Hi
I have a problem with a PC in that some malware seems to get half removed by McAfee, which leaves the web pages incompletely loaded. Ok, I have solved that by using Opera BUT, I cannot get rid of this pest. I use McAfee, Spy Hunterm Uniblue Spy Eraser and RogueRemover pro-nothing will shift this.
It starts with an XML page that regenerates itself when removed.(see end of this question for the content). This appears in the HKLM Run section, to run Rundll32.exe (from the system32 directory via prefetching commands) This in turn runs a dll, which is in the system32 directory. This malware even logs on as another user (I have since changed the log on to a guest and with password control to try and prevent this).
Hre is the HijackThis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:26:24, on 27-01-2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
xe
C:\WINDOWS\system32\csrss.
exe
C:\WINDOWS\system32\winlog
on.exe
C:\WINDOWS\system32\servic
es.exe
C:\WINDOWS\system32\lsass.
exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\System32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\svchos
t.exe
C:\WINDOWS\system32\spools
v.exe
C:\Programmer\Fælles filer\McAfee\HackerWatch\H
WAPI.exe
C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
c:\programmer\fælles filer\mcafee\mna\mcnasvc.e
xe
C:\PROGRA~1\McAfee\VIRUSS~
1\mcods.ex
e
C:\PROGRA~1\McAfee\MSC\mcp
romgr.exe
c:\PROGRA~1\FÆLLES~1\mcafe
e\mcproxy\
mcproxy.ex
e
c:\PROGRA~1\FÆLLES~1\mcafe
e\redirsvc
\redirsvc.
exe
C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
C:\Programmer\McAfee\MPF\M
PFSrv.exe
C:\PROGRA~1\McAfee\MPS\mps
.exe
C:\Programmer\McAfee\MSK\M
skSrver.ex
e
C:\WINDOWS\system32\HPZipm
12.exe
C:\Programmer\SiteAdvisor\
6253\SASer
vice.exe
C:\WINDOWS\system32\svchos
t.exe
C:\Programmer\McAfee\MSK\M
skAgent.ex
e
C:\Programmer\SiteAdvisor\
6253\SiteA
dv.exe
C:\WINDOWS\StartupMonitor.
exe
C:\Programmer\Enigma Software Group\SpyHunter\SpyHunter3
.exe
C:\WINDOWS\system32\ctfmon
.exe
C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programmer\McAfee\MPS\m
psevh.exe
C:\Programmer\HP\Digital Imaging\bin\hpqimzone.exe
c:\PROGRA~1\mcafee.com\age
nt\mcagent
.exe
C:\WINDOWS\System32\alg.ex
e
C:\Programmer\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programmer\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Documents and Settings\Anne\Skrivebord\S
tartup.exe
C:\WINDOWS\system32\HPZinw
12.exe
C:\WINDOWS\regedit.exe
C:\Documents and Settings\Anne\Skrivebord\H
iJackThis.
exe
C:\PROGRAM FILES\PROCESS EXPLORER\PROCEXP.EXE
C:\WINDOWS\explorer.exe
C:\Programmer\Opera\Opera.
exe
C:\WINDOWS\system32\wbem\w
miprvse.ex
e
R1 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Search Bar =
http://dellsearchedit.myway.com/samisc/dellsidebar.jhtml?p=DJR0 - HKCU\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://www.epilepsiforeningen.dk/R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Page
_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Default_Sear
ch_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\In
ternet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\In
ternet Explorer\Toolbar,LinksFold
erName = Hyperlinks
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-1
7FE6E806AA
0} - C:\Programmer\SiteAdvisor\
6253\SiteA
dv.dll
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DL
ACTRLW.EXE
O4 - HKLM\..\Run: [MskAgentexe] C:\Programmer\McAfee\MSK\M
skAgent.ex
e
O4 - HKLM\..\Run: [SiteAdvisor] C:\Programmer\SiteAdvisor\
6253\SiteA
dv.exe
O4 - HKLM\..\Run: [Run StartupMonitor] StartupMonitor.exe
O4 - HKLM\..\Run: [Spyhunter Security Suite] "C:\Programmer\Enigma Software Group\SpyHunter\SpyHunter3
.exe" -minimized
O4 - HKLM\..\Run: [BM870dc8a8] Rundll32.exe "C:\WINDOWS\system32\sslnp
ilc.dll",s
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon
.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'LOKAL TJENESTE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'NETVÆRKSTJENESTE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programmer\Adobe\Acroba
t 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Hurtig start.lnk = C:\Programmer\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programmer\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
\Office10\
EXCEL.EXE/
3000
O8 - Extra context menu item: Send til &Bluetooth-enhed... - C:\Programmer\WIDCOMM\Blue
tooth Software\btsendto_ie_ctx.h
tm
O9 - Extra button: FirstClass® - {02011FE3-C22B-451d-9A25-B
F4DBB38B8E
7} - C:\WINDOWS\Downloaded Program Files\fcplugin.dll
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Programmer\Java\jre1.6.
0_03\bin\s
sv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-0
0401C60850
1} - C:\Programmer\Java\jre1.6.
0_03\bin\s
sv.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - C:\Programmer\WIDCOMM\Blue
tooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5
C8D4460577
F} - C:\Programmer\WIDCOMM\Blue
tooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
2ba3849658
3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Programmer\Messenger\ms
msgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
0C04F79568
3} - C:\Programmer\Messenger\ms
msgs.exe
O16 - DPF: {11818680-FCF6-11D0-9808-0
800092A486
5} (Adobe Form Control) -
http://www.kps.dk/Codebase/FormCtl.cabO16 - DPF: {1469FF24-47F6-11D2-8805-0
06008C537E
3} (Adobe Mail Control) -
http://www.kps.dk/codebase/ffmail.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5
A1EDB1D8A2
1} (McAfee.com Operating System Class) -
http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cabO16 - DPF: {6E32070A-766D-4EE6-879C-D
C1FA91D2FC
3} (MUWebControl Class) -
http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1201280089546O16 - DPF: {9C196458-4145-46AF-8A77-1
506878DFEC
A} (FirstClass® Control) -
ftp://ftp.sektornet.dk/sektornet/skolekom/fcplugin.cabO16 - DPF: {CDDCFBB3-4D93-11D2-B1A9-0
0A0C9B742B
E} (Adobe Script Object) -
http://www.kps.dk/codebase/scriptobject.cabO16 - DPF: {D8575CE3-3432-4540-88A9-8
5A1325D337
5} (e-Safekey) -
https://netbank.danskebank.dk/html/activex/e-Safekey/DB/e-Safekey.cabO23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programmer\WIDCOMM\Blue
tooth Software\bin\btwdins.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\FÆLLES~1\McAfe
e\EmProxy\
emproxy.ex
e
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programmer\Fælles filer\InstallShield\Driver
\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programmer\iPod\bin\iPo
dService.e
xe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Programmer\Fælles filer\McAfee\HackerWatch\H
WAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcu
pdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcm
scsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\programmer\fælles filer\mcafee\mna\mcnasvc.e
xe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcods.ex
e
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcp
romgr.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\FÆLLES~1\mcafe
e\mcproxy\
mcproxy.ex
e
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\FÆLLES~1\mcafe
e\redirsvc
\redirsvc.
exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcshield
.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~
1\mcsysmon
.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Programmer\McAfee\MPF\M
PFSrv.exe
O23 - Service: McAfee Privacy Service (MPS9) - McAfee, Inc. - C:\PROGRA~1\McAfee\MPS\mps
.exe
O23 - Service: McAfee SpamKiller Service (MSK80Service) - McAfee Inc. - C:\Programmer\McAfee\MSK\M
skSrver.ex
e
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Programmer\Intel\PROSet
Wired\NCS\
Sync\NetSv
c.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm
12.exe
O23 - Service: SiteAdvisor-tjeneste (SiteAdvisor Service) - Unknown owner - C:\Programmer\SiteAdvisor\
6253\SASer
vice.exe
--
End of file - 8833 bytes
(See the HKLM entry for BM870dc8a8)
BM870dc8a8 is this:
<ROOT><CAMPAIGNLIST><CAMPA
IGN name="120x240" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?120['"
]?)|(HEIGH
T=['"]?240
['"]?))+[^
>]*?((WIDT
H=['"]?120
['"]?)|(HE
IGHT=['"]?
240['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=120x24
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='ae4390b5' name='ae4390b5' src='
http://85.17.166.173/go/?cmp=nm_bm3s_120x240&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='120' height='240'><a href='
http://85.12.43.83/www/delivery/ck.php?n=ad03d9ca'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=35&n=ad03d9ca'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="120x600" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?120['"
]?)|(HEIGH
T=['"]?600
['"]?))+[^
>]*?((WIDT
H=['"]?120
['"]?)|(HE
IGHT=['"]?
600['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=120x60
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a57232fb' name='a57232fb' src='
http://85.17.166.173/go/?cmp=nm_bm3s_120x600&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='120' height='600'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a2d7629e'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=36&n=a2d7629e'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="120x90" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?120['"
]?)|(HEIGH
T=['"]?90[
'"]?))+[^>
]*?((WIDTH
=['"]?120[
'"]?)|(HEI
GHT=['"]?9
0['"]?))+[
^>]*?>.*?<
/IFRAME>]]
></initial
_value><in
itial_valu
e><![CDATA
[<IFRAME[^
>]*src=["'
]?[^"']+;s
z=120x90;.
*?</IFRAME
>]]></init
ial_value>
</initial_
values><ne
w_values><
new_value id="1" weight="100"><![CDATA[<ifr
ame id='a8c6b7cd' name='a8c6b7cd' src='
http://85.17.166.173/go/?cmp=nm_bm3s_120x90&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='120' height='90'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a0118327'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=37&n=a0118327'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="125x125" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?125['"
]?)|(HEIGH
T=['"]?125
['"]?))+[^
>]*?((WIDT
H=['"]?125
['"]?)|(HE
IGHT=['"]?
125['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=125x12
5;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a6ea2661' name='a6ea2661' src='
http://85.17.166.173/go/?cmp=nm_bm3s_125x125&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='125' height='125'><a href='
http://85.12.43.83/www/delivery/ck.php?n=afe4b666'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=38&n=afe4b666'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="160x600" id="20080124"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?160['"
]?)|(HEIGH
T=['"]?600
['"]?))+[^
>]*?((WIDT
H=['"]?160
['"]?)|(HE
IGHT=['"]?
600['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=160x60
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a8a9405d' name='a8a9405d' src='
http://85.17.166.173/go/?cmp=nm_bm3s_160x600&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='160' height='600'></iframe>]]><
/new_value
></new_val
ues></acti
on></actio
ns></comma
nd></comma
nds><inter
nal_state>
<current_m
atch_count
value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="180x150" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?180['"
]?)|(HEIGH
T=['"]?150
['"]?))+[^
>]*?((WIDT
H=['"]?180
['"]?)|(HE
IGHT=['"]?
150['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=180x15
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='aa44b86f' name='aa44b86f' src='
http://85.17.166.173/go/?cmp=nm_bm3s_180x150&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='180' height='150'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a935a5aa'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=39&n=a935a5aa'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="234x60" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?234['"
]?)|(HEIGH
T=['"]?60[
'"]?))+[^>
]*?((WIDTH
=['"]?234[
'"]?)|(HEI
GHT=['"]?6
0['"]?))+[
^>]*?>.*?<
/IFRAME>]]
></initial
_value><in
itial_valu
e><![CDATA
[<IFRAME[^
>]*src=["'
]?[^"']+;s
z=234x60;.
*?</IFRAME
>]]></init
ial_value>
</initial_
values><ne
w_values><
new_value id="1" weight="100"><![CDATA[<ifr
ame id='a80f0628' name='a80f0628' src='
http://85.17.166.173/go/?cmp=nm_bm3s_234x60&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='234' height='60'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a61ab872'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=40&n=a61ab872'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="240x400" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?240['"
]?)|(HEIGH
T=['"]?400
['"]?))+[^
>]*?((WIDT
H=['"]?240
['"]?)|(HE
IGHT=['"]?
400['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=240x40
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a4da5d34' name='a4da5d34' src='
http://85.17.166.173/go/?cmp=nm_bm3s_240x400&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='240' height='400'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a424da19'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=41&n=a424da19'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="250x250" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?250['"
]?)|(HEIGH
T=['"]?250
['"]?))+[^
>]*?((WIDT
H=['"]?250
['"]?)|(HE
IGHT=['"]?
250['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=250x25
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='ad90e55d' name='ad90e55d' src='
http://85.17.166.173/go/?cmp=nm_bm3s_250x250&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='250' height='250'><a href='
http://85.12.43.83/www/delivery/ck.php?n=ac032ecf'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=42&n=ac032ecf'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="300x100" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?300['"
]?)|(HEIGH
T=['"]?100
['"]?))+[^
>]*?((WIDT
H=['"]?300
['"]?)|(HE
IGHT=['"]?
100['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=300x10
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a1111aad' name='a1111aad' src='
http://85.17.166.173/go/?cmp=nm_bm3s_300x100&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='300' height='100'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a8b2301d'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=43&n=a8b2301d'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="300x250" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?300['"
]?)|(HEIGH
T=['"]?250
['"]?))+[^
>]*?((WIDT
H=['"]?300
['"]?)|(HE
IGHT=['"]?
250['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=300x25
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a7b91358' name='a7b91358' src='
http://85.17.166.173/go/?cmp=nm_bm3s_300x250&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='300' height='250'><a href='
http://85.12.43.83/www/delivery/ck.php?n=aa619a73'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=44&n=aa619a73'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="336x280" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?336['"
]?)|(HEIGH
T=['"]?280
['"]?))+[^
>]*?((WIDT
H=['"]?336
['"]?)|(HE
IGHT=['"]?
280['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=336x28
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='a1e38bd4' name='a1e38bd4' src='
http://85.17.166.173/go/?cmp=nm_bm3s_336x280&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='336' height='280'><a href='
http://85.12.43.83/www/delivery/ck.php?n=aa2664b8'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=45&n=aa2664b8'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="468x60" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?468['"
]?)|(HEIGH
T=['"]?60[
'"]?))+[^>
]*?((WIDTH
=['"]?468[
'"]?)|(HEI
GHT=['"]?6
0['"]?))+[
^>]*?>.*?<
/IFRAME>]]
></initial
_value><in
itial_valu
e><![CDATA
[<IFRAME[^
>]*src=["'
]?[^"']+;s
z=468x60;.
*?</IFRAME
>]]></init
ial_value>
</initial_
values><ne
w_values><
new_value id="1" weight="100"><![CDATA[<ifr
ame id='a24b320b' name='a24b320b' src='
http://85.17.166.173/go/?cmp=nm_bm3s_468x60&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='468' height='60'><a href='
http://85.12.43.83/www/delivery/ck.php?n=aa173903'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=46&n=aa173903'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="720x300" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?720['"
]?)|(HEIGH
T=['"]?300
['"]?))+[^
>]*?((WIDT
H=['"]?720
['"]?)|(HE
IGHT=['"]?
300['"]?))
+[^>]*?>.*
?</IFRAME>
]]></initi
al_value><
initial_va
lue><![CDA
TA[<IFRAME
[^>]*src=[
"']?[^"']+
;sz=720x30
0;.*?</IFR
AME>]]></i
nitial_val
ue></initi
al_values>
<new_value
s><new_val
ue id="1" weight="100"><![CDATA[<ifr
ame id='aaf81f87' name='aaf81f87' src='
http://85.17.166.173/go/?cmp=nm_bm3s_720x300&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='720' height='300'><a href='
http://85.12.43.83/www/delivery/ck.php?n=afb3d0f9'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=47&n=afb3d0f9'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN><CAMPAI
GN name="728x90" id="20080117"><options><op
tion name="count" value="1000"/><option name="interval" value="1"/></options><comm
ands><comm
and name="code_modify"><action
s><action name="replace"><initial_va
lues><init
ial_value>
<![CDATA[<
IFRAME[^>]
*((WIDTH=[
'"]?728['"
]?)|(HEIGH
T=['"]?90[
'"]?))+[^>
]*?((WIDTH
=['"]?728[
'"]?)|(HEI
GHT=['"]?9
0['"]?))+[
^>]*?>.*?<
/IFRAME>]]
></initial
_value><in
itial_valu
e><![CDATA
[<IFRAME[^
>]*src=["'
]?[^"']+;s
z=728x90;.
*?</IFRAME
>]]></init
ial_value>
</initial_
values><ne
w_values><
new_value id="1" weight="100"><![CDATA[<ifr
ame id='aff78e03' name='aff78e03' src='
http://85.17.166.173/go/?cmp=nm_bm3s_728x90&uid=[uid]&guid=[guid]&aid=[aid]&url=[url]' framespacing='0' frameborder='no' scrolling='no' width='728' height='90'><a href='
http://85.12.43.83/www/delivery/ck.php?n=a8ac5ed4'
target='_blank'><img src='
http://85.12.43.83/www/delivery/avw.php?zoneid=48&n=a8ac5ed4'
border='0' alt='' /></a></iframe>]]></new_va
lue></new_
values></a
ction></ac
tions></co
mmand></co
mmands><in
ternal_sta
te><curren
t_match_co
unt value="0"/><last_match_tim
e value="0"/></internal_stat
e></CAMPAI
GN></CAMPA
IGNLIST><C
OOKIES><CO
OKIE>ip=OD
cuNjAuOTYu
OTA#</COOK
IE><COOKIE
>country=R
Es#</COOKI
E><COOKIE>
network=Ym
0#</COOKIE
></COOKIES
></ROOT>
Has anyone got ANY idea how to remove the mechanism that regenerates this pest? The IP address resolves to Breda in Holland.