Siggyx,
Thanks for your help!
Ewido found 48 problems! We DID NOT remove any of them since it was not in your instructions.
The problems found were a number of TrachingCookies.xxx where xxx is:
Casalemedia, Bursbeacon, Burstnet, Tacoda, Statcounter, Clickbank, Googleadservices,
com, Aavalue, Yadro, and Liveperson.
In addition it found a High Threat of popcaploader.dll
Here is the Ewido Report
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 10:37:18 PM, 4/24/2006
+ Report-Checksum: 3DC50058
+ Scan result:
:mozilla.21:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Trafic : Ignored
:mozilla.24:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored
:mozilla.25:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored
:mozilla.26:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored
:mozilla.27:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored
:mozilla.28:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored
:mozilla.29:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored
:mozilla.30:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored
:mozilla.31:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored
:mozilla.33:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignored
:mozilla.34:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Burstnet : Ignored
:mozilla.35:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Tacoda : Ignored
:mozilla.36:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Burstnet : Ignored
:mozilla.37:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Tacoda : Ignored
:mozilla.38:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Tacoda : Ignored
:mozilla.39:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Tacoda : Ignored
:mozilla.41:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Statcounter : Ignored
:mozilla.42:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Statcounter : Ignored
:mozilla.43:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Clickbank : Ignored
:mozilla.44:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored
:mozilla.50:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Com : Ignored
:mozilla.62:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored
:mozilla.76:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored
:mozilla.88:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored
:mozilla.103:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Liveperson : Ignored
:mozilla.104:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Liveperson : Ignored
:mozilla.105:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Liveperson : Ignored
:mozilla.107:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored
:mozilla.121:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Liveperson : Ignored
:mozilla.122:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Liveperson : Ignored
:mozilla.139:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.140:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.141:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.142:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.143:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.144:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.145:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.146:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Aavalue : Ignored
:mozilla.205:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yadro : Ignored
:mozilla.206:C:\Documents and Settings\Barb\Application Data\Mozilla\Firefox\Profiles\jp7amaih.default\cookies.txt -> TrackingCookie.Yadro : Ignored
C:\Documents and Settings\Barb\Cookies\barb@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored
C:\Documents and Settings\Barb\Cookies\barb@burstnet[2].txt -> TrackingCookie.Burstnet : Ignored
C:\Documents and Settings\Barb\Cookies\barb@com[1].txt -> TrackingCookie.Com : Ignored
C:\Documents and Settings\Barb\Cookies\barb@tacoda[2].txt -> TrackingCookie.Tacoda : Ignored
C:\Documents and Settings\Barb\Cookies\barb@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Ignored
C:\Documents and Settings\Barb\Cookies\barb@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Ignored
C:\Documents and Settings\MAINTENANCE\Cookies\maintenance@com[1].txt -> TrackingCookie.Com : Ignored
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Ignored
::Report End
-------------------------------------------------------------
-------------------------------------------------------------
Here is the HJT Report
Logfile of HijackThis v1.99.1
Scan saved at 10:44:20 PM, on 4/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\WINDOWS\system32\USRSTA.EXE
C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [USRSTA.EXE] USRSTA.EXE START
O4 - HKLM\..\Run: [WinPatrol] "C:\PROGRA~1\BILLPS~1\WINPAT~1\WinPatrol.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1129398134564
O16 - DPF: {8EDAD21C-3584-4E66-A8AB-EB0E5584767D} -
http://toolbar.googl...gleActivate.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://www.popcap.co...aploader_v6.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{2167FF87-B679-40E6-9BB6-E92161B815C5}: NameServer = 68.6.16.30,68.6.16.25
O17 - HKLM\System\CCS\Services\Tcpip\..\{91126EA4-322E-4C96-9381-73469498FFE2}: NameServer = 68.2.16.30,68.2.16.25
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
----------------------------------------------------------------------
----------------------------------------------------------------------
Thanks,
Harriet567