KillBox\winser.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
C:\!KillBox\wintrust32.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP423\A0033190.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP423\A0033191.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{B9823275-D858-498B-A4DC-C4EEDA322F67}\RP423\A0033192.exe -> Trojan.Agent.ye : Cleaned with backup (quarantined).
::Report end
and
Logfile of HijackThis v1.99.1
Scan saved at 1:52:37 AM, on 10/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
I could not do this either. Whenever I click on the activeX plugin install it will install, but when I get to the next step where I need to click install the program, I click it and the browser freezes up and says its not responding. This was what was happening to the last program too. What should I do?
Install and open Spybot.
Click "Search for Updates".
Select all and click "Download Updates".
After updating close Spybot.
Restart in safe mode.
Open Spybot and click "Check for Problems".
When it finishes, click "Fix selected problems".
Right click and select "Copy results" (not full report)
Open Notepad, paste and save them.
Restart in normal mode and try running either Kaspersky or ActiveScan again.
Post back with the Spybot log and the online scan log(if sucessful).