This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Newbie to HJT has been getting strange errors

16 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

I've been getting some strange viruses that have been being caught real-time by Norton Anti Virus. Also, despite having SpyBot, AdAware, I've also been getting some fastclick popups. Can someone please take a look at this?

Viruses have popped up in wbk21.tmp and bla.exe and A0008123.exe.

I also ran panda scan which logged the following :

Incident Status Location

Adware:Adware/SaveNow No disinfected Windows Registry
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\smdat32m.sys
Adware:Adware/P2PNetworking No disinfected C:\DOCUME~1\Warren\LOCALS~1\Temp\p2psetup.exe
Adware:Adware/P2PNetworking No disinfected C:\Documents and Settings\Warren\Local Settings\Temp\p2psetup.exe
Adware:Adware/EliteBar No disinfected C:\Documents and Settings\Warren\Local Settings\Temp\temp.frB496
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\mssl23.exe
Spyware:Spyware/ISTbar No disinfected C:\WINDOWS\oeunist.exe
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\smdat32m.sys
Adware:Adware/EliteBar No disinfected C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GBKLW1EX\silent_install[1].exe


Thanks,
-nightcrawler729.

Logfile of HijackThis v1.99.1
Scan saved at 10:10:07 PM, on 7/6/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\javaw.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.morganstanley.com/dana-cache…oterisSetup.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{FAECFD0F-2D1C-4B68-818D-2B9F8EB2A3F1}: NameServer = 151.202.0.85 151.203.0.85
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ms.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ms.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
Hello and welcome to the forums. Sorry for the delay in responding, but we have been pretty busy here lately. If you could please post a new log, I will be glad to review it.
Here is my updated log. Thank you very much for helping out with this.

I ran Spybot and Ad-Aware SE with the latest definitions before this.

Logfile of HijackThis v1.99.1
Scan saved at 9:40:49 PM, on 7/25/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\NavNT\defwatch.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_03\bin\javaw.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\DIGSTR~1\DIGSTR~1.EXE
C:\PROGRA~1\ESPNRU~1\DIGSER~1.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Warren\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online Enterprise Edition) - https://portal.morganstanley.com/llclient/p…invpn3,CT=java+
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.morganstanley.com/dana-cache…oterisSetup.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{FAECFD0F-2D1C-4B68-818D-2B9F8EB2A3F1}: NameServer = 151.202.0.85 151.203.0.85
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ms.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ms.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Ok, I don't see much in there. Let's try a trojan scan. Please download the trial version of Ewido Security Suite here. Install it, and update the definitions to the newest files. Run the scan and allow it fix what it finds. Please post the log for me to review.
Here it is. Thanks for looking. ——————————————————- ewido security suite - Scan report ——————————————————— + Created on: 7:43:04 PM, 7/26/2005 + Report-Checksum: 7A28E52A + Scan result: :mozilla.16:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Masterstats : Cleaned with backup :mozilla.18:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.19:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.20:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.21:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.22:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.23:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.24:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.25:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup :mozilla.26:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.27:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup :mozilla.48:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.110:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.154:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.205:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.206:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.207:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.208:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.209:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.210:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.211:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.212:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup :mozilla.246:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.263:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.264:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.265:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.277:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.290:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.291:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.292:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.305:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup :mozilla.326:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.329:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.330:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.331:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.332:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.333:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.334:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.335:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.336:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.337:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.338:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.339:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup :mozilla.340:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.342:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.355:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.363:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.364:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.365:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup :mozilla.366:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.367:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.368:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.369:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.370:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.371:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.372:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.373:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.374:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.375:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.376:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.377:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.378:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.379:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.380:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.381:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.382:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.383:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.392:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.393:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.403:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.404:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.405:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.406:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.407:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.408:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.409:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.410:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.420:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.421:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.422:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.423:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.442:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.443:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.444:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup :mozilla.455:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.456:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup :mozilla.457:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.458:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup :mozilla.459:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.460:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.461:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup :mozilla.462:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup :mozilla.465:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.466:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.467:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup :mozilla.468:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.469:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup :mozilla.470:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup :mozilla.471:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.472:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.473:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.474:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.475:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.476:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.477:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.478:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.479:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.480:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.481:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.482:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.483:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.484:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.485:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.486:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.487:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.488:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.489:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.490:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.491:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.492:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.493:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.494:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.495:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.496:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.497:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.498:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.499:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.500:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.501:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.502:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.503:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.504:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.505:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.506:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.507:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.508:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.509:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.510:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.511:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.512:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.513:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.514:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.515:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.516:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.517:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.518:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.519:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.520:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.521:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup :mozilla.522:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.523:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.524:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.525:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.526:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.527:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.528:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.529:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.530:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup :mozilla.531:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.532:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.533:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.534:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup :mozilla.535:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.536:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.537:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.538:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.539:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup :mozilla.540:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup :mozilla.544:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.545:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.546:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.547:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.548:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup :mozilla.549:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup :mozilla.550:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup :mozilla.551:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.552:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.553:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.554:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup :mozilla.555:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup :mozilla.556:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup :mozilla.557:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.558:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup :mozilla.559:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.560:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.561:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.562:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup :mozilla.565:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.566:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.567:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup :mozilla.570:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup :mozilla.573:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.574:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.575:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.576:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.579:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.580:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.581:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.582:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.583:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup :mozilla.588:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.591:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.602:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.603:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.605:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.606:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.607:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.608:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.609:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.611:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.612:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.613:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.614:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.615:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.616:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.644:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.645:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.653:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.657:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.659:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.660:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.664:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.665:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Clickzs : Cleaned with backup :mozilla.669:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup :mozilla.673:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.675:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup :mozilla.677:C:\Documents and Settings\Warren\Application Data\Mozilla\Firefox\Profiles\2rtgznuo.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Masterstats : Cleaned with backup C:\Documents and Settings\Warren\Cookies\[removed][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup C:\WINDOWS\mssl23.exe -> TrojanDownloader.IstBar.er : Cleaned with backup C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\GBKLW1EX\silent_install[1].exe -> Spyware.EliteBar : Cleaned with backup ::Report End
Hmmm, ok some traces of the EliteBar. Let's make sure we get all of it. Please download miekiemoes' LQfix batch here:
http://www.downloads.subratam.org/LQfix.zip
Unzip it to the desktop but do NOT run it yet.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml


Once in Safe Mode, please run LQfix.bat. When finished, restart your computer in normal mode and please post a new HijackThis log.
Done. Here is the latest HijackThis log.

Logfile of HijackThis v1.99.1
Scan saved at 1:12:34 AM, on 7/28/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DIGStream\digstream.exe
C:\Program Files\ESPNRunTime\DIGServices.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Microsoft Office\Office10\msoffice.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\hjavaw.exe
C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
C:\Program Files\NavNT\rtvscan.exe
C:\Program Files\Java\j2re1.4.2_03\bin\javaw.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Warren\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://dslstart.verizon.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://mcontrol.ms.com/mission_control/4.7…proxyconfig.cgi
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [BuildBU] c:\dell\bldbubg.exe
O4 - HKLM\..\Run: [vptray] C:\Program Files\NavNT\vptray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [DIGServices] C:\Program Files\ESPNRunTime\DIGServices.exe /brand=ESPN /priority=0 /poll=24
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {3BA494B1-D507-4C11-9BDA-D47E1A65DFCF} (Confidence Online Enterprise Edition) - https://portal.morganstanley.com/llclient/p…invpn3,CT=java+
O16 - DPF: {4CC35DAD-40EA-4640-ACC2-A1A3B6FB3E06} (NeoterisSetup Control) - https://portal.morganstanley.com/dana-cache…oterisSetup.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {D06A22B4-6087-4D3D-B7AF-82B113E9ABD4} (CPostLaunch Object) - http://www2.verizon.net/update/msnwebinsta…es/vzWebIns.CAB
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ms.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ms.com
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: DefWatch - Symantec Corporation - C:\Program Files\NavNT\defwatch.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: Hummingbird Inetd (HCLInetd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Inetd\inetd32.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Hummingbird Jconfig Daemon (Jconfigd) - Hummingbird Ltd. - C:\WINDOWS\system32\Hummingbird\Connectivity\7.10\Jconfig\jconfigdnt.exe
O23 - Service: Network Configuration Service (NetCfgSvr) - AT&T - C:\PROGRA~1\MSREMO~1\NetCfgSv.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\Program Files\NavNT\rtvscan.exe
Ok, looks good. Can you run the Ewido scan again and post the results?

There is one item in your log that is questionable.

O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
If you haven't used Spybot S&D or another protection program to set these internet restrictions, or if your system administrator hasn't set these, run HijackThis and click "Scan." Place a checkmark next to this entry. Close all browser and other windows except for HijackThis, and click "Fix Checked" to have HijackThis fix the entrys you checked.
Ok, most likely, but let's do one more scan. Please download the free MWAV antivirus tool from here. Save it to the desktop and run it. Follow the prompts to scan your system for viruses. Then please post for me the log of infected files from the BOTTOM panel of the scan window. Please remove any lines relating to "Invalid object" as they are not needed at this time.
I got this : Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "CWS.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken.
Glad to hear it. Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. :P
  • On a regular basis, please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows, including the latest version of Internet Explorer. This can patch many of the security holes through which attackers can gain access to your computer.
  • In order to protect yourself against spyware, you should consider installing and running the following free programs:
    • Ad-Aware SE. A tutorial on using Ad-Aware to remove spyware from your computer may be found here. You have this installed currently. Please keep it updated and run it on a regular basis.
    • Spybot-Search & Destroy. A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features. You have this installed currently. Please keep it updated and run it on a regular basis.
    • SpywareBlaster. A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.
    • SpywareGuard. A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.
    Keeping these programs up-to-date and running them regularly can prevent a great deal of spyware hassle.
  • Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here.
  • Also make sure to run your antivirus software regularly, and to keep it up-to-date.
  • Finally, consider maintaining a firewall. Some good free firewalls are ZoneAlarm, Kerio, and Sygate. A tutorial on understanding and using firewalls may be found here.
Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. :D
Thanks again for the advice. I already automatically download the latest Windows Updates, and have Ad-Aware and Spybot, have Norton Anti-Virus which is regularly updated, and use Firefox. I'll get the other two, and also install a firewall…much appreciated again! Cheers.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI