Hello again.
After the cleanup before, I still had problems... 1. computer was running really slow... 2. CPU usage 100%...
Didn't whant to boder you again, when you sad the log was clean. BUT... problems were still there. So, I tried to do something by myself. Had Zone Alarm, so I thought it was causing CPU 100% all the time (vsmon.exe bug); I uninstaled Zone Alarm and instaled Kapersky firewall instead... and then tried to scan with AdAware...it would stoped after few seconds, it would froze the system... I tried on-line scanners (Panda)...also frozen system... I tried registry scan...frozen system...nothing did work. Ewido did mange to get through...scan finished...founded several traces of spyware, adware, trojans...a lot of trojans, lik: Trojan.SMALL, DOWNLOADER.SMALL, Trojan.FAKEALERT, Trojan.PAKES... it did delete all of those, so I reseted System Restore...did a Cleanup and then set it ON again... computer did start to behave rather normally...but I did a scan again...and then the Trojans were there again! deleted them ... back again... and again... I did TrendMicro on line scan...deleted some things too... Then reset, and now Ewido again...and Trojans are backl again
Don't know what to do anymore really
Ewido reports:
1. report
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:18:22 AM 7/3/2006
+ Scan result:
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015848.exe -> Adware.-- Look for another playground -- : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{021E022B-8712-4354-894C-785D7A7BCEEB}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{0480910B-F772-4E3F-ACBC-76A6FCB5CAD0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{096B7726-FFF0-4EAE-A338-A99DE460C2A4}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{1A533ECE-61E2-4CB5-9D43-11D16DA104DC}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{206D82CE-7E26-4D43-A534-2B8FD4A5C203}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{235296BC-3EB2-4089-A9AD-3C6EA35B82CC}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{255CC78C-ED09-4D23-AED2-0C2716A73A48}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{257873F8-D57D-4FE8-8909-3E7AEDFDE443}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{2C69C28B-2920-4E13-90E8-C39AD75A1B77}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{35BB75F3-AE96-49DA-BE73-E1B1CC6C43EB}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3631859F-3E90-4E25-A92B-C9B2A01DD8EF}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3EA79157-2B79-41D9-BD73-29264C1EB70C}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{489A5578-6E05-4744-8CA5-105C04648CE9}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{7B7FB3D6-F21E-4E53-ABCA-DE7A256311AB}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{8E15F754-8830-45EC-A5DE-95C1EBC4459D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{ABFC9250-0491-484A-9884-6EB013D1598D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{AE12FFF2-1A66-4DC6-B37C-7851B172BE99}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{C046535B-34B1-44AB-B8CE-B5F56353BC4C}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{DB76876D-2872-432E-A33E-0E77FA64A5F0}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{DF4DBE4C-992D-423C-8C7A-9172665D4805}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E518C750-2E74-4D84-8708-012314E3988C}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{E81C9E80-DB4F-4B3A-84CA-2593AD91ED39}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{FA7D4C19-EBE5-4BDB-AF76-A312B981277D}.exe -> Adware.FindSpy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012600.exe -> Adware.MediaBack : Cleaned with backup (quarantined).
D:\PROGRAMI\Programi\Sve za Divx\DivX Repair 1.0.6\repair-1.0.6.exe -> Adware.MediaBack : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017908.exe -> Adware.Msnagent : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015846.exe -> Adware.Raze : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015847.dll -> Adware.SBSoft : Cleaned with backup (quarantined).
D:\hjt\backups\backup-20060628-201026-179.dll -> Adware.SBSoft : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015845.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.47:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.40:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.50:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.51:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.52:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.53:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.31:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.33:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.36:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.37:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.69:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.70:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.74:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.75:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.18:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.19:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.20:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.113:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.114:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.115:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.108:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.109:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.110:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.111:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.112:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.120:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.48:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.105:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.106:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.107:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0016852.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0016853.exe -> Trojan.Fakealert : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{1341FD65-896E-4EA2-B7AA-A824B4AE6F2C}.exe -> Trojan.Hoster : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017872.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017926.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017944.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017956.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017969.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018097.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018129.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018182.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018205.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018220.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018263.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018276.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018286.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018298.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018310.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0019310.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0019334.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0020334.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0021334.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0021401.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012795.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012821.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0013821.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0013836.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0014836.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015844.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dmfui.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\{3E45C219-33DF-4714-A4C5-D95CDD330A22}.exe -> Trojan.Small.gq : Cleaned with backup (quarantined).
::Report end
2. report
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 7:33:54 PM 7/3/2006
+ Scan result:
C:\WINDOWS\system32\{009AD4BF-FBCC-4BB2-8EC1-3B9BE233251B}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{21402490-239B-40C9-9D02-4B4F389AED9A}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{3F869366-57CC-4501-9ABA-BB26C07C55BD}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{4055CEE9-8E8D-418D-BAA4-24623C5883BB}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{5FA03C70-7AF0-4082-B084-318BA0EF1DF3}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{67A670C2-91B3-47EF-A936-6B0B51A3F985}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{8C1BA9A9-0F11-4ADE-8365-90BA97A3682B}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{90EE7FF3-B90F-46A8-9471-F6D212548D58}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{A4278C10-94B3-42D9-8143-A7870F3F0D5A}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{A79A5BB3-3B28-44AC-AF86-4FD5BFE0D04C}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{AFE9CF8C-8387-4FCB-9DF7-A797F55F0922}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{C6CC1F3F-C146-4A01-9C12-C988372ACB0E}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{DAE733EB-1A91-4B4B-A062-F54852B6FE12}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{F389AB47-F479-443F-B8CA-8A3B42AD241F}.exe -> Adware.FindSpy : Cleaned.
C:\WINDOWS\system32\{61B813FE-D24C-43C9-9DCF-F83FED6AB9B7}.exe -> Adware.Msnagent : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000005.exe -> Trojan.Pakes : Cleaned.
[1348] VM_00B40000 -> Trojan.Pakes : Error during cleaning.
C:\WINDOWS\system32\{F8216C14-2545-49C3-B0AD-8526AE75FC39}.exe -> Trojan.Small.gq : Cleaned.
::Report end
3. report
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 1:17:28 AM 7/3/2006
+ Scan result:
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015848.exe -> Adware.-- Look for another playground -- : No action taken.
C:\WINDOWS\system32\{021E022B-8712-4354-894C-785D7A7BCEEB}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{0480910B-F772-4E3F-ACBC-76A6FCB5CAD0}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{096B7726-FFF0-4EAE-A338-A99DE460C2A4}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{1A533ECE-61E2-4CB5-9D43-11D16DA104DC}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{206D82CE-7E26-4D43-A534-2B8FD4A5C203}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{235296BC-3EB2-4089-A9AD-3C6EA35B82CC}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{255CC78C-ED09-4D23-AED2-0C2716A73A48}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{257873F8-D57D-4FE8-8909-3E7AEDFDE443}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{2C69C28B-2920-4E13-90E8-C39AD75A1B77}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{35BB75F3-AE96-49DA-BE73-E1B1CC6C43EB}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{3631859F-3E90-4E25-A92B-C9B2A01DD8EF}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{3EA79157-2B79-41D9-BD73-29264C1EB70C}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{489A5578-6E05-4744-8CA5-105C04648CE9}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{7B7FB3D6-F21E-4E53-ABCA-DE7A256311AB}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{8E15F754-8830-45EC-A5DE-95C1EBC4459D}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{ABFC9250-0491-484A-9884-6EB013D1598D}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{AE12FFF2-1A66-4DC6-B37C-7851B172BE99}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{C046535B-34B1-44AB-B8CE-B5F56353BC4C}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{DB76876D-2872-432E-A33E-0E77FA64A5F0}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{DF4DBE4C-992D-423C-8C7A-9172665D4805}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{E518C750-2E74-4D84-8708-012314E3988C}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{E81C9E80-DB4F-4B3A-84CA-2593AD91ED39}.exe -> Adware.FindSpy : No action taken.
C:\WINDOWS\system32\{FA7D4C19-EBE5-4BDB-AF76-A312B981277D}.exe -> Adware.FindSpy : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012600.exe -> Adware.MediaBack : No action taken.
D:\PROGRAMI\Programi\Sve za Divx\DivX Repair 1.0.6\repair-1.0.6.exe -> Adware.MediaBack : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017908.exe -> Adware.Msnagent : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015846.exe -> Adware.Raze : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015847.dll -> Adware.SBSoft : No action taken.
D:\hjt\backups\backup-20060628-201026-179.dll -> Adware.SBSoft : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015845.exe -> Downloader.Small.buy : No action taken.
:mozilla.93:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.47:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.40:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.50:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.51:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.52:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.53:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.31:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.33:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.36:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.37:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.69:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.70:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.74:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.75:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.18:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken.
:mozilla.19:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken.
:mozilla.20:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken.
:mozilla.113:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.114:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.115:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.108:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.109:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.110:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.111:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.112:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.120:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.48:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.105:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.106:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.107:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0016852.exe -> Trojan.Fakealert : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0016853.exe -> Trojan.Fakealert : No action taken.
C:\WINDOWS\system32\{1341FD65-896E-4EA2-B7AA-A824B4AE6F2C}.exe -> Trojan.Hoster : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017872.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017926.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017944.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017956.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0017969.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018097.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018129.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018182.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018205.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018220.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018263.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018276.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018286.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018298.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0018310.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0019310.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0019334.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0020334.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0021334.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP75\A0021401.exe -> Trojan.Pakes : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012795.exe -> Trojan.Small : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0012821.exe -> Trojan.Small : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0013821.exe -> Trojan.Small : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0013836.exe -> Trojan.Small : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0014836.exe -> Trojan.Small : No action taken.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP74\A0015844.exe -> Trojan.Small : No action taken.
C:\WINDOWS\system32\dmfui.exe -> Trojan.Small : No action taken.
C:\WINDOWS\system32\{3E45C219-33DF-4714-A4C5-D95CDD330A22}.exe -> Trojan.Small.gq : No action taken.
::Report end
4. report
---------------------------------------------------------
ewido anti-spyware - Scan Report
---------------------------------------------------------
+ Created at: 9:49:35 PM 7/3/2006
+ Scan result:
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000017.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000018.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000019.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000020.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000021.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000022.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000023.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000024.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000025.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000026.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000027.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000028.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000029.exe -> Adware.FindSpy : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000030.exe -> Adware.FindSpy : Cleaned.
[1460] VM_00A50000 -> Downloader.Agent.uj : Error during cleaning.
[1540] VM_003F0000 -> Downloader.Agent.uj : Error during cleaning.
[1548] VM_009F0000 -> Downloader.Agent.uj : Error during cleaning.
[1572] VM_00920000 -> Downloader.Agent.uj : Error during cleaning.
[1584] VM_00B00000 -> Downloader.Agent.uj : Error during cleaning.
[1680] VM_00AD0000 -> Downloader.Agent.uj : Error during cleaning.
[548] VM_00DD0000 -> Downloader.Agent.uj : Error during cleaning.
[572] VM_00A70000 -> Downloader.Agent.uj : Error during cleaning.
:mozilla.16:C:\Documents and Settings\Hum\Application Data\Mozilla\Firefox\Profiles\6vr16ioq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000036.exe -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0001036.exe -> Trojan.Pakes : Cleaned.
C:\WINDOWS\system32\{5C448684-CDA7-42FA-9BA5-9F535717E349}.exe -> Trojan.Puper.bx : Cleaned.
C:\WINDOWS\system32\{67F65C13-3EA1-4140-92CE-44A065FECCB1}.exe -> Trojan.Puper.bx : Cleaned.
C:\System Volume Information\_restore{703B89D9-35CB-46F9-BC5C-340B0496462F}\RP1\A0000016.exe -> Trojan.Small.gq : Cleaned.
::Report end
I included all 4 reports so you can see that the trojans are getting back, and they are in Sys, restore :boh:
_______________________________________________________________________________________
I'll include a HJT log as well:
Logfile of HijackThis v1.99.1
Scan saved at 9:52:51 PM, on 7/3/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe
C:\Program Files\Pincom\PinCableViewer\PinCableViewer.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
D:\Programs\kerio_firewall\Personal Firewall\kpf4ss.exe
C:\WINDOWS\system32\svchost.exe
D:\Programs\kerio_firewall\Personal Firewall\kpf4gui.exe
C:\WINDOWS\System32\alg.exe
D:\Programs\kerio_firewall\Personal Firewall\kpf4gui.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Mozilla Firefox\firefox.exe
D:\hjt\HijackThis.exe
D:\Programs\kerio_firewall\Personal Firewall\assist.exe
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O1 - Hosts: localhost 127.0.0.1
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Programs\SpybotSD\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [dmorw.exe] C:\WINDOWS\system32\dmorw.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win
O4 - Global Startup: Check Local Printer.lnk = C:\Program Files\KXP6X00\Chkpnt.exe
O4 - Global Startup: PinCableViewer.lnk = C:\Program Files\Pincom\PinCableViewer\PinCableViewer.exe
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: I&zvoz u Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -
http://download.ewido.net/ewidoOnlineScan.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/shock...ash/swflash.cabO23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - D:\Programs\kerio_firewall\Personal Firewall\kpf4ss.exe
Any Ideas?