This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ready to erase the whole thing

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello and welcome at TomCoyoteforum, Sorry for the delay in responding, it's been pretty busy here and not all logs get answered as quickly as we'd like. If you still need help with your problem, please reply to this message with a new HijackThis log. I will be notified automatically when you reply.
THANKS!! :D I appreciate the persistence you folks continue to show.

Here is the latest log file….


Logfile of HijackThis v1.99.1
Scan saved at 1:29:56 PM, on 2/10/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9ZA.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe
C:\Program Files\InterMute\SpySubtract\SpySub.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Palm\HOTSYNC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Documents and Settings\Mike Kenney\Desktop\HJT\HIJACKTH.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NewzCrawlerRSSAutodiscovery2 Object - {5F50A50A-0A0F-4F58-8B1C-62BC60F9B05A} - C:\PROGRA~1\NEWZCR~1\NCRSSA~1.DLL
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [EPSON PictureMate 2005] C:\WINNT\system32\spool\DRIVERS\W32X86\3\E_FATI9ZA.EXE /P22 "EPSON PictureMate 2005" /O6 "USB002" /M "PictureMate 2005"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\SymProbe.exe -r "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\InterMute\SpySubtract\SpySub.exe
O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Subscribe in NewzCrawler - file://C:\Program Files\NewzCrawler\context.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://getdway.com/dwayready/dpcsysinfo.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2822.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



The machine is running very slow. One other item of concern, MS Outlook frequently stays resident when I quit. Don't know if it means anything.

I will await your reply.

Mike

persistence


Thats the real tool in the fight against malware ;)

Your logs seems clean, but as HJT does not always shows everything I suggest you do the following:


Download the trial version of Ewido Security Suite.
Install it, and update the definitions to the newest files. Do NOT run a scan yet.

To clean temporary files:
Go > start > run and type cleanmgr and click OK
Scan your system for files to remove.
Make sure Temporary Files, Temporary Internet Files and Recycle Bin are the only things checked.
Click OK to remove those files.
Click Yes to confirm deletion.

Safe mode for XP
Next, reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8 (or F5).
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Now scan with Ewido. Click on the Scanner button in the left menu, then click on Complete System Scan. This scan can take quite a while to run.
When the scan finishes, click on "Save Report". This will create a text file. Make sure you know where to find this file again.

Reboot the computer in normal mode and post back here with the Ewido scan log.
Thanks for the advice….here is the report. Let me know what you think. Mike ——————————————————— ewido anti-malware - Scan report ——————————————————— + Created on: 7:15:16 PM, 2/10/2006 + Report-Checksum: 73E72B5E + Scan result: HKLM\SOFTWARE\Classes\Applications\STC.exe -> Adware.SecondThought : Cleaned with backup HKLM\SOFTWARE\Classes\Applications\STC.exe\shell -> Adware.SecondThought : Cleaned with backup HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup HKLM\SOFTWARE\SecureWin -> Adware.Adlogix : Cleaned with backup HKU\S-1-5-21-73586283-436374069-1060284298-1000\Software\Bundles -> Adware.SecondThought : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Specificclick : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@com[2].txt -> TrackingCookie.Com : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@cnn.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][3].txt -> TrackingCookie.Specificclick : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed]-banners[1].txt -> TrackingCookie.Top-banners : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@adtrak[1].txt -> TrackingCookie.Adtrak : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Enhance : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Burstnet : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@microsofteup.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@buildabear.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@marykay.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Adbutler : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][3].txt -> TrackingCookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@marykay.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@burstnet[4].txt -> TrackingCookie.Burstnet : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@microsofteup.112.2o7[3].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed]-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@msnportal.112.2o7[3].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@webstat[3].txt -> TrackingCookie.Web-stat : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Euroclick : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][4].txt -> TrackingCookie.Burstbeacon : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Overture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@gateway.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@greatschools.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Overture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Overture : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@adtech[2].txt -> TrackingCookie.Adtech : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Pointroll : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike kenney@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup C:\Documents and Settings\Mike Kenney\Cookies\mike [removed][1].txt -> TrackingCookie.Addynamix : Cleaned with backup :mozilla.12:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.13:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.14:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.15:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.16:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.17:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.18:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.19:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.20:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.21:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.22:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.23:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.24:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.25:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.26:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.27:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.28:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.29:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.30:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.31:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.32:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.33:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.34:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.35:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.36:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.37:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.40:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.41:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.47:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.48:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.49:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.50:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.51:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.52:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.53:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.54:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.55:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.56:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.57:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.58:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.59:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.60:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.61:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.62:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup :mozilla.65:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned with backup :mozilla.72:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.73:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup :mozilla.74:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.75:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.76:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.77:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup :mozilla.93:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.94:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.95:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup :mozilla.122:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.123:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup :mozilla.127:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.128:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup :mozilla.141:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.142:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup :mozilla.146:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup :mozilla.150:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.151:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.152:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.153:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup :mozilla.154:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.155:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup :mozilla.163:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.164:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup :mozilla.190:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.192:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.193:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.194:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.195:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.196:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.197:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.198:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup :mozilla.228:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.229:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.230:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.231:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.232:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.233:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup :mozilla.249:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup :mozilla.256:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.257:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.258:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.259:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.260:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.261:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup :mozilla.267:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.268:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup :mozilla.269:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.270:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup :mozilla.274:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup :mozilla.279:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.280:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup :mozilla.281:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup :mozilla.292:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup :mozilla.304:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.316:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.317:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.318:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.319:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.320:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.321:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.322:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup :mozilla.338:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.347:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.348:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.349:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.350:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.351:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.352:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup :mozilla.370:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup :mozilla.375:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.376:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup :mozilla.382:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.398:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.399:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.400:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.401:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.415:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.417:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.418:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.419:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.420:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup :mozilla.421:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.422:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.423:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.424:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup :mozilla.436:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.437:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.438:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup :mozilla.457:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.458:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.459:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.460:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.461:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.462:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup :mozilla.466:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.481:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup :mozilla.482:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.483:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.484:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.485:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup :mozilla.518:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.519:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.520:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.521:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.522:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.523:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup :mozilla.524:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup :mozilla.536:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.537:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.539:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup :mozilla.540:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup :mozilla.577:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.578:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup :mozilla.580:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.583:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.644:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.645:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.646:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.647:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.648:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.649:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.653:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.654:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.655:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.656:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup :mozilla.681:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.682:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.686:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.687:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.688:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.689:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.693:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup :mozilla.708:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.714:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.722:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup :mozilla.723:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.735:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup :mozilla.751:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.752:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.763:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.764:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.767:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.768:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.769:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup :mozilla.775:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.776:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup :mozilla.796:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.797:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.798:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.799:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.800:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup :mozilla.803:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup :mozilla.814:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup :mozilla.837:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup :mozilla.838:C:\Documents and Settings\Mike Kenney\Application Data\Mozilla\Firefox\Profiles\vy1a2lp0.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup ::Report End
Looks fine :)

Download Ccleaner Install it to your desktop, but do NOT run it yet.

Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)

1. Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.

2. Reboot.

3. Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.


Next run CCleaner
1. Open CCleaner.
2. Place a check by everything in the Applications tab.
3. Place a check by Internet Explorer, Windows explorer, and System in the Windows tab (take care that Windows logfiles is unchecked).
4. Hit the button that says Run CCleaner
5. Reboot to remove index.dat files.
Okay….I had to handle some other issues but I am back. I am running win2000 so did not have the system restore capability. I did download and run CCleaner. Shall I run another HJT log? Mike
Thanks for the reply.

The computer is running better. There are still times when it drags though. I may need to eliminate some extra files and add additional RAM. I may be to the point where there is just too much on the machine.

I also have another problem that raises its head regularly. Outlook will often stay resident after I quit. My concern is could that ne some program using my Outlook to send emails.

Here is the HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 7:08:26 AM, on 2/18/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jucheck.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Palm\HOTSYNC.EXE
C:\WINNT\system32\svchost.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Documents and Settings\Mike Kenney\Desktop\HJT\HIJACKTH.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NewzCrawlerRSSAutodiscovery2 Object - {5F50A50A-0A0F-4F58-8B1C-62BC60F9B05A} - C:\PROGRA~1\NEWZCR~1\NCRSSA~1.DLL
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\SymProbe.exe -r "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Subscribe in NewzCrawler - file://C:\Program Files\NewzCrawler\context.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://getdway.com/dwayready/dpcsysinfo.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2822.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


Mike
You also can defrag the system. It is important to shut down applications such as a screensaver or antivirusprogram during the defrag. For instance you can defraf in safe mode:

Reboot your pc into safe mode for all OS

Here is a link that shows the way to a Proper Defrag

Click start > all program’s > accessoires > systeemworkset. Choose diskcleaning first and then defrag.

Reboot the computer.


If you are concerned about hidden trojans you can follow this advice:

Download and Save blacklight to your desktop.
F-Secure Blacklight
Double-click blbeta.exe click: I accept the agreement.
Click > scan then > next,
You'll see a list of all items found.
Don't choose for rename yet! I want to see the log first, because legit items can also be present there…
There must be also a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
Post the contents of the log in your next reply.


Besides there is this thorough scanner….


Please download mwav.exe MicroWorld - Free AntiVirus standalone scanner
to that new folder.
Double-click mwav.exe which will start run mwavscan.com > select all local drives > scan all files > press 'scan' and when it is completed, anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply. (except for the "refers to invalid object“-notifications, you do not have to copy them) This tool will only report and not fix anything, but is thorough.
Since the log is so large, we only need to see the lines with "action taken" in them, so copy/paste those into the reply.
Okay…It has been a few days but here is what I've got….


F-Secure Blacklight did not find anything…here is the log:

02/28/06 17:29:05 [Info]: BlackLight Engine 1.0.33 initialized
02/28/06 17:29:05 [Info]: OS: 5.0 build 2195 (Service Pack 4)
02/28/06 17:29:05 [Note]: 7019 4
02/28/06 17:29:05 [Note]: 7005 0
02/28/06 17:29:14 [Note]: 7006 0
02/28/06 17:29:16 [Note]: 7011 1004
02/28/06 17:29:17 [Note]: FSRAW library version 1.7.1015
02/28/06 17:29:50 [Note]: 7007 0


Microworld found two virus infected files….here is the log entries:

File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\66FF72DF infected by "Trojan-Downloader.Win32.Small.abd" Virus! Action Taken: No Action Taken.
File C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\194B2186 infected by "Trojan-Downloader.Win32.Adload.a" Virus! Action Taken: No Action Taken.


I also ran another HJT log….here it is:

Logfile of HijackThis v1.99.1
Scan saved at 8:16:36 PM, on 2/28/2006
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\mspmspsv.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\j2re1.4.2_07\bin\jucheck.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Palm\HOTSYNC.EXE
C:\WINNT\system32\wuauclt.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\DOCUME~1\MIKEKE~1\LOCALS~1\Temp\mwavscan.com
C:\DOCUME~1\MIKEKE~1\LOCALS~1\Temp\kavss.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\MICROS~2\Office\OUTLOOK.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\system32\NOTEPAD.EXE
C:\Documents and Settings\Mike Kenney\Desktop\HJT\HIJACKTH.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.msn.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NewzCrawlerRSSAutodiscovery2 Object - {5F50A50A-0A0F-4F58-8B1C-62BC60F9B05A} - C:\PROGRA~1\NEWZCR~1\NCRSSA~1.DLL
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb03.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_07\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SSC_UserPrompt] "C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] C:\Program Files\Common Files\Symantec Shared\SymProbe.exe -r "C:\Program Files\Norton AntiVirus\CfgWiz.exe" /GUID {0D7956A2-5A08-4ec2-A72C-DF8495A66016} /MODE CfgWiz /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Subscribe in NewzCrawler - file://C:\Program Files\NewzCrawler\context.htm
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O9 - Extra 'Tools' menuitem: Newz Crawler - {CA7C41C8-5C9D-4A03-A101-B0AA4F0C3ABC} - C:\Program Files\NewzCrawler\News.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835
O16 - DPF: {76D90D08-EAB7-46D8-BF99-87445BF59E72} (SystemInfo Class) - http://getdway.com/dwayready/dpcsysinfo.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://mycampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - https://a248.e.akamai.net/f/248/5462/2h/www…ol/SymDlBrg.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab34246.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2822.cab
O16 - DPF: {FA9740A2-5802-42E2-B509-81186EEB3C42} (WABControl Class) - https://www.linkedin.com/cab/wabctrl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS1\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O17 - HKLM\System\CS2\Services\Tcpip\..\{162302B7-E486-4E25-919A-757866A9FCF8}: NameServer = 166.102.165.13,166.102.165.11
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SPBBCSvc - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe



Let me know what you think.

Thanks, Mike
Here are some tips, please follow these simple steps in order to keep your computer clean and secure:
  • Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.

    A tutorial on installing & using this product can be found here:

    Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI