This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help the laptop keeps restarting when I try to get on the internet

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Please do not delete anything unless instructed to.

Go to start > run and copy and paste next commands in the field:

sc delete lsass Hit enter



Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe

O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe


O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)

Close ALL windows and browsers except HijackThis and click "Fix checked"




Delete these Files if listed:
C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe

Delete this Folder if listed:
C:\windows\System32\_zskwrkni04



Empty Recycle Bin

Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I also forgot to mention that I can't install updates for windows.

Logfile of HijackThis v1.99.1
Scan saved at 16:35:04, on 2006-07-24
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\windows\Explorer.EXE
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\toshiba\ivp\ism\pinger.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\ctfmon.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\Program Files\GetRight\getright.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Foxie Suite\Firewall.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\New Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan along with a new HijackThis log.
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:16:30 2006-07-27

+ Scan result:



C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{32619CD5-8216-436F-AF23-1F75F1884532} -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{5C03E65B-EA9F-4C47-A6AC-0BC6D10578D3}/clientax.dll -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{762C3A6F-CE14-42B3-9E42-08C592A58BB5} -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{79BC4238-4B6B-4355-B556-353999DFA827} -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{CC90A134-A2D8-49EF-B8F6-D45EB1F6AC76} -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{FCB2A19E-9AA6-4DFB-B33B-91A69EBCAC21}/clientax.dll -> Adware.180Solutions : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{2049CC9B-7FDA-4C33-9F74-61D8C9A87632} -> Adware.Adstart : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{BFA25C29-588F-49C3-8A02-95FCC21908CF} -> Adware.Adstart : No action taken.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{011B7C5D-D7BD-4D9C-810A-551B518AB014} -> Adware.CommAd : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{8273E492-302A-4A01-9632-0FCEE8295382} -> Adware.DealHelper : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{BC865305-1F63-4924-853A-232189000B11} -> Adware.DealHelper : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\20050705110202.zip/Program Files/common files/uninstall information/RemoveDisplayUtility.exe -> Adware.DelphinMediaViewer : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{06B0338B-1591-4C22-B1BB-EB1E20440E31} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{0BC78448-5309-4BFA-857C-89A3CF5E9F30} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{1CC2184A-189E-4088-BA1E-6753AD8F1757} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{22A66607-F800-459A-9FE1-65980160CF30} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{236B5594-A404-4F04-BFDB-FE353C70E2FC} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{30C57790-AF4B-46D6-9716-C9DE45AA9DEA} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{35396D32-617A-48B7-83E7-B2F8056EC081} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{36A207B3-0C44-4F28-A316-26BFAD5FD0AE} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{450C563D-BF74-46FC-B745-B1E7D34463BF} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{50C136B2-D697-4DCB-BAB6-04031FD98B95} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{51803ADA-94B0-439B-B72A-BD132C73686C} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{55E6863C-6872-4211-BDB0-CF6C416948FA} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{5ABFADB4-D7B0-412B-93E4-AC2DA3FE9F84} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{7A062DFE-BF74-407C-8A1A-E9F904003088} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{9BC3EED2-ABD6-44E3-B37F-DC9DFDFFE639} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{A1ECD0E3-60CD-48E6-9BF5-5A80B6D86170} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{A342F732-9087-4B54-9117-4E6DD1D789F2} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{A9CFB272-C0BD-4778-BEDC-4117F6F819E1} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{AF2A26FF-F7C6-4E79-90BD-0134C50976E5} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{CE457991-BBC8-4CE1-84AD-7B195588007B} -> Adware.Look2Me : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{FF27C656-E6D8-4DC2-BBEA-A3B76F65A612} -> Adware.Look2Me : No action taken.
C:\Program Files\Windows Media Player\wmplayer.exe.tmp -> Adware.Pacer : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{4526C407-EA06-4941-BC25-DF39F696625C} -> Adware.SurfSide : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{C06C2025-0466-4BB3-ABA0-BAD00996702A} -> Adware.SurfSide : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{4A0C9343-6A22-4111-A744-5A37E57F3672} -> Adware.WinAD : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{61629789-3F4C-4EB8-A969-170F137020A3} -> Adware.WinAD : No action taken.
C:\WINDOWS\system32\TFTP5632 -> Backdoor.Rbot.sp : No action taken.
C:\!Submit\fdhbe_76748.exe -> Backdoor.SdBot.acr : No action taken.
C:\!Submit\eraseme_73048.exe -> Backdoor.SdBot.xd : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{67E795BE-AB93-4483-A334-718F4123D6EE} -> Downloader.Agent.qg : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{3567A2A9-4086-4EE2-95CD-8F97D0EEF53B} -> Downloader.PurityScan.af : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{EB4BFEBD-FD19-447D-8661-574BAF0ACB95} -> Downloader.PurityScan.an : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{5243A592-A941-44BB-98C0-303EAA11EEA9} -> Downloader.Small.asf : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{5FE87145-F466-4309-ACB6-036957692248} -> Downloader.Small.asf : No action taken.
C:\!Submit\qynbdil.exe -> Downloader.Small.chk : No action taken.
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine\Quarantine - 08-31-2005 - 04-21-27.SBU/{0D2D5537-5A2D-48F3-AC2A-C4D50657EE08} -> Dropper.Agent.pb : No action taken.
:mozilla.12:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\j8u4b1ij.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Ryan\Cookies\ryan@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B.tmp -> TrackingCookie.2o7 : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqFB.tmp -> TrackingCookie.2o7 : No action taken.
:mozilla.148:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.149:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.150:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.151:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.79:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.92:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.93:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.94:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.95:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.88:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.89:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.22:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.23:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.24:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.25:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.27:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.70:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.74:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.75:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.77:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.78:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.139:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.140:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.141:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.142:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.28:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.33:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.34:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.35:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.36:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.37:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28.tmp -> TrackingCookie.Casalemedia : No action taken.
:mozilla.8:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\j8u4b1ij.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.99:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.9:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\j8u4b1ij.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq29.tmp -> TrackingCookie.Com : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8D.tmp -> TrackingCookie.Com : No action taken.
:mozilla.10:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\j8u4b1ij.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.6:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqFC.tmp -> TrackingCookie.Doubleclick : No action taken.
:mozilla.272:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.273:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.274:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.275:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.120:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.121:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.122:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.123:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.68:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.69:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.71:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.73:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.80:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.68:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.69:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp -> TrackingCookie.Hypertracker : No action taken.
:mozilla.73:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq90.tmp -> TrackingCookie.Mediaplex : No action taken.
:mozilla.367:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.368:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.369:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Onestat : No action taken.
:mozilla.19:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.20:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.21:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Ryan\Cookies\ryan@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq91.tmp -> TrackingCookie.Questionmarket : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq92.tmp -> TrackingCookie.Realtracker : No action taken.
:mozilla.147:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2D.tmp -> TrackingCookie.Revenue : No action taken.
:mozilla.143:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.144:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.145:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.146:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.40:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.41:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.42:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.43:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.44:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.187:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.67:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.72:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.76:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.79:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.81:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.87:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.40:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.41:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.42:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.43:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.44:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.45:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.46:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.47:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.48:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.60:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.61:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.62:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.29:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.30:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.31:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.32:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.33:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.34:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.35:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.36:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.37:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.38:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.38:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.39:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.39:C:\Documents and Settings\Sheila\Application Data\Mozilla\Firefox\Profiles\d5gdqsw2.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.93:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.94:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.95:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.96:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.97:C:\Documents and Settings\Ryan\Application Data\Mozilla\Firefox\Profiles\4ctx3z2b.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\!Submit\ptamgum.exe -> Trojan.Spambot : No action taken.
C:\ejnn3.exe -> Trojan.Spambot : No action taken.


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 11:35:08, on 2006-07-27
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\windows\Explorer.EXE
C:\windows\System32\ctfmon.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\TOSHIBA\Ivp\netint\netint.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\windows\system32\NOTEPAD.EXE
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\New Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Can you see any folders starting with C:\windows\System32\_zsk
C:\windows\System32\_zskwrkni04

If so, try and delete all folders starting with _zsk

Clean out the Quarantine items in Super Ad Blocker
C:\Program Files\SuperAdBlocker.com\Super Ad Blocker\Quarantine

Delete this File if listed:
C:\WINDOWS\system32\TFTP5632




Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
I could not find any of the files in the system32 folder that you asked me to delete.


Logfile of HijackThis v1.99.1
Scan saved at 17:00:10, on 2006-07-28
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\windows\System32\smss.exe
C:\windows\system32\csrss.exe
C:\windows\system32\winlogon.exe
C:\windows\system32\services.exe
C:\windows\system32\lsass.exe
C:\windows\system32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\windows\System32\svchost.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\windows\System32\nvsvc32.exe
C:\windows\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\windows\System32\WgaTray.exe
C:\windows\Explorer.EXE
C:\windows\System32\ctfmon.exe
C:\Program Files\EzButton\CplBTQ00.EXE
C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Toshiba Controls\CpRmtKey.EXE
C:\Program Files\TOSHIBA\Power Management\CePMTray.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Program Files\TOSHIBA\TouchPad\TPTray.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MessengerPlus! 3\MsgPlus.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Messenger\msmsgs.exe
C:\windows\System32\wuauclt.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe
C:\PROGRA~1\GoGoData.com\GOGODA~1\ADBUST~1.EXE
C:\Program Files\GetRight\getright.exe
C:\WINDOWS\system32\RAMASST.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\GetRight\getright.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\toshiba\ivp\ism\ivpsvmgr.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\New Folder\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: bho2gr Class - {31FF080D-12A3-439A-A2EF-4BA95A3148E8} - C:\Program Files\GetRight\xx2gr.dll
O2 - BHO: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Foxie - {09C02180-3B46-4CD8-83FF-34DAF442BDEF} - C:\Program Files\Foxie Suite\foxiecoreu.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: GoGoData AdBuster - {3EB9C349-7473-48AC-A59B-42F31751974B} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\windows\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] "nwiz.exe" /install
O4 - HKLM\..\Run: [CplBTQ00] "C:\Program Files\EzButton\CplBTQ00.EXE"
O4 - HKLM\..\Run: [CeEKEY] "C:\Program Files\TOSHIBA\E-KEY\CeEKey.exe"
O4 - HKLM\..\Run: [LtMoh] "C:\Program Files\ltmoh\Ltmoh.exe"
O4 - HKLM\..\Run: [CpRmtKey] "C:\Program Files\Toshiba Controls\CpRmtKey.EXE"
O4 - HKLM\..\Run: [CeEPOWER] "C:\Program Files\TOSHIBA\Power Management\CePMTray.exe"
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TPNF] "C:\Program Files\TOSHIBA\TouchPad\TPTray.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Pinger] "c:\toshiba\ivp\ism\pinger.exe" /run
O4 - HKLM\..\Run: [RealTray] "C:\Program Files\Real\RealPlayer\RealPlay.exe" SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] "C:\PROGRA~1\SYMNET~1\SNDMon.exe" /Consumer
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] "C:\Program Files\Logitech\Video\ISStart.exe"
O4 - HKLM\..\Run: [LogitechVideoTray] "C:\Program Files\Logitech\Video\LogiTray.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\windows\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKLM\..\Run: [SpyCatcher Reminder] "C:\Program Files\SpyCatcher 2006\SpyCatcher.exe" reminder
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\RunServices: [ÿ_zskFSD_RQARX] C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
O4 - HKLM\..\RunServices: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\windows\System32\ctfmon.exe
O4 - HKCU\..\Run: [GoogleAdBGone] C:\Program Files\GoogleAdBGone\GoogleAdBGone.exe
O4 - HKCU\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" /WinStart
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe" -quiet
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [ÿ_zsk]ifzq`iesm`i_vmt40inkrwksz_] c:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe
O4 - HKCU\..\Run: [GoGoTray.exe] "C:\Program Files\GoGoData.com\GoGoData Toolbar\GoGoTray.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Program Files\GetRight\getright.exe
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O4 - Global Startup: SpyCatcher Protector.lnk = C:\Program Files\SpyCatcher 2006\Protector.exe
O9 - Extra button: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra 'Tools' menuitem: Desktop Search - {306BBB66-D9E4-4481-833E-C1D5FCA06774} - C:\Program Files\Foxie Suite\Resources\HTML\Desktop.htm
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll
O9 - Extra button: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra 'Tools' menuitem: Privacy Cleaner - {546E08AA-809F-4F1A-BE1A-6B122EBFCD5A} - C:\Program Files\Foxie Suite\Cleaner.exe
O9 - Extra button: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra 'Tools' menuitem: Swift Sweeper - {61039B22-563D-4922-B844-B076C318A66A} - C:\Program Files\Foxie Suite\Sweeper.exe
O9 - Extra button: (no name) - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra 'Tools' menuitem: GoGoData AdBuster - {7B6E4BB4-8464-47CF-9A5B-F82F6B408A6E} - C:\PROGRA~1\GoGoData.com\GOGODA~1\TOMAHA~1.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra 'Tools' menuitem: The Infinity Button - {E4143585-2688-4EBC-B264-27C774F600D5} - C:\Program Files\Foxie Suite\Resources\HTML\Infinity.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshiba.com
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1138189251421
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} (ZoneAxRcMgr Class) - http://messenger.zone.msn.com/binary/ZAxRcMgr.cab
O16 - DPF: {A2E05F45-F127-4092-B9F7-9A02C3E04C77} (HGPlugin7USA Class) - http://gamedownload.ijjimax.com/gamedownlo…GPlugin7USA.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit…wn.cab31267.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: interceptor.dll
O20 - Winlogon Notify: WgaLogon - C:\windows\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\windows\SYSTEM32\WRLogonNTF.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\windows\dcmhelp.exe (file missing)
O23 - Service: DiamondCS Process Guard Service v3.000 (DCSPGSRV) - Unknown owner - C:\Program Files\ProcessGuard\dcsuserprot.exe (file missing)
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\System32\DVDRAMSV.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\windows\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\windows\System32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\windows\System32\HPHipm09.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
You need To disable SpySweeper:it can stop our fix.

Open it click >Options over to the left then >program options >Uncheck "load at windows startup".
Over to the left click "shields" and uncheck all there.
Uncheck "home page shield".
Uncheck 'automaticly restore default without notifiction".
_ _ _ _ _ _


Download Pocket Killbox
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Then double-click on the killbox.exe program.


Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.

Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.


When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.

C:\windows\System32\_zskwrkni04]\SM_G\XRAQR_DSF.exe
C:\windows\system32\_zskwrkni04tmv_i`msei`qzfi].exe


Return to Killbox, go to the File menu and select Paste from Clipboard.


Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually

Post a new HijackThis log
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI