Browser problems & strange error messages
Hi - I'm getting some problems when browsing or attempting to open a page from a link (its opening sometimes after 3 attempts or not at all) and also getting error pop ups. Also when I try to open some of my files the app crashes (like Word). Any help would be very much appreciated as I am not too savvy with this kind of thing.
I've run a Hijackthis scan
Thnx
Jon
Logfile of HijackThis v1.99.1
Scan saved at 8:31:18 AM, on 6/16/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\metc\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\System32\PAStiSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Jonathan\My Documents\Security, Virus & Spyware Protection\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:9090
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /R
O4 - HKLM\..\Run: [EnGraph QuickTimeKiller] C:\Program Files\EnGraph\QuickTimeKiller\QuickTimeKiller.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O15 - Trusted Zone: http://ajmyers.4java.ca
O15 - Trusted Zone: http://www.coolinvestor.com
O15 - Trusted Zone: http://*.eblackbox.net
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) - http://housecall65.trendmicro.com/ho...vex/hcImpl.cab
O16 - DPF: {21F49842-BFA9-11D2-A89C-00104B62BDDA} (ChartFX Internet Control) - http://www.schaeffersresearch.com/download/CfxIEAx.cab
O16 - DPF: {24BACF02-5676-11D3-B8DE-00105A17A9E6} (ChartFX Internet Financial Client 4.0) - http://www.schaeffersresearch.com/Do...4Financial.cab
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/actives.../as2stubie.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/reso...an8/oscan8.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/...toUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {BCBC9371-595D-11D4-A96D-00105A1CEF6C} (View22RTE Class) - http://onlinedesigner.hgtv.com/images/app/view22rte.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: metc-mysql - Unknown owner - C:\metc\mysql\bin\mysqld-nt.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: STI Simulator - Unknown owner - C:\WINDOWS\System32\PAStiSvc.exe
RE Browser problems & strange error messages
Hi - I followed the instructions for Superantispyware and Malwarebytes (which found and removed spme things) but had problems with gmer. It ran then when I checked it had finished my system had crashed. And I couldn't get a log. On restarting chkdisk was run automatically (with some things being fixed). Following this problems as before are still there. Also boot takes much longer now.
Any help would be appreciated.
Thnx.
Logs as follows:
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 06/16/2009 at 06:56 PM
Application Version : 4.22.1014
Core Rules Database Version : 3942
Trace Rules Database Version: 1884
Scan type : Complete Scan
Total Scan Time : 02:13:55
Memory items scanned : 148
Memory threats detected : 0
Registry items scanned : 7384
Registry threats detected : 0
File items scanned : 200076
File threats detected : 202
Adware.Tracking Cookie
C:\Documents and Settings\Jonathan\Cookies\jonathan@accountancyage[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adinterax[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adrevolver[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@11627418[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@atdmt[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@pwc[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@statcounter[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@questionmarket[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@serving-sys[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@kontera[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@zedo[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@apmebf[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@tribalfusion[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@collective-media[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@pwcuk[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@chitika[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@invitemedia[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@tacoda[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@77tracking[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@bristol-ext[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1058016793[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@revsci[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@advertising[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@5233448[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adviva[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@lse[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@burstnet[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@countrycallingcodes[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@media6degrees[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@travelexcom[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@cgi-bin[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adtech[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@dmtracker[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@trafficmp[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@specificclick[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@32020749[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1071750821[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1044287580[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1064725664[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@mediaplex[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@tradedoubler[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@66651396[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@cgi-bin[3].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@75452214[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1069095226[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@hotlog[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1070571421[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@intermundomedia[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@azjmp[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1038508577[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@hitbox[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@travelex[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@interclick[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@cgi-bin[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@S130923[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1072369480[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@casalemedia[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@capemaycountyherald[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@pro-market[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@valueclick[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@doubleclick[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1066705604[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@fastclick[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@insightexpressai[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@xiti[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@36491059[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@bristol[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@specificmedia[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1071060019[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@ak[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@realmedia[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adlegend[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@elitetrader[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1071617997[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1072546229[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1069695406[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@tdstats[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1054028224[2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@************[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adbrite[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@bravenet[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@trackalyzer[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1065846711[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@adrevolver[3].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1070369589[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1069721519[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1068592129[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@clicket[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@elitechoice[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1071603191[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@27908301[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1040926861[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1072740219[1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@1068570593[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@strath-ext[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@strathclyde[1].txt
C:\Documents and Settings\Jonathan\Cookies\[email protected][1].txt
.bs.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\Jonathan\Application Data\Mozilla\Firefox\Profiles\6cpxf44d.default\cookies.txt ]
C:\Documents and Settings\Jonathan\Cookies\jonathan@accounts[2].txt
C:\Documents and Settings\Jonathan\Cookies\jonathan@webstats[1].txt
Trojan.Unclassified-Packed/Suspicious
C:\PROGRAM FILES\COMMON FILES\SOFTINFORM\************\SEARCHENGINE\PLUGINS\ICQDS.DLL
C:\PROGRAM FILES\COMMON FILES\SOFTINFORM\************\SEARCHENGINE\PLUGINS\MDBDS.DLL
C:\PROGRAM FILES\COMMON FILES\SOFTINFORM\************\SEARCHENGINE\PLUGINS\QIPDS.DLL
C:\PROGRAM FILES\COMMON FILES\SOFTINFORM\************\SEARCHENGINE\PLUGINS\TRILLIANDS.DLL
C:\PROGRAM FILES\COMMON FILES\SOFTINFORM\************\SEARCHENGINE\PLUGINS\YAHOODS.DLL
Malwarebytes' Anti-Malware 1.37
Database version: 2290
Windows 5.1.2600 Service Pack 2
6/17/2009 6:01:44 AM
mbam-log-2009-06-17 (06-01-44).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 381071
Time elapsed: 2 hour(s), 6 minute(s), 31 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 2
Folders Infected: 3
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
c:\documents and settings\Jonathan\Application Data\FunWebProducts (Adware.MyWay) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathan\application data\funwebproducts\Data (Adware.MyWay) -> Quarantined and deleted successfully.
c:\documents and settings\Jonathan\application data\funwebproducts\Data\Jonathan (Adware.MyWay) -> Quarantined and deleted successfully.
Files Infected:
c:\documents and settings\Jonathan\application data\funwebproducts\Data\Jonathan\avatar.dat (Adware.MyWay) -> Quarantined and deleted successfully.
C:\WINDOWS\f49f4daa.dat (Worm.Koobface) -> Quarantined and deleted successfully.