This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT log..tagasaurus

47 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of HijackThis v1.99.1
Scan saved at 9:59:19 PM, on 7/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\TWF0dA\command.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\dfndred_7.exe
C:\kybrded_7.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\cfg32.exe
C:\nwnmed_7.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\zqskw.exe
C:\WINDOWS\system32\ghynf.exe
C:\Program Files\webHancer\Programs\whAgent.exe
C:\WINDOWS\pop06ap2.exe
C:\Program Files\Common Files\{B43C29F6-0958-1033-0428-030211050001}\Update.exe
C:\Program Files\PSHope\PSHope.exe
C:\Program Files\System Files\System.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\TClock\TClock.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\System32\svchost.exe
C:\DOCUMENTS AND SETTINGS\DANIEL\DESKTOP\XPProfiles-1.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\dftaa.exe
F2 - REG:system.ini: UserInit=userinit.exe,obbekhu.exe
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int408387.exe -auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [defender] C:\\dfndred_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrded_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [blld06ee] "RUNDLL32.EXE" w0035e7d.dll,n 001d06ed000000030035e7d
O4 - HKLM\..\Run: [w00386be.dll] "RUNDLL32.EXE" w00386be.dll,I2 001d06ed000386be
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinspez.exe CORN003
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmed_7.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\whAgent.exe"
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinspez.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.media-motor.net/cabs/joysavsht.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\ir6ml5j11.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0dA\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe




L2MFIX find log 051206
These are the registry keys present
**********************************************************************************
Winlogon/notify:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"Asynchronous"=dword:00000000
"DllName"=""
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\logons]
"DllName"="C:\\WINDOWS\\system32\\redist.dll"
"Logoff"="WinLogoff"
"Logon"="WinLogon"
"Shutdown"="WinShutdown"
"Asynchronous"=dword:00000001
"Impersonate"=dword:00000001

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\SideBySide]
"Asynchronous"=dword:00000000
"DllName"="C:\\WINDOWS\\system32\\ir6ml5j11.dll"
"Impersonate"=dword:00000000
"Logon"="WinLogon"
"Logoff"="WinLogoff"
"Shutdown"="WinShutdown"

**********************************************************************************
useragent:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform]
"{5E657F06-5EB5-FEFA-DE2D-9D8BF00C9BAE}"=""

**********************************************************************************
Shell Extension key:
Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{00022613-0000-0000-C000-000000000046}"="Multimedia File Property Sheet"
"{176d6597-26d3-11d1-b350-080036a75b03}"="ICM Scanner Management"
"{1F2E5C40-9550-11CE-99D2-00AA006E086C}"="NTFS Security Page"
"{3EA48300-8CF6-101B-84FB-666CCB9BCD32}"="OLE Docfile Property Page"
"{40dd6e20-7c17-11ce-a804-00aa003ca9f6}"="Shell extensions for sharing"
"{41E300E0-78B6-11ce-849B-444553540000}"="PlusPack CPL Extension"
"{42071712-76d4-11d1-8b24-00a0c9068ff3}"="Display Adapter CPL Extension"
"{42071713-76d4-11d1-8b24-00a0c9068ff3}"="Display Monitor CPL Extension"
"{42071714-76d4-11d1-8b24-00a0c9068ff3}"="Display Panning CPL Extension"
"{4E40F770-369C-11d0-8922-00A024AB2DBB}"="DS Security Page"
"{513D916F-2A8E-4F51-AEAB-0CBC76FB1AF8}"="Compatibility Page"
"{56117100-C0CD-101B-81E2-00AA004AE837}"="Shell Scrap DataHandler"
"{59099400-57FF-11CE-BD94-0020AF85B590}"="Disk Copy Extension"
"{59be4990-f85c-11ce-aff7-00aa003ca9f6}"="Shell extensions for Microsoft Windows Network objects"
"{5DB2625A-54DF-11D0-B6C4-0800091AA605}"="ICM Monitor Management"
"{675F097E-4C4D-11D0-B6C1-0800091AA605}"="ICM Printer Management"
"{764BF0E1-F219-11ce-972D-00AA00A14F56}"="Shell extensions for file compression"
"{77597368-7b15-11d0-a0c2-080036af3f03}"="Web Printer Shell Extension"
"{7988B573-EC89-11cf-9C00-00AA00A14F56}"="Disk Quota UI"
"{853FE2B1-B769-11d0-9C4E-00C04FB6C6FA}"="Encryption Context Menu"
"{85BBD920-42A0-1069-A2E4-08002B30309D}"="Briefcase"
"{88895560-9AA2-1069-930E-00AA0030EBC8}"="HyperTerminal Icon Ext"
"{BD84B380-8CA2-1069-AB1D-08000948F534}"="Fonts"
"{DBCE2480-C732-101B-BE72-BA78E9AD5B27}"="ICC Profile"
"{F37C5810-4D3F-11d0-B4BF-00AA00BBB723}"="Printers Security Page"
"{f81e9010-6ea4-11ce-a7ff-00aa003ca9f6}"="Shell extensions for sharing"
"{f92e8c40-3d33-11d2-b1aa-080036a75b03}"="Display TroubleShoot CPL Extension"
"{7444C717-39BF-11D1-8CD9-00C04FC29D45}"="Crypto PKO Extension"
"{7444C719-39BF-11D1-8CD9-00C04FC29D45}"="Crypto Sign Extension"
"{7007ACC7-3202-11D1-AAD2-00805FC1270E}"="Network Connections"
"{992CFFA0-F557-101A-88EC-00DD010CCC48}"="Network Connections"
"{E211B736-43FD-11D1-9EFB-0000F8757FCD}"="Scanners & Cameras"
"{FB0C9C8A-6C50-11D1-9F1D-0000F8757FCD}"="Scanners & Cameras"
"{905667aa-acd6-11d2-8080-00805f6596d2}"="Scanners & Cameras"
"{3F953603-1008-4f6e-A73A-04AAC7A992F1}"="Scanners & Cameras"
"{83bbcbf3-b28a-4919-a5aa-73027445d672}"="Scanners & Cameras"
"{F0152790-D56E-4445-850E-4F3117DB740C}"="Remote Sessions CPL Extension"
"{5F327514-6C5E-4d60-8F16-D07FA08A78ED}"="Auto Update Property Sheet Extension"
"{60254CA5-953B-11CF-8C96-00AA00B8708C}"="Shell extensions for Windows Script Host"
"{2206CDB2-19C1-11D1-89E0-00C04FD7A829}"="Microsoft Data Link"
"{DD2110F0-9EEF-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Icon Handler"
"{797F1E90-9EDD-11cf-8D8E-00AA0060F5BF}"="Tasks Folder Shell Extension"
"{D6277990-4C6A-11CF-8D87-00AA0060F5BF}"="Scheduled Tasks"
"{0DF44EAA-FF21-4412-828E-260A8728E7F1}"="Taskbar and Start Menu"
"{2559a1f0-21d7-11d4-bdaf-00c04f60b9f0}"="Search"
"{2559a1f1-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f2-21d7-11d4-bdaf-00c04f60b9f0}"="Help and Support"
"{2559a1f3-21d7-11d4-bdaf-00c04f60b9f0}"="Run…"
"{2559a1f4-21d7-11d4-bdaf-00c04f60b9f0}"="Internet"
"{2559a1f5-21d7-11d4-bdaf-00c04f60b9f0}"="E-mail"
"{D20EA4E1-3957-11d2-A40B-0C5020524152}"="Fonts"
"{D20EA4E1-3957-11d2-A40B-0C5020524153}"="Administrative Tools"
"{875CB1A1-0F29-45de-A1AE-CFB4950D0B78}"="Audio Media Properties Handler"
"{40C3D757-D6E4-4b49-BB41-0E5BBEA28817}"="Video Media Properties Handler"
"{E4B29F9D-D390-480b-92FD-7DDB47101D71}"="Wav Properties Handler"
"{87D62D94-71B3-4b9a-9489-5FE6850DC73E}"="Avi Properties Handler"
"{A6FD9E45-6E44-43f9-8644-08598F5A74D9}"="Midi Properties Handler"
"{c5a40261-cd64-4ccf-84cb-c394da41d590}"="Video Thumbnail Extractor"
"{5E6AB780-7743-11CF-A12B-00AA004AE837}"="Microsoft Internet Toolbar"
"{22BF0C20-6DA7-11D0-B373-00A0C9034938}"="Download Status"
"{91EA3F8B-C99B-11d0-9815-00C04FD91972}"="Augmented Shell Folder"
"{6413BA2C-B461-11d1-A18A-080036B11A03}"="Augmented Shell Folder 2"
"{F61FFEC1-754F-11d0-80CA-00AA005B4383}"="BandProxy"
"{7BA4C742-9E81-11CF-99D3-00AA004AE837}"="Microsoft BrowserBand"
"{30D02401-6A81-11d0-8274-00C04FD5AE38}"="Search Band"
"{32683183-48a0-441b-a342-7c2a440a9478}"="Media Band"
"{169A0691-8DF9-11d1-A1C4-00C04FD75D13}"="In-pane search"
"{07798131-AF23-11d1-9111-00A0C98BA67D}"="Web Search"
"{AF4F6510-F982-11d0-8595-00AA004CD6D8}"="Registry Tree Options Utility"
"{01E04581-4EEE-11d0-BFE9-00AA005B4383}"="&Address"
"{A08C11D2-A228-11d0-825B-00AA005B4383}"="Address EditBox"
"{00BB2763-6A77-11D0-A535-00C04FD7D062}"="Microsoft AutoComplete"
"{7376D660-C583-11d0-A3A5-00C04FD706EC}"="TridentImageExtractor"
"{6756A641-DE71-11d0-831B-00AA005B4383}"="MRU AutoComplete List"
"{6935DB93-21E8-4ccc-BEB9-9FE3C77A297A}"="Custom MRU AutoCompleted List"
"{7e653215-fa25-46bd-a339-34a2790f3cb7}"="Accessible"
"{acf35015-526e-4230-9596-becbe19f0ac9}"="Track Popup Bar"
"{E0E11A09-5CB8-4B6C-8332-E00720A168F2}"="Address Bar Parser"
"{00BB2764-6A77-11D0-A535-00C04FD7D062}"="Microsoft History AutoComplete List"
"{03C036F1-A186-11D0-824A-00AA005B4383}"="Microsoft Shell Folder AutoComplete List"
"{00BB2765-6A77-11D0-A535-00C04FD7D062}"="Microsoft Multiple AutoComplete List Container"
"{ECD4FC4E-521C-11D0-B792-00A0C90312E1}"="Shell Band Site Menu"
"{3CCF8A41-5C85-11d0-9796-00AA00B90ADF}"="Shell DeskBarApp"
"{ECD4FC4C-521C-11D0-B792-00A0C90312E1}"="Shell DeskBar"
"{ECD4FC4D-521C-11D0-B792-00A0C90312E1}"="Shell Rebar BandSite"
"{DD313E04-FEFF-11d1-8ECD-0000F87A470C}"="User Assist"
"{EF8AD2D1-AE36-11D1-B2D2-006097DF8C11}"="Global Folder Settings"
"{EFA24E61-B078-11d0-89E4-00C04FC9E26E}"="Favorites Band"
"{0A89A860-D7B1-11CE-8350-444553540000}"="Shell Automation Inproc Service"
"{E7E4BC40-E76A-11CE-A9BB-00AA004AE837}"="Shell DocObject Viewer"
"{A5E46E3A-8849-11D1-9D8C-00C04FC99D61}"="Microsoft Browser Architecture"
"{FBF23B40-E3F0-101B-8488-00AA003E56F8}"="InternetShortcut"
"{3C374A40-BAE4-11CF-BF7D-00AA006946EE}"="Microsoft Url History Service"
"{FF393560-C2A7-11CF-BFF4-444553540000}"="History"
"{7BD29E00-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{7BD29E01-76C1-11CF-9DD0-00A0C9034933}"="Temporary Internet Files"
"{CFBFAE00-17A6-11D0-99CB-00C04FD64497}"="Microsoft Url Search Hook"
"{A2B0DD40-CC59-11d0-A3A5-00C04FD706EC}"="IE4 Suite Splash Screen"
"{67EA19A0-CCEF-11d0-8024-00C04FD75D13}"="CDF Extension Copy Hook"
"{131A6951-7F78-11D0-A979-00C04FD705A2}"="ISFBand OC"
"{9461b922-3c5a-11d2-bf8b-00c04fb93661}"="Search Assistant OC"
"{3DC7A020-0ACD-11CF-A9BB-00AA004AE837}"="The Internet"
"{871C5380-42A0-1069-A2EA-08002B30309D}"="Internet Name Space"
"{EFA24E64-B078-11d0-89E4-00C04FC9E26E}"="Explorer Band"
"{9E56BE60-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{9E56BE61-C50F-11CF-9A2C-00A0C90A90CE}"="Sendmail service"
"{88C6C381-2E85-11D0-94DE-444553540000}"="ActiveX Cache Folder"
"{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"="WebCheck"
"{ABBE31D0-6DAE-11D0-BECA-00C04FD940BE}"="Subscription Mgr"
"{F5175861-2688-11d0-9C5E-00AA00A45957}"="Subscription Folder"
"{08165EA0-E946-11CF-9C87-00AA005127ED}"="WebCheckWebCrawler"
"{E3A8BDE6-ABCE-11d0-BC4B-00C04FD929DB}"="WebCheckChannelAgent"
"{E8BB6DC0-6B4E-11d0-92DB-00A0C90C2BD7}"="TrayAgent"
"{7D559C10-9FE9-11d0-93F7-00AA0059CE02}"="Code Download Agent"
"{E6CC6978-6B6E-11D0-BECA-00C04FD940BE}"="ConnectionAgent"
"{D8BD2030-6FC9-11D0-864F-00AA006809D9}"="PostAgent"
"{7FC0B86E-5FA7-11d1-BC7C-00C04FD929DB}"="WebCheck SyncMgr Handler"
"{352EC2B7-8B9A-11D1-B8AE-006008059382}"="Shell Application Manager"
"{0B124F8F-91F0-11D1-B8B5-006008059382}"="Installed Apps Enumerator"
"{CFCCC7A0-A282-11D1-9082-006008059382}"="Darwin App Publisher"
"{e84fda7c-1d6a-45f6-b725-cb260c236066}"="Shell Image Verbs"
"{66e4e4fb-f385-4dd0-8d74-a2efd1bc6178}"="Shell Image Data Factory"
"{3F30C968-480A-4C6C-862D-EFC0897BB84B}"="GDI+ file thumbnail extractor"
"{9DBD2C50-62AD-11d0-B806-00C04FD706EC}"="Summary Info Thumbnail handler (DOCFILES)"
"{EAB841A0-9550-11cf-8C16-00805F1408F3}"="HTML Thumbnail Extractor"
"{eb9b1153-3b57-4e68-959a-a3266bc3d7fe}"="Shell Image Property Handler"
"{CC6EEFFB-43F6-46c5-9619-51D571967F7D}"="Web Publishing Wizard"
"{add36aa8-751a-4579-a266-d66f5202ccbb}"="Print Ordering via the Web"
"{6b33163c-76a5-4b6c-bf21-45de9cd503a1}"="Shell Publishing Wizard Object"
"{58f1f272-9240-4f51-b6d4-fd63d1618591}"="Get a Passport Wizard"
"{7A9D77BD-5403-11d2-8785-2E0420524153}"="User Accounts"
"{BD472F60-27FA-11cf-B8B4-444553540000}"="Compressed (zipped) Folder Right Drag Handler"
"{888DCA60-FC0A-11CF-8F0F-00C04FD7D062}"="Compressed (zipped) Folder SendTo Target"
"{f39a0dc0-9cc8-11d0-a599-00c04fd64433}"="Channel File"
"{f3aa0dc0-9cc8-11d0-a599-00c04fd64434}"="Channel Shortcut"
"{f3ba0dc0-9cc8-11d0-a599-00c04fd64435}"="Channel Handler Object"
"{f3da0dc0-9cc8-11d0-a599-00c04fd64437}"="Channel Menu"
"{f3ea0dc0-9cc8-11d0-a599-00c04fd64438}"="Channel Properties"
"{63da6ec0-2e98-11cf-8d82-444553540000}"="FTP Folders Webview"
"{883373C3-BF89-11D1-BE35-080036B11A03}"="Microsoft DocProp Shell Ext"
"{A9CF0EAE-901A-4739-A481-E35B73E47F6D}"="Microsoft DocProp Inplace Edit Box Control"
"{8EE97210-FD1F-4B19-91DA-67914005F020}"="Microsoft DocProp Inplace ML Edit Box Control"
"{0EEA25CC-4362-4A12-850B-86EE61B0D3EB}"="Microsoft DocProp Inplace Droplist Combo Control"
"{6A205B57-2567-4A2C-B881-F787FAB579A3}"="Microsoft DocProp Inplace Calendar Control"
"{28F8A4AC-BBB3-4D9B-B177-82BFC914FA33}"="Microsoft DocProp Inplace Time Control"
"{8A23E65E-31C2-11d0-891C-00A024AB2DBB}"="Directory Query UI"
"{9E51E0D0-6E0F-11d2-9601-00C04FA31A86}"="Shell properties for a DS object"
"{163FDC20-2ABC-11d0-88F0-00A024AB2DBB}"="Directory Object Find"
"{F020E586-5264-11d1-A532-0000F8757D7E}"="Directory Start/Search Find"
"{0D45D530-764B-11d0-A1CA-00AA00C16E65}"="Directory Property UI"
"{62AE1F9A-126A-11D0-A14B-0800361B1103}"="Directory Context Menu Verbs"
"{ECF03A33-103D-11d2-854D-006008059367}"="MyDocs Copy Hook"
"{ECF03A32-103D-11d2-854D-006008059367}"="MyDocs Drop Target"
"{4a7ded0a-ad25-11d0-98a8-0800361b1103}"="MyDocs Properties"
"{750fdf0e-2a26-11d1-a3ea-080036587f03}"="Offline Files Menu"
"{10CFC467-4392-11d2-8DB4-00C04FA31A66}"="Offline Files Folder Options"
"{AFDB1F70-2A4C-11d2-9039-00C04F8EEB3E}"="Offline Files Folder"
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"
"{ECCDF543-45CC-11CE-B9BF-0080C87CDBA6}"="DfsShell"
"{60fd46de-f830-4894-a628-6fa81bc0190d}"="%DESC_PublishDropTarget%"
"{7A80E4A8-8005-11D2-BCF8-00C04F72C717}"="MMC Icon Handler"
"{0CD7A5C0-9F37-11CE-AE65-08002B2E1262}"=".CAB file viewer"
"{32714800-2E5F-11d0-8B85-00AA0044F941}"="For &People…"
"{8DD448E6-C188-4aed-AF92-44956194EB1F}"="Windows Media Player Play as Playlist Context Menu Handler"
"{CE3FB1D1-02AE-4a5f-A6E9-D9F1B4073E6C}"="Windows Media Player Burn Audio CD Context Menu Handler"
"{F1B9284F-E9DC-4e68-9D7E-42362A59F0FD}"="Windows Media Player Add to Playlist Context Menu Handler"
"{5E44E225-A408-11CF-B581-008029601108}"="Adaptec DirectCD Shell Extension"
"{2559a1f7-21d7-11d4-bdaf-00c04f60b9f0}"="Set Program Access and Defaults"
"{596AB062-B4D2-4215-9F74-E9109B0A8153}"="Previous Versions Property Page"
"{9DB7A13C-F208-4981-8353-73CC61AE2783}"="Previous Versions"
"{692F0339-CBAA-47e6-B5B5-3B84DB604E87}"="Extensions Manager Folder"
"{0006F045-0000-0000-C000-000000000046}"="Microsoft Outlook Custom Icon Handler"
"{640167b4-59b0-47a6-b335-a6b3c0695aea}"="Portable Media Devices"
"{cc86590a-b60a-48e6-996b-41d25ed39a1e}"="Portable Media Devices Menu"
"{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF}"="iTunes"
"{21569614-B795-46b1-85F4-E737A8DC09AD}"="Shell Search Band"
"{D0F93101-DF40-47B2-8538-C1A6F389F7C1}"=""
"{76BE349D-4348-463F-ADFE-6DE1335A39F3}"=""
"{9BB39977-05E3-4E62-B486-76F45D7F41F4}"=""
"{7C9D5882-CB4A-4090-96C8-430BFE8B795B}"="Webroot Spy Sweeper Context Menu Integration"
"{628AEDFC-82B4-4387-89C6-8301423C517F}"=""
"{1A230FBC-951F-4B79-B7B6-BC1DB96100EE}"=""
"{9F97547E-4609-42C5-AE0C-81C61FFAEBC3}"="AVG7 Shell Extension"
"{9F97547E-460A-42C5-AE0C-81C61FFAEBC3}"="AVG7 Find Extension"

**********************************************************************************
HKEY ROOT CLASSIDS:
Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{D0F93101-DF40-47B2-8538-C1A6F389F7C1}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{D0F93101-DF40-47B2-8538-C1A6F389F7C1}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D0F93101-DF40-47B2-8538-C1A6F389F7C1}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{D0F93101-DF40-47B2-8538-C1A6F389F7C1}\InprocServer32]
@="C:\\WINDOWS\\system32\\dTdrm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{76BE349D-4348-463F-ADFE-6DE1335A39F3}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{76BE349D-4348-463F-ADFE-6DE1335A39F3}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{76BE349D-4348-463F-ADFE-6DE1335A39F3}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{76BE349D-4348-463F-ADFE-6DE1335A39F3}\InprocServer32]
@="C:\\WINDOWS\\system32\\guard.tmp"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{9BB39977-05E3-4E62-B486-76F45D7F41F4}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9BB39977-05E3-4E62-B486-76F45D7F41F4}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9BB39977-05E3-4E62-B486-76F45D7F41F4}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{9BB39977-05E3-4E62-B486-76F45D7F41F4}\InprocServer32]
@="C:\\WINDOWS\\system32\\dyactfrm.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{628AEDFC-82B4-4387-89C6-8301423C517F}]
@=""
"IDEx"="ADDR"

[HKEY_CLASSES_ROOT\CLSID\{628AEDFC-82B4-4387-89C6-8301423C517F}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{628AEDFC-82B4-4387-89C6-8301423C517F}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{628AEDFC-82B4-4387-89C6-8301423C517F}\InprocServer32]
@="C:\\WINDOWS\\system32\\ayivvaxx.dll"
"ThreadingModel"="Apartment"

Windows Registry Editor Version 5.00

[HKEY_CLASSES_ROOT\CLSID\{1A230FBC-951F-4B79-B7B6-BC1DB96100EE}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1A230FBC-951F-4B79-B7B6-BC1DB96100EE}\Implemented Categories]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1A230FBC-951F-4B79-B7B6-BC1DB96100EE}\Implemented Categories\{00021492-0000-0000-C000-000000000046}]
@=""

[HKEY_CLASSES_ROOT\CLSID\{1A230FBC-951F-4B79-B7B6-BC1DB96100EE}\InprocServer32]
@="C:\\WINDOWS\\system32\\rlcns4.dll"
"ThreadingModel"="Apartment"

**********************************************************************************
Files Found are not all bad files:

C:\WINDOWS\SYSTEM32\
atmtd.dll Thu Jul 20 2006 12:23:46a A…. 687,592 671.48 K
awstream.dll Fri Jul 21 2006 11:53:46p ..S.R 234,272 228.78 K
ayivvaxx.dll Fri Jul 21 2006 11:53:56p ..S.R 234,272 228.78 K
battyrun.dll Thu Jun 29 2006 9:07:36a A…. 61,440 60.00 K
blld06ee.dll Thu Jul 20 2006 12:24:30a A…. 61,440 60.00 K
bszip.dll Thu Jul 20 2006 12:22:40a A…. 62,464 61.00 K
dillsys.dll Thu Jul 20 2006 12:23:56a ..S.R 234,272 228.78 K
dsrgsnap.dll Thu Jul 20 2006 12:24:00a ..S.R 234,272 228.78 K
dvvclnt.dll Sat Jul 22 2006 12:54:14a ..S.R 234,272 228.78 K
fp6s03~1.dll Fri Jul 21 2006 11:54:06p ..S.R 234,281 228.79 K
gwkcsp.dll Thu Jul 20 2006 12:25:04a ..S.R 234,272 228.78 K
h0n0la~1.dll Thu Jul 20 2006 12:29:40a ..S.R 235,322 229.80 K
hdfcisp2.dll Thu Jul 20 2006 12:25:22a ..S.R 234,272 228.78 K
hnzidr12.dll Thu Jul 20 2006 12:25:14a ..S.R 234,272 228.78 K
ir02l5~1.dll Wed Jul 19 2006 11:47:54a ..S.R 235,477 229.96 K
ir6ml5~1.dll Sun Jul 23 2006 6:14:58p ..S.R 233,830 228.35 K
jbagpbcc.dll Thu Jul 20 2006 12:27:44a A…. 69,632 68.00 K
jjjokkfd.dll Thu Jul 20 2006 12:27:34a A…. 69,632 68.00 K
nodeip~1.dll Tue Jun 20 2006 7:55:26p A…. 389,120 380.00 K
rlcns4.dll Sun Jul 23 2006 6:14:58p ..S.R 236,227 230.69 K
w0035e7d.dll Thu Jul 20 2006 12:24:28a A…. 29,696 29.00 K
windmy.dll Sun Jul 23 2006 6:38:14p A…. 32,768 32.00 K
winnb58.dll Sun Jul 23 2006 6:38:06p A…. 380,928 372.00 K
wrlogo~1.dll Fri Jul 7 2006 4:43:54p A…. 208,896 204.00 K
wrlzma.dll Fri Jul 7 2006 4:43:48p A…. 20,992 20.50 K
xeymi.dll Sun Jul 23 2006 6:15:48p A…. 221,184 216.00 K

26 items found: 26 files (13 H/S), 0 directories.
Total of file sizes: 5,345,097 bytes 5.09 M
Locate .tmp files:

C:\WINDOWS\SYSTEM32\
guard.tmp Sun Jul 23 2006 9:37:58p ..S.R 236,227 230.69 K

1 item found: 1 file (1 H/S), 0 directories.
Total of file sizes: 236,227 bytes 230.69 K
**********************************************************************************
Directory Listing of system files:
Volume in drive C has no label.
Volume Serial Number is B43C-29F6

Directory of C:\WINDOWS\System32

07/23/2006 09:55 PM ..
07/23/2006 09:55 PM .
07/23/2006 09:37 PM 236,227 guard.tmp
07/23/2006 06:14 PM 236,227 rlcns4.dll
07/23/2006 06:14 PM 233,830 ir6ml5j11.dll
07/22/2006 12:54 AM 234,272 dVvclnt.dll
07/21/2006 11:54 PM 234,281 fp6s03j7e.dll
07/21/2006 11:53 PM 234,272 ayivvaxx.dll
07/21/2006 11:53 PM 234,272 awstream.dll
07/20/2006 12:29 AM 235,322 h0n0la5m1d.dll
07/20/2006 12:25 AM 234,272 hdfcisp2.dll
07/20/2006 12:25 AM 234,272 HNZidr12.dll
07/20/2006 12:25 AM 234,272 gwkcsp.dll
07/20/2006 12:23 AM 234,272 dsrgsnap.dll
07/20/2006 12:23 AM 234,272 DillSys.dll
07/19/2006 11:47 AM 235,477 ir02l5do1.dll
07/19/2006 11:30 AM dllcache
08/15/2004 10:32 PM Microsoft
14 File(s) 3,285,540 bytes
4 Dir(s) 2,044,772,352 bytes free
Close any programs you have open since this step requires a reboot.

From the l2mfix folder on your desktop, double click l2mfix.bat and select option #2 for Run Fix by typing 2 and then pressing enter. It will process then start. Your desktop and icons will disappear (this is normal). L2mfix will continue to scan your computer and when it's finished, it will be ready for a reboot. Press any key to reboot. After the reboot notepad will open with a log. Copy the contents of that log and paste it back into this thread, along with a new hijackthis log.

IMPORTANT: Do NOT run any other files in the l2mfix folder unless you are asked to do so!
If after the reboot the log does not open double click on it in the l2mfix folder.

********************************

I need to see another uninstall list. looks like some more things got installed:

Open HijackThis, click Config, click Misc Tools
Click "Open Uninstall Manager"
Click "Save List" (generates uninstall_list.txt)
Click Save, copy and paste the results in your next post.


In your next post, please include
  • new hijackthis log
  • uninstall list
  • l2mfix log
please try to keep this machine disconnected as much as you can (if you can, transfer downloaded programs from another computer), because your infection is downloading more and more malware.
Logfile of HijackThis v1.99.1
Scan saved at 12:46:27 AM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\TWF0dA\command.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\dfndred_7.exe
C:\kybrded_7.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\cfg32.exe
C:\nwnmed_7.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\cvn0.exe
C:\WINDOWS\system32\n9nyb.exe
C:\WINDOWS\system32\ghynf.exe
C:\WINDOWS\system32\wfxqhv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\zqskw.exe
C:\Program Files\webHancer\Programs\whAgent.exe
C:\WINDOWS\pop06ap2.exe
C:\Program Files\Common Files\{B43C29F6-0958-1033-0428-030211050001}\Update.exe
C:\Program Files\PSHope\PSHope.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\System Files\System.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\HJT\HijackThis.exe
C:\Program Files\Internet Explorer\iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\system32\dftaa.exe
F2 - REG:system.ini: UserInit=userinit.exe,obbekhu.exe
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: ToolBar888 - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int408387.exe -auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [defender] C:\\dfndred_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrded_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [blld06ee] "RUNDLL32.EXE" w0035e7d.dll,n 001d06ed000000030035e7d
O4 - HKLM\..\Run: [w00386be.dll] "RUNDLL32.EXE" w00386be.dll,I2 001d06ed000386be
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinspez.exe CORN003
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmed_7.exe
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\system32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [webHancer Agent] "C:\Program Files\webHancer\Programs\whAgent.exe"
O4 - HKLM\..\Run: [webHancer Survey Companion] "C:\Program Files\webHancer\Programs\whSurvey.exe"
O4 - HKLM\..\Run: [pop06ap] C:\WINDOWS\pop06ap2.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinspez.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: (no name) - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra 'Tools' menuitem: Java - {4ABF810A-F11D-4169-9D5F-7D274F2270A1} - C:\WINDOWS\system32\dmonwv.dll (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O10 - Hijacked Internet access by WebHancer
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} (mm06ocx.mm06ocxf) - http://cabs.media-motor.net/cabs/joysavsht.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\ir6ml5j11.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0dA\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Ad-Aware SE Personal
Adobe Download Manager 2.0 (Remove Only)
AOL Instant Messenger
ATI Control Panel
ATI Display Driver
Audacity 1.2.3
AVG Free Edition
BitTorrent 4.0.3
Broadcom 440x Driver Installer
Broadcom Advanced Control Suite
Citrix ICA Web Client
Collab
Command
Conexant D480 MDC V.92 Modem
Dell ResourceCD
Digital Line Detect
DivX
DivX Player
Easy CD Creator 5 Basic
Finale NotePad 2005
FL Studio 5
Forethought
Guitar Pro 4 Demo
HijackThis 1.99.1
hp instant support
HP Memories Disc
HP Photo and Imaging 2.0 - All-in-One
HP Photo and Imaging 2.0 - All-in-One Drivers
HP Photo and Imaging 2.0 - hp psc 1200 series
hp psc 1200 series
Icons
iTunes
J2SE Runtime Environment 5.0 Update 1
Media-motor
Microsoft Data Access Components KB870669
Microsoft Office 2000 Small Business
Mozilla Firefox (1.0.4)
MSN Music Assistant
NetBattle
OpenMG Limited Patch 4.2-05-07-27-01
OpenMG Secure Module 4.2.00
Quicklinks
QuickTime
Related Page
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899587)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB903235)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Sibelius Scorch
SigmaTel AC97 Audio Drivers
SonicStage 3.2
SoulSeek Client 156c
Spy Sweeper
Sunbelt Kerio Personal Firewall
SYMPHONY X - SPECIAL EDITION Screen Saver
Synaptics TouchPad
TeamSpeak 2 RC2
ToolBar888
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB910437)
Ventrilo Client
Web Nexus Network
webHancer Customer Companion
webHancer Survey Companion
Windows Installer 3.1 (KB893803)
Windows Media Format Runtime
Windows Media Player 10
Windows XP Hotfix - KB834707
Windows XP Hotfix - KB867282
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885836
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB890047
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB890923
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893066
Windows XP Hotfix - KB893086
Windows XP Service Pack 2
WordPerfect Office 2002
WordPerfect Office 2002
World of Warcraft
WowEquip (remove only)
XnView 1.74
Yahoo! Toolbar


L2mfix 051206
Creating Account.
The account already exists.

More help is available by typing NET HELPMSG 2224.

Adding Administrative privleges.
Checking for L2MFix account(0=no 1=yes):
1
Granting SeDebugPrivilege to L2MFIX … successful
Checking for L2MFix account(0=no 1=yes):
0
Zipping up files for submission:
adding: dlls/awstream.dll (188 bytes security) (deflated 4%)
adding: dlls/ayivvaxx.dll (188 bytes security) (deflated 4%)
adding: dlls/DillSys.dll (188 bytes security) (deflated 4%)
adding: dlls/dsrgsnap.dll (188 bytes security) (deflated 4%)
adding: dlls/dVvclnt.dll (188 bytes security) (deflated 4%)
adding: dlls/fp6s03j7e.dll (188 bytes security) (deflated 4%)
adding: dlls/guard.tmp (188 bytes security) (deflated 5%)
adding: dlls/gwkcsp.dll (188 bytes security) (deflated 4%)
adding: dlls/h0n0la5m1d.dll (188 bytes security) (deflated 5%)
adding: dlls/hdfcisp2.dll (188 bytes security) (deflated 4%)
adding: dlls/HNZidr12.dll (188 bytes security) (deflated 4%)
adding: dlls/ir02l5do1.dll (188 bytes security) (deflated 5%)
adding: backregs/1A230FBC-951F-4B79-B7B6-BC1DB96100EE.reg (212 bytes security) (deflated 70%)
adding: backregs/628AEDFC-82B4-4387-89C6-8301423C517F.reg (212 bytes security) (deflated 69%)
adding: backregs/76BE349D-4348-463F-ADFE-6DE1335A39F3.reg (212 bytes security) (deflated 70%)
adding: backregs/9BB39977-05E3-4E62-B486-76F45D7F41F4.reg (212 bytes security) (deflated 70%)
adding: backregs/D0F93101-DF40-47B2-8538-C1A6F389F7C1.reg (212 bytes security) (deflated 69%)
adding: backregs/notibac.reg (188 bytes security) (deflated 79%)
adding: backregs/shell.reg (188 bytes security) (deflated 73%)
Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


First, Download LSPFix.exe to a convenient location. Do NOT run this program. This is only to be used if you lose Internet Access after removing webHancer.

Please remove these entries from Add or Remove Programs in the Control Panel(if present):

Forethought
Icons
Media-motor
Quicklinks
Related Page
ToolBar888
Web Nexus Network
webHancer Customer Companion
webHancer Survey Companion

The following are optional; however, any time your are running any type of P2P application, you are FAR more prone to infection by malware. Your current infections are likely due to P2P use. At the VERY LEAST, please refrain from using any p2p programs while we are cleaning your computer:

BitTorrent 4.0.3

Please note any other programs that you dont recognize in that list in your next response

(an easy way to get to Add or Remove programs is to go to start–>run and type appwiz.cpl)

In the event that you lose Internet access after removing webHancer, please double-click LSPFix.exe that you downloaded earlier. Check the "I know what I'm doing" button. You will see 2 panels. If there is any file listed in the "Remove" panel on the right-side, leave it as is and just click "Finish>>" then reboot your computer and you should now have access to the Internet. If nothing is listed under the "Remove Panel", do NOT do anything - just close the program. You will need to use another computer to come back here for further instructions on what to do.

**************************

Please download Qoofix by RubbeR DuckY from one of the following locations:

http://www.malwarebytes.org/Qoofix.zip or
http://www.besttechie.net/tools/Qoofix.zip
  • Unzip all files to a convenient location such as C:\Qoofix.
  • Go to the folder you unzipped all files and run Qoofix.exe.
  • Click Begin Removal and wait for the scan to finish.
  • If an infection has been found, select yes to restart your computer.
Finally post a new Hijack This log and the contents of the Qoofix logfile.

*************************

Please download Ewido to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install Ewido by double clicking the installer.
  • Follow the prompts. Make sure that Launch Ewido is checked.
  • On the main screen under Your Computer's security.
  • Click on Change state next to Resident shield. It should now change to inactive.
  • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
  • Wait until you see the Update succesfull message.
    Note: If the Update now option is grayed out, follow the steps below.
  • Click on Update on the toolbar.
  • Under Manual update, click on the Start Update button.
  • Wait until you see the Update succesfull message.
[*]Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.

If you are having problems with the updater, you can use this link to manually update ewido.
Ewido manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that Ewido is closed before installing the update.

Please download Brute Force Uninstaller to your desktop.
  • Right click the BFU folder on your desktop, and choose Extract All
  • Click "Next"
  • In the box to choose where to extract the files to,
  • Click "Browse"
  • Click on the + sign next to "My Computer"
  • Click on "Local Disk (C:) or whatever your primary drive is
  • Click "Make New Folder"
  • Type in BFU
  • Click "Next", and Uncheck the "Show Extracted Files" box and then click "Finish".
RIGHT-CLICK HERE and choose "Save As" (in IE it's "Save Target As") in order to download Alcra PLUS Remover.
Save it in the same folder you made earlier (c:\BFU).

Do not do anything with these yet!

***************************************

Next, please reboot your computer in SafeMode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear
  • Select the first option, to run Windows in Safe Mode.
For additional help in booting into Safe Mode, see the following site:
http://www.pchell.com/support/safemode.shtml

***************************************

Navigate to C:\Windows\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Navigate to C:\Documents and Settings\(EVERY LISTED USER)\Local Settings\Temp
Click Edit, click Select All, press the DELETE key, and then click Yes to confirm that you want to send all the items to the Recycle Bin.

Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.
Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.
______________________________

Please go to Start > My Computer and navigate to the C:\BFU folder.
  • Start the Brute Force Uninstaller by doubleclicking BFU.exe
  • Behind the scriptline to execute field click the folder icon [external image: Posted Image] and select alcanshorty.bfu
  • Press Execute and let the program do it’s job. (You ought to see a progress bar if you did this correctly.)
  • Wait for the complete script execution box to pop up and press OK.
  • Press exit to terminate the BFU program.
Then, Close ALL open Windows / Programs / Folders. Please start Ewido and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the Ewido Tray Icon and select Exit. Confirm by clicking Yes.
***************************************

reboot your system back into Normal Mode

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report
in your next post, please include
  • new hijackthis log
  • ewido log
  • panda log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Logfile of HijackThis v1.99.1
Scan saved at 1:24:19 AM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\TWF0dA\command.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\dfndred_7.exe
C:\kybrded_7.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\cfg32.exe
C:\nwnmed_7.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\zqskw.exe
C:\Program Files\Common Files\{B43C29F6-0958-1033-0428-030211050001}\Update.exe
C:\Program Files\Java\jre1.5.0_01\bin\jucheck.exe
C:\Program Files\PSHope\PSHope.exe
C:\Program Files\System Files\System.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\cfg32a.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int408387.exe -auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [defender] C:\\dfndred_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrded_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [blld06ee] "RUNDLL32.EXE" w0035e7d.dll,n 001d06ed000000030035e7d
O4 - HKLM\..\Run: [w00386be.dll] "RUNDLL32.EXE" w00386be.dll,I2 001d06ed000386be
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinspez.exe CORN003
O4 - HKLM\..\Run: [Configuration Manager] C:\WINDOWS\cfg32.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmed_7.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [PSHope] "C:\Program Files\PSHope\PSHope.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinspez.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\ir6ml5j11.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\TWF0dA\command.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Qoofix v1.02 by http://www.malwarebytes.org
Scan started on [7/24/2006] at [1:14:30 AM]
————————————————————-
No malicious modules found!
————————————————————-
No Qoologic infected files found!
————————————————————-
Scan COMPLETED SUCCESSFULLY on [7/24/2006] at [1:16:27 AM]

Note: Some registry keys may have been removed.
Well I think I'm going to call it a night (have to wake up early tomorrow). Hopefully I'll the next three logs up by noon tomorrow.
Logfile of HijackThis v1.99.1
Scan saved at 10:48:09 AM, on 7/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Sunbelt Software\Personal Firewall\kpf4gui.exe
C:\WINDOWS\system32\carpserv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\TClock\TClock.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - (no file)
O2 - BHO: CExtension Object - {0019C3E2-DD48-4A6D-ABCD-8D32436323D9} - C:\WINDOWS\cfg32p.dll (file missing)
O2 - BHO: CFG32S - {7564B020-44E8-4c9b-A887-C6EC41AC67DA} - C:\WINDOWS\cfg32r.dll (file missing)
O2 - BHO: Scaggy Insert - {C68AE9C0-0909-4DDC-B661-C1AFB9F59898} - C:\WINDOWS\cfg32o.dll (file missing)
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\system32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll
O3 - Toolbar: Search - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\WINDOWS\cfg32s.dll (file missing)
O3 - Toolbar: Related Page - {9A9C9B68-F908-4AAB-8D0C-10EA8997F37E} - C:\WINDOWS\system32\WinNB58.dll (file missing)
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SynTPLpr] "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe"
O4 - HKLM\..\Run: [SynTPEnh] "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [websx] C:\Program Files\websx\int408387.exe -auto
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [SsAAD.exe] C:\PROGRA~1\Sony\SONICS~1\SsAAD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [blld06ee] "RUNDLL32.EXE" w0035e7d.dll,n 001d06ed000000030035e7d
O4 - HKLM\..\Run: [w00386be.dll] "RUNDLL32.EXE" w00386be.dll,I2 001d06ed000386be
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\system32\wfxqhv.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.adgate.info
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.errorsafe.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.matcash.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.mmohsix.com
O15 - Trusted Zone: *.mt-download.com
O15 - Trusted Zone: *.snipernet.biz
O15 - Trusted Zone: *.systemdoctor.com
O15 - Trusted Zone: *.winantivirus.com
O15 - Trusted Zone: *.winfixer.com
O15 - Trusted Zone: *.adgate.info (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.elitemediagroup.net (HKLM)
O15 - Trusted Zone: *.errorsafe.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.matcash.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.media-motor.net (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.mt-download.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O15 - Trusted Zone: *.snipernet.biz (HKLM)
O15 - Trusted Zone: *.systemdoctor.com (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.winfixer.com (HKLM)
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\system32\xeymi.dll
O20 - Winlogon Notify: logons - C:\WINDOWS\system32\redist.dll (file missing)
O20 - Winlogon Notify: SideBySide - C:\WINDOWS\system32\ir6ml5j11.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sunbelt Kerio Personal Firewall 4 (KPF4) - Sunbelt Software - C:\Program Files\Sunbelt Software\Personal Firewall\kpf4ss.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 8:39:17 AM 7/24/2006 + Scan result: C:\WINDOWS\icont.exe -> Adware.AdURL : Cleaned with backup (quarantined). C:\WINDOWS\system32\jbagpbcc.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\WINDOWS\system32\jjjokkfd.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined). C:\WINDOWS\cfg32o.dll -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\WINDOWS\cfg32p.dll -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\WINDOWS\cfg32r.dll -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\WINDOWS\cfg32s.dll -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\WINDOWS\diovzgbj.exe -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\stub_sca3.exe -> Adware.BookedSpace : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Adware.BookedSpace : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Adware.BookedSpace : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\BookedSpace.Extension.5 -> Adware.BookedSpace : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Adware.BookedSpace : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Adware.BookedSpace : Cleaned with backup (quarantined). C:\Program Files\Batty\Batty.exe -> Adware.CASClient : Cleaned with backup (quarantined). C:\Program Files\System Files\plugin.dll -> Adware.CASClient : Cleaned with backup (quarantined). C:\Documents and Settings\Daniel\My Documents\My Documents\installcasino.exe -> Adware.Casino : Cleaned with backup (quarantined). C:\Documents and Settings\Daniel\My Documents\pacificpoker.exe -> Adware.Casino : Cleaned with backup (quarantined). C:\WINDOWS\system32\nsw69.dll -> Adware.Ezula : Cleaned with backup (quarantined). HKU\S-1-5-21-1343024091-1580818891-2146950067-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined). C:\WINDOWS\system32\blld06ee.dll -> Adware.IEHelper : Cleaned with backup (quarantined). C:\Program Files\Uninstall Need2Find Bar.dll -> Adware.IESearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\ftuninst.exe -> Adware.Linkmaker : Cleaned with backup (quarantined). C:\WINDOWS\system32ftuninst.exe -> Adware.Linkmaker : Cleaned with backup (quarantined). C:\Installer2.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\Installer3.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\DillSys.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\HNZidr12.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\awstream.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\ayivvaxx.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\dVvclnt.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\dsrgsnap.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\fp6s03j7e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\guard.tmp -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\gwkcsp.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\h0n0la5m1d.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\hdfcisp2.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\l2mfix\dlls\ir02l5do1.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\warebundle2.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\warebundle3.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\warebundlenewer.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\pop06ap2.exe -> Adware.MediaMotor : Cleaned with backup (quarantined). C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined). C:\WINDOWS\system32\WinDmy.dll -> Adware.Mirar : Cleaned with backup (quarantined). C:\WINDOWS\system32\WinNB58.dll -> Adware.Mirar : Cleaned with backup (quarantined). C:\WINDOWS\mirar.exe -> Adware.NetNucleus : Cleaned with backup (quarantined). C:\NNSCAA638.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\KBBar.KBBarBand -> Adware.PowerStrip : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\KBBar.KBBarBand.1 -> Adware.PowerStrip : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CLSID -> Adware.PowerStrip : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\KBBar.KBBarBand\CurVer -> Adware.PowerStrip : Cleaned with backup (quarantined). C:\Program Files\PSHope\PSHope.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\WINDOWS\system32tfthot.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined). C:\WINDOWS\system32\gbe90qs.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32\n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined). HKLM\SOFTWARE\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined). HKLM\SOFTWARE\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined). HKU\S-1-5-21-1343024091-1580818891-2146950067-1003\Software\SurfSideKick3 -> Adware.SurfSide : Cleaned with backup (quarantined). HKU\S-1-5-21-1343024091-1580818891-2146950067-1003\Software\SurfSideKick3\Internet Explorer -> Adware.SurfSide : Cleaned with backup (quarantined). C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup (quarantined). C:\Program Files\whInstall\whAgent.inf -> Adware.Webhancer : Cleaned with backup (quarantined). C:\Program Files\whInstall\whInstaller.ini -> Adware.Webhancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\webHancer -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\webHancer\CC -> Adware.WebHancer : Cleaned with backup (quarantined). C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\system32\w0035e7d.dll -> Downloader.Small : Cleaned with backup (quarantined). C:\WINDOWS\amm06.ocx -> Downloader.VB.bo : Cleaned with backup (quarantined). C:\Documents and Settings\Daniel\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup (quarantined). :mozilla.871:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.876:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.878:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.126:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.127:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.128:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.177:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.178:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.179:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.180:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.181:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.182:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.183:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.184:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.185:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.479:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.812:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.845:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.877:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.348:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.673:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.719:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.753:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.801:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.836:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.612:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined). :mozilla.513:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.514:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.515:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.516:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.517:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.518:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.165:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.579:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.580:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.581:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.582:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.583:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.860:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.861:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.823:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.160:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.161:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.162:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.163:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.164:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.174:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.91:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.92:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.93:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.94:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.101:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.813:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.189:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup (quarantined). :mozilla.187:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.155:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined). :mozilla.156:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.157:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.158:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.107:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.108:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.109:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.110:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.165:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.166:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.167:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.168:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.169:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.170:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.664:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup (quarantined). :mozilla.539:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.540:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.541:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.542:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). C:\Documents and Settings\Administrator\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.51:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.67:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.68:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.69:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.70:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\guest@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.520:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned with backup (quarantined). :mozilla.110:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.111:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.112:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup (quarantined). :mozilla.359:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.360:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.361:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.15:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.33:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.65:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.66:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.68:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.69:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.152:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.153:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.154:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.53:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.54:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.55:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.56:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.16:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). :mozilla.77:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.78:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.79:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.699:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined). :mozilla.136:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.140:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.143:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.512:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.558:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.590:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.591:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.594:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.705:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.706:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.751:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.826:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.827:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.828:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.833:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.895:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup (quarantined). :mozilla.87:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined). :mozilla.88:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined). :mozilla.89:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined). :mozilla.90:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup (quarantined). :mozilla.661:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup (quarantined). :mozilla.424:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined). :mozilla.426:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup (quarantined). :mozilla.10:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.11:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.12:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.693:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.694:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.700:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.701:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.93:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.94:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.97:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.523:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.193:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.194:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.195:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.196:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.336:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.337:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.338:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.339:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.343:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.344:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined). :mozilla.131:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.132:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.133:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.623:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.624:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.625:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.626:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.627:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.25:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.31:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.32:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.33:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.364:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.365:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.366:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.367:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.441:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.533:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.534:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.535:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.536:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.853:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.854:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.855:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned with backup (quarantined). :mozilla.313:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.320:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\LocalService\Application Data\Mozilla\Firefox\Profiles\hac8r2gb.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.66:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.72:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.73:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.74:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.75:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.76:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.62:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.63:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.64:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.67:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.838:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.630:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup (quarantined). :mozilla.584:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined). :mozilla.192:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.557:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.264:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.265:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.266:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.267:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.268:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.269:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.270:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.271:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.272:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.175:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.176:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\umlx841j.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.57:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.58:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.59:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.60:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.61:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.62:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\4h4yfyoq.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.63:C:\Document

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI