Hijack This Log

Discussion in 'Windows - Virus and spyware problems' started by chayne04, Aug 27, 2006.

  1. chayne04

    chayne04 Regular member

    Joined:
    Mar 18, 2006
    Messages:
    216
    Likes Received:
    0
    Trophy Points:
    26
    can someone take a look at this HiJack This Log and see if you can find anything wrong with this log. Thanks.

    Logfile of HijackThis v1.99.1
    Scan saved at 8:12:13 PM, on 8/27/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\LEXBCES.EXE
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\system32\LEXPPS.EXE
    C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    C:\WINDOWS\system32\drivers\KodakCCS.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\pctspk.exe
    C:\Program Files\Logitech\Video\LogiTray.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\WINDOWS\system32\PRISMSVR.EXE
    C:\Program Files\Yahoo!\browser\ybrwicon.exe
    C:\Program Files\2Wire\2PortalMon.exe
    C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
    C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
    C:\PROGRA~1\Yahoo!\YOP\yop.exe
    C:\PROGRA~1\Yahoo!\browser\ycommon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\REGIST~1\RegClean.exe
    C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    C:\Program Files\Logitech\Video\FxSvr2.exe
    C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
    C:\Program Files\Yahoo!\Messenger\YPAGER.EXE
    C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    C:\Program Files\Common Files\WinTools\WToolsS.exe
    C:\Program Files\Common Files\WinTools\WSup.exe
    C:\Program Files\Yahoo!\browser\ybrowser.exe
    C:\Documents and Settings\test\Local Settings\Temporary Internet Files\Content.IE5\K9X1KMEH\HijackThis[1].exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.seekerbar.com/ie.aspx?tb_id=50154
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl_/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl_/*http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...sbcydsl_/*http://www.yahoo.com/search/ie.html
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ie/defaults/sp/sbcydsl_/*http://www.yahoo.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/sbcydsl_/*http://www.yahoo.com
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: ATLDistrib Object - {3FE36807-69ED-45D1-B9BE-85C0E3F75B6A} - C:\WINDOWS\system32\hgdcc.dll (file missing)
    O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn3\yt.dll
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
    O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
    O4 - HKLM\..\Run: [OSS] c:\windows\system32\ossproxy.exe -boot
    O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
    O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\system32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
    O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
    O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
    O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
    O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\RunOnce: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe /boot
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [Registry Cleaner] C:\PROGRA~1\REGIST~1\RegClean.exe
    O4 - Global Startup: 2Wire Wireless Client.lnk = C:\Program Files\2Wire 802.11g Wireless\PRISMCFG.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare Software\bin\EasyShare.exe
    O4 - Global Startup: Kodak software updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
    O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http:/_/*.billingnow.com
    O15 - Trusted Zone: http:/_/*.reliablestats.com
    O15 - Trusted Zone: http:/_/*.winantispyware.com
    O15 - Trusted Zone: http:/_/*.winantivirus.com
    O15 - Trusted Zone: http:/_/*.winantiviruspro.com
    O15 - Trusted Zone: http:/_/*.winfixer.com
    O15 - Trusted Zone: http:/_/*.winnanny.com
    O15 - Trusted Zone: http:/_/*.winsoftware.com
    O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/platypus/miniclipGameLoader.dll
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www2.snapfish.com/SnapfishActivia.cab
    O16 - DPF: {54823A9D-6BAE-11D5-B519-0050BA2413EB} (ChkDVDCtl Class) - http://www.gocyberlink.com/winxp/CheckDVD.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {94837F90-A2CA-4A8A-9DA0-B5438EC563EA} (WildTangent Active Launcher) - http://install.wildtangent.com/cda/islandrally/ActiveLauncher/ActiveLauncherSetup.cab
    O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
    O20 - Winlogon Notify: hgdcc - C:\WINDOWS\system32\hgdcc.dll (file missing)
    O23 - Service: AOL Spyware Protection Service (AOLService) - Unknown owner - C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\\aolserv.exe (file missing)
    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
    O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
    O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
    O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe
    O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\system32\YPCSER~1.EXE
     
  2. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    go to add/remove programs and remove Win Tools if there.

    Download the trial version of Ewido Security Suite http://www.ewido.net/en/download/ (W2K/XP Only)
    · Install ewido.
    · Run the application
    · Clickon scanner
    · then select the "Settings" tab.
    · Once in the Settings screen click on "Recommended actions" and then select "Delete".
    · Select "Automatically generate report after every scan"
    · Un-Select "Only if threats were found"
    · Click Complete System Scan and the scan will begin.
    · When the scan is finished, Set all items to delete
    · Apply all actions
    · look at the bottom of the screen and click the Save report button.
    · Save the report to your C: Drive
    This will take some time to run!
    RE-Boot


    In normal mode
    Run ActiveScan online virus scan:
    http://www.pandasoftware.com/products/activescan.htm
    When the scan is finished, save the results from the scan!

    Come back here and post a new Hijack This log along with the logs from the Ewido and Panda scans.
     
    Last edited: Aug 27, 2006
  3. chayne04

    chayne04 Regular member

    Joined:
    Mar 18, 2006
    Messages:
    216
    Likes Received:
    0
    Trophy Points:
    26
    ok, i have just finished the Ewido Scan. Here is the log. i will post the other two later on this evening. Thank YOu for your help.

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

    e w i d o a n t i - s p y w a r e - S c a n R e p o r t

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -



    + C r e a t e d a t : 5 : 4 2 : 2 4 P M 8 / 2 8 / 2 0 0 6



    + S c a n r e s u l t :







    H K L M \ S O F T W A R E \ C l a s s e s \ A p p I D \ A l t n e t S i g n i n g M o d u l e . E X E - > A d w a r e . A l t n e t : C l e a n e d .

    H K L M \ S O F T W A R E \ C l a s s e s \ A p p I D \ a d m . E X E - > A d w a r e . A l t n e t : C l e a n e d .

    C : \ W I N D O W S \ s y s t e m 3 2 \ S H A g e n t N e w . d l l - > A d w a r e . B a r g a i n B u d d y : C l e a n e d .

    H K L M \ S O F T W A R E \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ U n i n s t a l l \ R e l e v a n t K n o w l e d g e - > A d w a r e . B r o a d C a s t P C : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 3 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 4 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 5 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 3 6 . t m p - > A d w a r e . G o W e b S i t e : C l e a n e d .

    H K L M \ S O F T W A R E \ C l a s s e s \ I E x p l o r r 2 4 . c l s D W - > A d w a r e . I n e t S p e a k : C l e a n e d .

    H K L M \ S O F T W A R E \ C l a s s e s \ I E x p l o r r 2 4 . c l s D W \ C l s i d - > A d w a r e . I n e t S p e a k : C l e a n e d .

    C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ 9 8 C 4 0 0 6 8 - 5 9 4 C - 4 E 4 1 - A 6 C 4 - 5 9 1 2 9 E \ 5 D B 1 3 B 5 C - F 0 5 E - 4 9 1 9 - B 6 2 6 - A D 2 9 C 7 - > A d w a r e . N e w D o t N e t : C l e a n e d .

    H K L M \ S O F T W A R E \ C l a s s e s \ C L S I D \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

    H K L M \ S O F T W A R E \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ E x p l o r e r \ B r o w s e r H e l p e r O b j e c t s \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

    H K U \ S - 1 - 5 - 2 1 - 1 4 0 9 0 8 2 2 3 3 - 1 5 2 0 4 9 1 7 1 - 1 3 4 3 0 2 4 0 9 1 - 1 0 0 3 \ S o f t w a r e \ M i c r o s o f t \ W i n d o w s \ C u r r e n t V e r s i o n \ E x t \ S t a t s \ { 3 F E 3 6 8 0 7 - 6 9 E D - 4 5 D 1 - B 9 B E - 8 5 C 0 E 3 F 7 5 B 6 A } - > A d w a r e . V i r t u m o n d e : C l e a n e d .

    C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 6 5 . e x e - > A d w a r e . W e b R e b a t e s : C l e a n e d .

    C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 7 8 . E X E - > A d w a r e . W e b R e b a t e s : C l e a n e d .

    C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 4 1 7 9 . E X E - > A d w a r e . W e b R e b a t e s : C l e a n e d .

    C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 3 8 7 3 . e x e - > A d w a r e . W e b S e a r c h : C l e a n e d .

    C : \ R E C Y C L E R \ N P R O T E C T \ 0 0 0 0 3 8 7 4 . d l l - > A d w a r e . W e b S e a r c h : C l e a n e d .

    H K L M \ S O F T W A R E \ C l a s s e s \ P R O T O C O L S \ N a m e - S p a c e H a n d l e r \ r e s - > A d w a r e . W e b S e a r c h : C l e a n e d .

    H K L M \ S O F T W A R E \ T o o l b a r - > A d w a r e . W e b S e a r c h : C l e a n e d .

    H K L M \ S O F T W A R E \ T o o l b a r \ P l u g I n s - > A d w a r e . W e b S e a r c h : C l e a n e d .

    H K L M \ S O F T W A R E \ T o o l b a r \ P l u g I n s \ C O M M O N - > A d w a r e . W e b S e a r c h : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 7 A . t m p \ F C r X M L . d l l - > A d w a r e . W i n f i x e r : C l e a n e d .

    C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p \ d n y y z i c . t m p - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p \ d n y y z i l . t m p - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s A . e x e - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ _ _ d e l e t e _ o n _ r e b o o t _ _ W _ T _ o _ o _ l _ s _ B _ . _ d _ l _ l _ - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ A 6 E B 4 3 6 4 - 1 F 1 A - 4 3 7 B - 8 4 5 0 - 0 A 2 F 1 E \ 8 7 0 8 0 F 6 7 - C 9 9 4 - 4 4 B 0 - 8 2 2 F - 5 3 9 4 B A - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W S u p . e x e - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s A . e x e - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s B . d l l - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ W I N D O W S \ T e m p \ W T u n i n s t . e x e - > A d w a r e . W i n t o l : C l e a n e d .

    C : \ W I N D O W S \ T e m p \ ~ 7 5 2 3 2 2 . t m p - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

    [ 1 0 7 6 ] C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s B . d l l - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

    [ 3 1 5 6 ] C : \ P r o g r a m F i l e s \ C o m m o n F i l e s \ W i n T o o l s \ W T o o l s B . d l l - > A d w a r e . W i n t o l : E r r o r d u r i n g c l e a n i n g .

    C : \ W I N D O W S \ T e m p \ ~ 5 6 1 9 2 5 . t m p - > D o w n l o a d e r . W i n t o o l . a : E r r o r d u r i n g c l e a n i n g .

    C : \ W I N D O W S \ T e m p \ ~ 9 7 5 9 7 1 . t m p - > D o w n l o a d e r . W i n t o o l . a : E r r o r d u r i n g c l e a n i n g .

    C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ L o c a l S e t t i n g s \ T e m p o r a r y I n t e r n e t F i l e s \ C o n t e n t . I E 5 \ 0 D Y 9 8 J O J \ W i n T S [ 1 ] . c a b / W T o o l s S . e x e - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

    C : \ P r o g r a m F i l e s \ M i c r o s o f t A n t i S p y w a r e \ Q u a r a n t i n e \ A 6 E B 4 3 6 4 - 1 F 1 A - 4 3 7 B - 8 4 5 0 - 0 A 2 F 1 E \ E 2 A 5 2 B E C - 3 0 6 2 - 4 4 2 2 - A 3 2 7 - 2 8 C 7 6 1 - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 8 B . t m p \ W T o o l s S . e x e - > D o w n l o a d e r . W i n t o o l . f : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 C . t m p - > T r a c k i n g C o o k i e . 2 o 7 : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 7 . t m p - > T r a c k i n g C o o k i e . A d s e r v e r : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 E . t m p - > T r a c k i n g C o o k i e . A d v e r t i s i n g : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q 9 F . t m p - > T r a c k i n g C o o k i e . A t d m t : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 0 . t m p - > T r a c k i n g C o o k i e . B f a s t : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 2 . t m p - > T r a c k i n g C o o k i e . B u r s t n e t : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 3 . t m p - > T r a c k i n g C o o k i e . C a s a l e m e d i a : C l e a n e d .

    C : \ D o c u m e n t s a n d S e t t i n g s \ t e s t \ C o o k i e s \ t e s t @ c o m [ 1 ] . t x t - > T r a c k i n g C o o k i e . C o m : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 5 . t m p - > T r a c k i n g C o o k i e . D o u b l e c l i c k : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 8 . t m p - > T r a c k i n g C o o k i e . F a s t c l i c k : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 9 . t m p - > T r a c k i n g C o o k i e . H i t b o x : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A A . t m p - > T r a c k i n g C o o k i e . H i t b o x : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A B . t m p - > T r a c k i n g C o o k i e . H i t s l i n k : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A D . t m p - > T r a c k i n g C o o k i e . M e d i a p l e x : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A E . t m p - > T r a c k i n g C o o k i e . Q k s r v : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A F . t m p - > T r a c k i n g C o o k i e . Q u e s t i o n m a r k e t : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q A 6 . t m p - > T r a c k i n g C o o k i e . R u 4 : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 1 . t m p - > T r a c k i n g C o o k i e . S p y l o g : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 2 . t m p - > T r a c k i n g C o o k i e . T r a f f i c m p : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 3 . t m p - > T r a c k i n g C o o k i e . T r i b a l f u s i o n : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 5 . t m p - > T r a c k i n g C o o k i e . V a l u e c l i c k : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 6 . t m p - > T r a c k i n g C o o k i e . W e b t r e n d s l i v e : C l e a n e d .

    C : \ P r o g r a m F i l e s \ Y a h o o ! \ Y P S R \ Q u a r a n t i n e \ p p q B 8 . t m p - > T r a c k i n g C o o k i e . Z e d o : C l e a n e d .





    : : R e p o r t e n d


     
  4. Niobis

    Niobis Active member

    Joined:
    Jan 30, 2005
    Messages:
    2,326
    Likes Received:
    0
    Trophy Points:
    66
    Post a fresh HijackThis log.
     
  5. maca1

    maca1 Regular member

    Joined:
    Mar 15, 2006
    Messages:
    630
    Likes Received:
    0
    Trophy Points:
    26
    @Niobis

    and I'm also looking for a panda log.
     
    Last edited: Aug 30, 2006

Share This Page