This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer slow; opens with "Server Busy"

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.98.2
Scan saved at 8:15:59 AM, on 10/14/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Intuit\QAgent\QAGENT.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Samsung\Digimax Viewer 2.0\STImgBrowser.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Symantec\ACT\act.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\HJT\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.provide.net/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E9147A0A-A866-4214-B47C-DA821891240F} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\Intuit\QAgent\QAGENT.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra 'Tools' menuitem: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://V4.Windowsupdate.microsft.com
O15 - Trusted Zone: http://Windowsupdate.micrsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - https://quickplace01.geextranet.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} - http://movie-browser.com/tl4000.dll
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F31B9DB5-982E-4AB8-B336-C2CE48DDF39D}: NameServer = 151.164.1.8,206.13.28.12


On boot up a window indicating "Server Busy" appears briefly. Computer operation has become sluggish over months of useage. Have run Ad-Aware and Spybot.
We are sorry for the delay in replying to you.

If you still require help, please Update to HijackThis 1.99.1.
  • Open HijackThis and click config.. < Misc. Tools, scroll down and click Check for Update Online.
Post a fresh Hijackthis log as a reply to this thread.

I'll receive an e-mail notification of your reply and will respond as soon as possible.

Thank you for your patience.
Alan,

Thnaks for the response.
I am trying to attahced the "new" log after having updated to 1.99.1.

I have not seen the "Server Busy" message on boot up for a couple of days.

MI am convinced my computer is loadced with junk accumulated over the years that
I neither recogniser nort know how to eliminate.

Thanks,
Randy

Logfile of HijackThis v1.99.1
Scan saved at 8:56:55 AM, on 10/31/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Intuit\QAgent\QAGENT.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Samsung\Digimax Viewer 2.0\STImgBrowser.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Outlook Express\MSIMN.EXE
C:\Program Files\Symantec\ACT\act.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Norton AntiVirus\OPScan.exe
C:\DOCUME~1\RANDAL~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.provide.net/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {E9147A0A-A866-4214-B47C-DA821891240F} - (no file)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\Intuit\QAgent\QAGENT.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra 'Tools' menuitem: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://V4.Windowsupdate.microsft.com
O15 - Trusted Zone: http://Windowsupdate.micrsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - https://quickplace01.geextranet.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} - http://movie-browser.com/tl4000.dll
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F31B9DB5-982E-4AB8-B336-C2CE48DDF39D}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
Hello rrumpf and welcome to TomCoyote. :wavey:

You have the latest version of HijackThis but are now running it from within the zipped folder.
There is not many bad items showing in the HijackThis log. We'll fix what is present then run several scans to see if anything else can be found.

Step 1
Move HijackThis to Permanent Folder:
HijackThis needs to be unzipped into a permanent folder in order to save backups just in case something goes wrong.
  • Go to Start > My Computer > and double click on C:.
  • Now right click an open area and click New > folder and change the folder name to HJT.
  • Extract HijackThis from the zipped file into this new folder.
Step 2
Open HijackThis, run a scan, then check the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com

O2 - BHO: (no name) - {E9147A0A-A866-4214-B47C-DA821891240F} - (no file)

O16 - DPF: {C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} - http://movie-browser.com/tl4000.dll


With all other programs and browsers closed, click fix checked.


Step 3
Please set your computer to show all files.
  • Double-click My Computer.
  • Click the Tools menu, and then click Folder Options.
  • Click the View tab.
  • Clear "Hide file extensions for known file types."
  • Under the "Hidden files" folder, select "Show hidden files and folders."
  • Clear "Hide protected operating system files."
  • Click Apply, and then click OK.
You will need to reverse this process when all steps are done.


Step 4
Please download the trial version of Ewido security suite.

Install and Update Ewido:
  • Download and install Ewido security suite.
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch Ewido, there should be an icon on your desktop for it to double-click.
    • The program will prompt you to update, click the OK button.
    • The program will now go to the main screen.
  • You will need to update ewido to the latest definition files.
    • On the left hand side of the main screen click update.
    • Click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
  • Once the updates are installed, close the program.
Scanning With Ewido:
  • Reboot into Safe Mode (tap F8 during bootup, use arrow keys to select Safe Mode, then hit 'enter').
  • Launch Ewido again.
    • Click on scanner
    • Click on Complete System Scan and the scan will begin.
    • While the scan is in progress you will be prompted to clean files, click OK
    • When it asks if you want to clean the first file, put a check in the lower left corner of the boxes that say "Perform action on all infections"and "Create encrypted backup" then choose clean and click OK.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    • Click Save report.
    • Save the report .txt file to your desktop.
  • Now close ewido security suite.
Step 5
Please download and install Ad-Aware SE and Spybot S&D according to the following instructions. If you already have these programs, please make sure they are the latest version (Ad-Aware SE Personal 1.06, Spybot Search and Destroy 1.4), than run scans as described below.

Scanning with Spybot S&D;:
  • Downloaded and Install Spybot S&D; accepting the Default Settings.
  • In the Menu Bar at the top of the Spybot window you will see 'Mode'. Make certain that 'default mode' has a check mark beside it.
  • Close ALL windows except Spybot S&D.
  • Click the button to ‘Search for Updates’ then download and install the Updates.
  • Next click the button ‘Check for Problems’
  • When Spybot is complete, it will be showing ‘RED’ entries bold 'Black' entries and ‘GREEN’ entries in the window.
  • Make certain there is a check mark beside all of the RED entries ONLY.
  • Choose ‘Fix Selected Problems’ and allow Spybot to fix the RED entries.
  • REBOOT to complete the scan and clear memory.
  • Do not enable Tea Timer until the log is clean as it will prevent the fix from working.
Scanning with Ad-Aware SE:
  • Download and Install Ad-Aware SE, keeping the default options. However, some of the settings will need to be changed before your first scan.
  • Close ALL windows except Ad-Aware SE.
  • Click on the‘world’ icon at the top right of the Ad-Aware SE window and let AdAware SE update the reference list for the adware and malware.
  • Once the update is finished click on the ‘Gear’ icon (second from the left at the top of the window) to access the preferences/settings window.
    • In the ‘General’ window make sure the following are selected in green:
      • Automatically save log-file
      • Automatically quarantine objects prior to removal
      • Safe Mode (always request confirmation)
    • Under Definitions:
      • Prompt to udate outdated definitions - set the number of days
    • Click on the ‘Scanning’ button on the left and select in green :
      • Under Driver, Folders & Files:
        • Scan Within Archives
      • Under Select drives & folders to scan -
        • choose all hard drives
      • Under Memory & Registry: all green
      • Scan active processes
      • Scan registry
      • Deep-scan registry
      • Scan my IE favorites for banned URLs
      • Scan my Hosts file
    • Click on the ‘Advanced’ button on the left and select in green:
      • Under Shell Integration:
        • Move deleted files to recycle bin
      • Under Logfile Detail Level: (all green)
        • include addtional object information
        • DESELECT - include negligible objects information
        • include environment information
      • Under Alternate Data Streams:
        • Don't log streams smaller than 0 bytes
        • Don't log ADS with the following names: CA_INOCULATEIT
    • Click the ‘Tweak’ button and select in green:
      • Under the ‘Scanning Engine’:
        • Unload recognized processes during scanning
        • Scan registry for all users instead of current user only
      • Under the ‘Cleaning Engine’:
        • Always try to unload modules before deletion
        • During removal, unload Explorer and IE if necessary
        • Let Windows remove files in use at next reboot
      • Under the Log Files:
        • Include basic Ad-aware SE settings in logfile
        • Include additional Ad-aware SE settings in logfile
        • Create logfile for removal operations.
        • Please do not check or make green: Include Module list in logfile
  • Click on ‘Proceed’ to save the settings.
  • Click ‘Start’
    • Choose:'Perform Full System Scan'
    • DESELECT "Search for negligible risk entries", as negligible risk entries (MRU's) are not considered to be a threat.
  • Click ‘Next’ and Ad-Aware SE will scan your hard drive(s) with the options you have selected and clean automatically.
  • If Ad-Aware SE finds bad entries, you will receive a list of what it found in the window, click "Next".
  • The bad files will be listed, right click the pane and click "Select all objects" - this will put a check mark in the box at the side, click "Next" again and click "OK" at the prompt "# objects will be removed. Continue?".
  • Save the logfile when asked.
  • REBOOT to complete the removal of what Ad-Aware SE found.

Step 6
Reboot normally and scan with HijackThis. Post the new log as a reply to this thread. Include the Ewido results.txt.
Please let us know of any complications you had and how the computer is behaving.
To get Spybot and Adaware updates i Had to boot up normally vs Safe.

Step 5 was not done in Safe Mode.

I moved from to HJT file.

When rebooting a window - End Program - ccApp - appears for several seconds at pc shuts down.

I do not know how to end and send these messages, I mean new posts, but you seemed to have
received at least one with my log appended. Now I am at a loss as to how to "send" this.

Again, thanks, thanks, thanks for your assistance and the time taken to look at my problem(s).

Randy

HJT:

Logfile of HijackThis v1.97.7
Scan saved at 10:57:03 AM, on 11/1/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Intuit\QAgent\QAGENT.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Samsung\Digimax Viewer 2.0\STImgBrowser.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Messenger\msmsgs.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.provide.net/
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\Intuit\QAgent\QAGENT.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Start PostSmile (HKLM)
O9 - Extra 'Tools' menuitem: Start PostSmile (HKLM)
O9 - Extra button: Yahoo! Login (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Login (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O15 - Trusted Zone: http://V4.Windowsupdate.microsft.com
O15 - Trusted Zone: http://Windowsupdate.micrsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - https://quickplace01.geextranet.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) - http://download.yahoo.com/dl/installs/ymail/ymmapi.dll
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://download.yahoo.com/dl/installs/yab_af.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F31B9DB5-982E-4AB8-B336-C2CE48DDF39D}: NameServer = 151.164.1.8,206.13.28.12

Log from Ewido:

———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 9:55:54 AM, 11/1/2005
+ Report-Checksum: 98C8C01F

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{BEB133E5-FD72-43b7-8AFF-681831CC72D9} -> Spyware.Hijacker.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{DB767162-0D30-4181-9ED6-8019F6452FFF} -> Dialer.Generic : Cleaned with backup
HKLM\SOFTWARE\Classes\ngsw31.clsIS\Clsid\\ -> Spyware.ESD : Cleaned with backup
HKLM\SOFTWARE\saap -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-2060844374-244029631-3471578459-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-2060844374-244029631-3471578459-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{E9147A0A-A866-4214-B47C-DA821891240F} -> Spyware.ESD : Cleaned with backup
HKU\S-1-5-21-2060844374-244029631-3471578459-1005\Software\saap -> Spyware.180Solutions : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\default.8gi\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\default.8gi\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\default.8gi\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.85:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.86:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.104:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.105:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.106:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.115:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.129:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.130:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.131:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.132:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.136:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.149:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.150:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.151:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.159:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.162:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.163:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.164:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.165:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.175:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.184:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.185:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.186:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.205:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.206:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.207:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.208:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.209:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.292:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.293:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.298:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.311:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.312:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.314:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.316:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.320:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.321:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.322:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.323:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.325:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.326:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.329:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.330:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.331:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.332:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.333:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.336:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.337:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.339:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.347:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.348:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.386:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.388:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.389:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.393:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.399:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.401:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.403:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Revenue : Cleaned with backup
:mozilla.417:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Sexcounter : Cleaned with backup
:mozilla.450:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.451:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.452:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.453:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.454:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.455:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.457:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.472:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.485:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.525:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.526:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.527:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.532:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Burstbeacon : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Burstnet : Cleaned with backup
:mozilla.546:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Esomniture : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.571:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.572:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.576:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.577:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.612:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Adjuggler : Cleaned with backup
:mozilla.618:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.627:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.655:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.656:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.670:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.671:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Pro-market : Cleaned with backup
:mozilla.672:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.673:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.674:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.675:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.676:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.690:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.750:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.751:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.766:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.768:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.788:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.790:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.792:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
:mozilla.807:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.808:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.809:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.810:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Onestat : Cleaned with backup
:mozilla.842:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.844:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.845:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.899:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.900:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.918:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.919:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.922:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.923:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.924:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.932:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Paycounter : Cleaned with backup
:mozilla.990:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\Default User\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\default.lwp\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\default.lwp\cookies.txt -> Spyware.Cookie.Sextracker : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\default.lwp\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Randall Rumpf\Application Data\Mozilla\Firefox\Profiles\default.lwp\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26
Ewido found mostly just cookies. Your last HijackThis log was posted using the old version again. Please delete that version and post a new log using HijackThis v1.99.1.

Ewido found mostly just cookies.

Your last HijackThis log was posted using the old version again. Please delete that version and post a new log using HijackThis v1.99.1.


I had v1.99.1 with which following was created (had to delete the former ver.).
Hope this works and thanks for the patience needed to try to help me.

Randy

Logfile of HijackThis v1.99.1
Scan saved at 10:29:24 AM, on 11/2/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Intuit\QAgent\QAGENT.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\system32\mrtMngr.EXE
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Iomega\AutoDisk\ADService.exe
C:\Program Files\Samsung\Digimax Viewer 2.0\STImgBrowser.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\QUICKENW\QWDLLS.EXE
C:\Program Files\TrueAssistant\TrueAssistant.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://smbusiness.dellnet.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://yahoo.sbc.com/dsl
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.provide.net/
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Common\ycomp5_1_6_0.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Deskup] C:\Program Files\Iomega\DriveIcons\deskup.exe /IMGSTART
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [ADUserMon] C:\Program Files\Iomega\AutoDisk\ADUserMon.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QAGENT] C:\Program Files\Intuit\QAgent\QAGENT.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: TrueAssistant.lnk = C:\Program Files\TrueAssistant\TrueAssistant.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Digimax Viewer 2.0.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra 'Tools' menuitem: Start PostSmile - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\PostSmile\postsmile.exe
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://V4.Windowsupdate.microsft.com
O15 - Trusted Zone: http://Windowsupdate.micrsoft.com
O15 - Trusted Zone: http://Download.Windowsupdate.com
O16 - DPF: symsupportutil - https://www-secure.symantec.com/techsupp/ac…supportutil.CAB
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} (QuickPlace Class) - https://quickplace01.geextranet.com/qp2.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {231B1C6E-F934-42A2-92B6-C2FEFEC24276} (yucsetreg Class) - C:\Program Files\Yahoo!\common\yucconfig.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D18F962A-3722-4B59-B08D-28BB9EB2281E} (PhotosCtrl Class) - http://photos.yahoo.com/ocx/us/yexplorer1_9us.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312
O16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{F31B9DB5-982E-4AB8-B336-C2CE48DDF39D}: NameServer = 151.164.1.8,206.13.28.12
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE
O23 - Service: Iomega Active Disk (_IOMEGA_ACTIVE_DISK_SERVICE_) - Iomega Corporation - C:\Program Files\Iomega\AutoDisk\ADService.exe
Your new log appears clean. :)

Reset and Re-enable your System Restore to remove bad files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected.)

1. Right-click My Computer, and then click Properties.
2. On the System Restore tab, put a check mark in the 'Turn Off System Restore' check box.
3. Click OK, and then click Yes.
4. Restart the computer.
5. Repeat steps 1 - 2, this time clearing the box beside 'Turn Off System Restore', click 'OK'.


You are using an older version of Sun Java on your computer. I recommend downloading and installing the newest version from here.


I suggest that you download these programs to help keep the computer clean:

Spyware Blaster - Blocks bad ActiveX items from installing on your computer. Spyware Blaster runs silently in the background.
ie-spyad - Puts over 12,000 bad URLs into your restricted sites for Internet Explorer.
Google Toolbar - Blocks many unwanted pop-ups in Internet Explorer.
Firefox - 'Safer' alternative to the Internet Explorer web browser.

Update these regularly.

You may also want to read the following posts to learn how to better secure your computer.
"So how did I get infected in the first place"
"Securing Your PC After An Attack"

Be sure to keep Windows and your Anti-virus updated.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI