This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijacked by Surf Sidekick

26 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ran Spybot and Adaware SE, both current on updates. Being bombarded by pop ups. Mainly ad.firstadsolution.com and heavy.com.

Here's a hijackthis.log

Thanks in Advance.

Logfile of HijackThis v1.99.1
Scan saved at 11:40:57 PM, on 7/25/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\SLClient.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\SSC Service Utility\ssc_serv.exe
C:\WINDOWS\System32\cvn0.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wfxqhv.exe
C:\dfndref_7.exe
C:\kybrdef_7.exe
C:\WINDOWS\System32\zqskw.exe
C:\WINDOWS\System32\n9nyb.exe
C:\WINDOWS\win32098182528936.exe
C:\WINDOWS\bamzswmA.exe
C:\Program Files\Common Files\{6CCBB498-063A-1033-1029-040410060001}\Update.exe
C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe
C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
c:\windows\system32\dwdsregt.exe
C:\Program Files\Cirond\Cirond Winc\Winc.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\PROGRA~1\COMMON~1\iouz\iouza.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\WINDOWS\system32\lwinmpez.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\mcmus.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,xwsydme.exe
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] C:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdef_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win32098182528936] C:\WINDOWS\win32098182528936.exe
O4 - HKLM\..\Run: [bamzswmA] C:\WINDOWS\bamzswmA.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [{BB-B4-49-98-ZN}] c:\windows\system32\dwdsregt.exe CORN003
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt yazr
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\oldsregk.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain = mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O20 - AppInit_DLLs: repairs303169590.dll
O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\lvjs0917e.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation - C:\WINDOWS\System32\SLClient.exe
Tried spybot and adaware in safe mode and that seemed to help, but I'm still getting popups and my computer seems to lock up after surfing for a couple minutes. Ran a new hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 9:05:50 PM, on 7/27/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe, C:\WINDOWS\System32\mcmus.exe
F2 - REG:system.ini: UserInit=userinit.exe,xwsydme.exe
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] C:\\dfndref_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdef_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win32098182528936] C:\WINDOWS\win32098182528936.exe
O4 - HKLM\..\Run: [bamzswmA] C:\WINDOWS\bamzswmA.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [{BB-B4-49-98-ZN}] C:\windows\system32\dwdsregt.exe CORN003
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt yazr
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\TEMP\42.tmp3072.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\oldsregk.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain = mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_27.dll
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi25757.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation - C:\WINDOWS\System32\SLClient.exe
Hello and welcome to the forum.

Please download Qoofix by RubbeR DuckY from one of the following locations:

http://www.malwarebytes.org/Qoofix.zip or
http://www.besttechie.net/tools/Qoofix.zip
  • Unzip all files to a convenient location such as C:\Qoofix.
  • Go to the folder you unzipped all files and run Qoofix.exe.
  • Click Begin Removal and wait for the scan to finish.
  • If an infection has been found, select yes to restart your computer.

Finally post a new Hijack This log and the contents of the Qoofix logfile.
Ran Qoofix and it seemed to work, however now my machine is taking FOREVER to load. Took at least 15-20 minutes just to load windows. At that time it seemed to lock up. Booted up in safe mode and ran hijackthis. Not sure how helpful that is, but here it is.

Logfile of HijackThis v1.99.1
Scan saved at 9:13:36 PM, on 8/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =

http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =

http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =

http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =

http://us.rd.yahoo.com/customize/ie/defaul…xt/search/searc

h.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =

http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

http://www.mrfindalot.com/search.asp?si=
R3 - Default URLSearchHook is missing
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} -

C:\WINDOWS\System32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} -

C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program

Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE"

/STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common

Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common

Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard

Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common

Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300

Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] C:\\dfndrff_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win32098182528936] C:\WINDOWS\win32098182528936.exe
O4 - HKLM\..\Run: [bamzswmA] C:\WINDOWS\bamzswmA.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [{BB-B4-49-98-ZN}] c:\windows\system32\oldsregk.exe CORN003
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinmpez.exe CORN003
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series]

C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300

Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt yazr
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application

Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\TEMP\42.tmp3072.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web

Folders\ibm00001.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN

Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare

software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program

files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program

files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program

files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program

files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program

files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -

C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) -

http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -

http://appldnld.m7z.net/content.info.apple…11.MmVrT/iTunes

Setup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -

http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/microsoftupdat…_site.cab?11399

70307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdat…_site.cab?11399

70297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) -

http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) -

http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) -

http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} -

http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain =

mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList =

mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnson

line.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList =

mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnson

line.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} -

C:\WINDOWS\System32\xeymi.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} -

C:\WINDOWS\System32\2236_28.dll
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner -

C:\WINDOWS\System32\aspi25757.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program

Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard

Disk\User\DISrv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology,

Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows

XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program

Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner -

C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. -

C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. -

C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. -

C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program

Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard

Disk\User\PCGProt.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program

Files\Spyware Doctor\sdhelp.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation -

C:\WINDOWS\System32\SLClient.exe
Qoofix v1.03 by http://www.malwarebytes.org
Scan started on [8/1/2006] at [7:51:50 PM]
————————————————————-
Terminated module: cauqjpp.dll found in Qoofix.exe (4112)
Terminated module: cauqjpp.dll found in vsuqsh.exe (252)
Terminated module: cauqjpp.dll found in mcmus.exe (152)
Terminated module: cauqjpp.dll found in mcmus.exe (176)
Terminated module: cauqjpp.dll found in mcmus.exe (204)
Terminated module: cauqjpp.dll found in explorer.exe (2168)
Terminated module: cauqjpp.dll found in shstat.exe (2272)
Terminated module: cauqjpp.dll found in UpdaterUI.exe (2288)
Terminated module: cauqjpp.dll found in SynTPLpr.exe (2300)
Terminated module: cauqjpp.dll found in ctfmon.exe (2308)
Terminated module: cauqjpp.dll found in SynTPEnh.exe (2320)
Terminated module: cauqjpp.dll found in TBMon.exe (2364)
Terminated module: cauqjpp.dll found in AGRSMMSG.exe (2416)
Terminated module: cauqjpp.dll found in LaunchEPHD.exe (2468)
Terminated module: cauqjpp.dll found in E_S4I2F1.EXE (2616)
Terminated module: cauqjpp.dll found in realsched.exe (2628)
Terminated module: cauqjpp.dll found in iTunesHelper.exe (2688)
Terminated module: cauqjpp.dll found in qttask.exe (2704)
Terminated module: cauqjpp.dll found in ssc_serv.exe (2728)
Terminated module: cauqjpp.dll found in dfndref_7.exe (2872)
Terminated module: cauqjpp.dll found in kybrdef_7.exe (2912)
Terminated module: cauqjpp.dll found in win32098182528936.exe (2968)
Terminated module: cauqjpp.dll found in bamzswmA.exe (2984)
Terminated module: cauqjpp.dll found in ghynf.exe (3000)
Terminated module: cauqjpp.dll found in lwinmpez.exe (3180)
Terminated module: cauqjpp.dll found in iouzm.exe (3432)
Terminated module: cauqjpp.dll found in iouza.exe (3660)
Terminated module: cauqjpp.dll found in Winc.exe (3740)
Terminated module: cauqjpp.dll found in FireTray.exe (3784)
Terminated module: cauqjpp.dll found in tclock.exe (3820)
Terminated module: cauqjpp.dll found in kybrdff_7.exe (2436)
Terminated module: cauqjpp.dll found in dfndrff_7.exe (3172)
Terminated module: cauqjpp.dll found in iexplore.exe (5168)
————————————————————-
C:\WINDOWS\System32\cauqjpp.dll will be deleted on reboot!
C:\WINDOWS\System32\cpkte.dat will be deleted on reboot!
C:\WINDOWS\System32\mcmus.exe will be deleted on reboot!
C:\WINDOWS\System32\vsuqsh.exe will be deleted on reboot!
C:\WINDOWS\System32\xwsydme.exe will be deleted on reboot!
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\oahry.exe will be deleted on reboot!

User prompted YES to reboot, system now rebooting…
————————————————————-
Scan COMPLETED SUCCESSFULLY on [8/1/2006] at [7:53:27 PM]

Note: Some registry keys may have been removed.
Logfile of HijackThis v1.99.1
Scan saved at 9:13:36 PM, on 8/1/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - Default URLSearchHook is missing
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] C:\\dfndrff_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win32098182528936] C:\WINDOWS\win32098182528936.exe
O4 - HKLM\..\Run: [bamzswmA] C:\WINDOWS\bamzswmA.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [{BB-B4-49-98-ZN}] c:\windows\system32\oldsregk.exe CORN003
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\system32\lwinmpez.exe CORN003
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt yazr
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\TEMP\42.tmp3072.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain = mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_28.dll
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi25757.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation - C:\WINDOWS\System32\SLClient.exe
That scan looks like it's from Safe Mode. I need to see the HJT log post from Normal Mode. Please reboot in Normal Mode and post a new HJT log.
Logfile of HijackThis v1.99.1
Scan saved at 8:44:00 PM, on 8/3/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\aspi25757.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\SLClient.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SSC Service Utility\ssc_serv.exe
C:\WINDOWS\System32\wfxqhv.exe
C:\dfndrff_7.exe
C:\kybrdff_7.exe
C:\WINDOWS\win32098182528936.exe
C:\WINDOWS\bamzswmA.exe
C:\windows\system32\oldsregk.exe
C:\Program Files\Common Files\{6CCBB498-063A-1033-1029-040410060001}\Update.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe
C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
C:\Program Files\Cirond\Cirond Winc\Winc.exe
C:\WINDOWS\System32\zqskw.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\WINDOWS\System32\n9nyb.exe
C:\WINDOWS\System32\ghynf.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\iouz\iouza.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\System32\lwinmpez.exe
C:\WINDOWS\System32\cvn0.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - Default URLSearchHook is missing
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [ad8rIU3s] C:\WINDOWS\System32\cvn0.exe
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [defender] C:\\dfndrff_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [win32098182528936] C:\WINDOWS\win32098182528936.exe
O4 - HKLM\..\Run: [bamzswmA] C:\WINDOWS\bamzswmA.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [{BB-B4-49-98-ZN}] C:\windows\system32\oldsregk.exe CORN003
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKLM\..\Run: [BrowserUpdateSched] C:\WINDOWS\System32\lwinmpez.exe CORN003
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt yazr
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [WinMedia] C:\WINDOWS\TEMP\42.tmp3072.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain = mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_28.dll
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi25757.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation - C:\WINDOWS\System32\SLClient.exe
You have quit a collection :o

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan along with a new HijackThis log.
Alright, I obviously can't follow directions. Hopefully it doesn't cause a problem. I forgot to boot into safe mode before running ewido so I have two scan results, one in regular mode and one in safe mode. SORRY!!!! ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 12:45:37 AM 8/4/2006 + Scan result: C:\Documents and Settings\ABray\Local Settings\Temp\Tspd.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\WINDOWS\system32\ddpdieed.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\WINDOWS\system32\eagfngik.dll -> Adware.Agent : Cleaned with backup (quarantined). C:\WINDOWS\system32\advert.dll -> Adware.Aureate : Cleaned with backup (quarantined). C:\WINDOWS\system32\nodeipproc.dll -> Adware.BHO : Cleaned with backup (quarantined). C:\Program Files\Batty\Batty.exe -> Adware.CASClient : Cleaned with backup (quarantined). C:\WINDOWS\system32\xrefc27a.dll -> Adware.IEHelper : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\temp.fr62B6 -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\azaslg1716.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\enp6l17s1.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\h00qlad51d0.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\hr8u05l9e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\k0nola531d.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\k4no0e53eh.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\k6jslg1716.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\k8800ilme8qa0.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\lv4609hse.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\lvp4097qe.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\lvps0977e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\lvrq0995e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\mv42l9ho1.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\C9A72.tmp/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined). C:\WINDOWS\System32bez6n4r21.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined). C:\WINDOWS\system32\bez6n4r21.exe -> Adware.SearchAssistant : Cleaned with backup (quarantined). [2180] C:\WINDOWS\System32\cvn0.exe -> Adware.SearchAssistant : Error during cleaning. C:\Documents and Settings\ABray\Local Settings\Temp\C9A72.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\System32n9nyb.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32\__delete_on_reboot__x_e_y_m_i_._d_l_l_ -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32\xeymi.dll -> Adware.Suggestor : Cleaned with backup (quarantined). [2612] C:\WINDOWS\System32\xeymi.dll -> Adware.Suggestor : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\i86.tmp -> Adware.SurfSide : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\iCE.tmp -> Adware.SurfSide : Cleaned with backup (quarantined). C:\Program Files\webHancer\Programs\__delete_on_reboot__w_e_b_h_d_l_l_._d_l_l_ -> Adware.WebHancer : Cleaned with backup (quarantined). C:\Program Files\webHancer\Programs\__delete_on_reboot__w_h_i_e_h_l_p_r_._d_l_l_ -> Adware.WebHancer : Cleaned with backup (quarantined). C:\Program Files\webHancer\Programs\whinstaller.exe -> Adware.WebHancer : Cleaned with backup (quarantined). C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup (quarantined). C:\Program Files\whInstall\license.txt -> Adware.Webhancer : Cleaned with backup (quarantined). C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : Cleaned with backup (quarantined). C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj.1 -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\WhIeHelperObj.WhIeHelperObj\CurVer -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\webHancer Agent -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\webhancer -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\webhancer\CC -> Adware.WebHancer : Cleaned with backup (quarantined). HKLM\SOFTWARE\webhancer\ESO -> Adware.WebHancer : Cleaned with backup (quarantined). [3060] C:\Program Files\webHancer\Programs\webhdll.dll -> Adware.WebHancer : Error during cleaning. C:\WINDOWS\system32\ZICORN003.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\1747\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\18641\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\22292\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\22773\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\25395\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\28673\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\8801\2236.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\WINDOWS\system32\2236_27.dll -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\WINDOWS\temp\ntmihoda.exe -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\WINDOWS\system32\mscdaux.dll -> Backdoor.Delf.aml : Cleaned with backup (quarantined). C:\WINDOWS\system32\__delete_on_reboot__a_s_p_i_2_5_7_5_7_._e_x_e_ -> Backdoor.Rbot.bei : Cleaned with backup (quarantined). C:\WINDOWS\system32\aspi252807.exe -> Backdoor.Rbot.bei : Cleaned with backup (quarantined). C:\dist13.exe -> Downloader.Agent.aaf : Cleaned with backup (quarantined). C:\WINDOWS\system32\dmonwv.dll_tobedeleted -> Downloader.Agent.agw : Cleaned with backup (quarantined). C:\fym9bvo.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined). C:\WINDOWS\temp\44.tmp -> Downloader.Agent.aox : Cleaned with backup (quarantined). C:\WINDOWS\temp\4C.tmp -> Downloader.Agent.aox : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\ac2_0006.exe -> Downloader.Small.cpu : Cleaned with backup (quarantined). C:\WINDOWS\temp\vx4.game -> Downloader.Small.ctk : Cleaned with backup (quarantined). C:\WINDOWS\system32\testtestt.exe -> Downloader.Small.cyb : Cleaned with backup (quarantined). C:\WINDOWS\temp\vxt3.game -> Downloader.Small.cyb : Cleaned with backup (quarantined). C:\ac3_0003.exe -> Downloader.Small.cyh : Cleaned with backup (quarantined). C:\WINDOWS\temp\6.dlb -> Downloader.Small.dht : Cleaned with backup (quarantined). C:\WINDOWS\temp\7.dlb -> Downloader.Small.dht : Cleaned with backup (quarantined). C:\WINDOWS\temp\vx3.game -> Downloader.Small.diy : Cleaned with backup (quarantined). C:\WINDOWS\system32\sys32.exe -> Downloader.Small.djr : Cleaned with backup (quarantined). C:\WINDOWS\system32\kernels8.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined). C:\WINDOWS\temp\2.dlb -> Downloader.Tibs.gc : Cleaned with backup (quarantined). C:\WINDOWS\temp\vxt2.game -> Downloader.Tibs.gc : Cleaned with backup (quarantined). C:\WINDOWS\temp\win32.exe -> Downloader.Tibs.gc : Cleaned with backup (quarantined). C:\WINDOWS\temp\qvxt3.game -> Downloader.Tiny.ap : Cleaned with backup (quarantined). C:\Program Files\Common Files\iouz\iouzp.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined). C:\Program Files\Common Files\iouz\__delete_on_reboot__i_o_u_z_a_._e_x_e_ -> Downloader.TSUpdate.l : Cleaned with backup (quarantined). [3324] C:\PROGRA~1\COMMON~1\iouz\iouza.exe -> Downloader.TSUpdate.l : Error during cleaning. C:\Program Files\Common Files\iouz\iouzl.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined). C:\WINDOWS\__delete_on_reboot__w_i_n_3_2_0_9_8_1_8_2_5_2_8_9_3_6_._e_x_e_ -> Downloader.VB.aga : Cleaned with backup (quarantined). C:\kybrdef_7.exe -> Downloader.VB.air : Cleaned with backup (quarantined). C:\WINDOWS\offun.exe -> Downloader.VB.nw : Cleaned with backup (quarantined). C:\visfx500new.exe -> Dropper.Agent.aie : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\pre.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined). C:\webnexmknew.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined). C:\626_101newer.exe -> Dropper.Agent.mu : Cleaned with backup (quarantined). C:\Program Files\iPass\Sprint Remote Access\idialer.exe -> Heuristic.Win32.Dialer : Ignored. C:\RECYCLER\S-1-5-21-1833908083-351470168-689510791-2798\Dc481.exe -> Hijacker.Small : Cleaned with backup (quarantined). C:\WINDOWS\temp\nxmczion.exe -> Hijacker.Small.cc : Cleaned with backup (quarantined). C:\Program Files\MSN\pono.html -> Hijacker.Small.jf : Cleaned with backup (quarantined). C:\Program Files\Windows NT\meleci.html -> Hijacker.Small.jf : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\drsmartload180a.exe -> Hijacker.VB.fg : Cleaned with backup (quarantined). C:\__delete_on_reboot__d_f_n_d_r_f_f___7_._e_x_e_ -> Hijacker.VB.ly : Cleaned with backup (quarantined). C:\dfndref_7.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined). C:\dfndrff_7.exe -> Hijacker.VB.ly : Cleaned with backup (quarantined). [2304] C:\dfndrff_7.exe -> Hijacker.VB.ly : Error during cleaning. C:\WINDOWS\system32\ipod.raw.exe -> Proxy.Lager.bz : Cleaned with backup (quarantined). :mozilla.127:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.105:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.112:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.176:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.19:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.20:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.21:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.22:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.23:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.24:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.25:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.26:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.27:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.28:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.29:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.30:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.31:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.32:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.33:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.35:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.36:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.38:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.39:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.40:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.41:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.42:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.43:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.71:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.72:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.73:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.74:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.75:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.76:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.77:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.78:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.79:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.80:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.81:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.82:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.83:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.84:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.8:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : Cleaned. :mozilla.600:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.601:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.142:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.226:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.227:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.228:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.229:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.230:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.475:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.476:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.477:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.478:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.479:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.480:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.481:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.482:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.483:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.484:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.797:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.782:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.783:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.784:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.785:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.786:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.787:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.788:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.789:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.151:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.152:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Adtech : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned. :mozilla.14:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.15:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.15:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.16:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.16:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.17:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.18:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.18:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.19:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.242:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Adviva : Cleaned. :mozilla.19:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.21:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.22:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.280:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.56:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.264:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. :mozilla.21:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.220:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.795:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.205:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.48:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.49:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.50:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.51:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.214:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Centrport : Cleaned. :mozilla.215:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Centrport : Cleaned. :mozilla.119:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.21:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.225:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Com : Cleaned. :mozilla.226:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Com : Cleaned. :mozilla.10:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.11:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.12:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.21:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-2.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.22:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.9:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.19:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.20:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.75:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.251:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.252:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.253:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.254:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.255:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.256:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.257:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.258:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.259:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.260:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.261:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.262:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.263:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.264:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.265:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.266:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.267:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.268:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.269:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.270:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.271:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.272:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.273:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.274:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.275:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.276:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.277:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.278:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.279:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.280:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.281:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.282:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.283:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.284:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.285:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.286:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.287:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.288:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.289:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.290:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.291:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.292:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.293:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.294:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.295:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.295:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.296:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.297:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.298:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.299:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.300:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.301:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.302:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.303:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.304:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.305:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.306:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.307:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.308:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.309:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.310:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.311:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.312:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.313:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.314:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.315:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.316:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.317:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.318:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.319:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.320:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.321:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.322:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.323:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.324:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.325:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.326:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.327:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.328:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.329:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.330:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.331:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.332:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.333:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.334:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.335:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.336:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.337:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.338:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.339:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.340:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.341:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.342:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.343:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.344:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.345:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.346:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.347:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.348:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.349:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.350:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.351:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.352:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.353:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.354:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.355:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.356:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.357:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.358:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.359:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.360:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.361:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.243:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.244:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.245:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.246:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.171:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.22:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.23:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.24:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.25:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.26:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.27:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.86:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.87:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.88:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.89:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Falkag : Cleaned. :mozilla.17:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.18:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-4.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.63:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.64:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned. :mozilla.172:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.126:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.127:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.128:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.177:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.179:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.216:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.225:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles&
:mozilla.225:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.240:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.241:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.605:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.606:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.607:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.614:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.615:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.616:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.617:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.618:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.619:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.800:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.801:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.423:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.18:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.66:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.635:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.636:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Onestat : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Onestat : Cleaned. :mozilla.107:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.549:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@overture[1].txt -> TrackingCookie.Overture : Cleaned. :mozilla.146:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.147:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.148:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.149:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.67:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.68:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.69:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.70:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.564:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pro-market : Cleaned. :mozilla.565:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Pro-market : Cleaned. :mozilla.28:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.29:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.30:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.31:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.570:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@revenue[1].txt -> TrackingCookie.Revenue : Cleaned. :mozilla.145:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.146:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.147:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.148:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.149:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.150:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.151:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.372:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned. :mozilla.157:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.158:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.159:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.160:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.203:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.621:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.622:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.623:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.624:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.625:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned. :mozilla.27:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.28:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-3.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.68:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.69:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.6:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-2.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.70:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.71:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.72:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.73:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.110:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.111:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.113:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.202:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.129:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.663:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.118:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.119:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.120:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.121:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.122:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.123:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.124:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.76:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.79:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.80:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.81:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.82:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.83:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.84:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.85:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.108:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.113:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.115:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.380:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.381:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Valuead : Cleaned. :mozilla.671:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.767:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.768:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.161:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.777:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.778:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.100:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.101:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.102:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.103:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.104:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.105:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.106:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.107:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.108:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.109:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.60:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.61:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.62:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.90:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.91:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.92:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.93:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.94:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.95:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.96:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.98:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.99:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.19:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-2.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.284:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.285:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.286:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.790:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.791:C:\Documents and Settings\ABray\Application Data\Mozilla\Firefox\Profiles\0oipzglg.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\system32\redist.dll -> Trojan.Agent.sx : Cleaned with backup (quarantined). C:\WINDOWS\system32\redistributor.exe -> Trojan.Agent.sx : Cleaned with backup (quarantined). C:\WINDOWS\system32\winup.dll -> Trojan.Hooker.52 : Cleaned with backup (quarantined). C:\WINDOWS\temp\42.tmp -> Trojan.OpenPort.c : Cleaned with backup (quarantined). C:\WINDOWS\temp\47.tmp -> Trojan.OpenPort.c : Cleaned with backup (quarantined). C:\WINDOWS\temp\49.tmp -> Trojan.OpenPort.c : Cleaned with backup (quarantined). C:\WINDOWS\temp\4D.tmp -> Trojan.OpenPort.c : Cleaned with backup (quarantined). C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.dll -> Trojan.Sinowal.ae : Cleaned with backup (quarantined). C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00002.dll -> Trojan.Sinowal.ae : Cleaned with backup (quarantined). C:\WINDOWS\temp\msn.exe -> Trojan.Sinowal.ae : Cleaned with backup (quarantined). C:\WINDOWS\uni_eh.exe -> Trojan.VB.tg : Cleaned with backup (quarantined). C:\WINDOWS\unin101.exe -> Trojan.VB.tg : Cleaned with backup (quarantined). ::Report end
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 7:35:50 AM 8/4/2006 + Scan result: C:\quarantine\mmxsnet.exe.Vir -> Adware.MediaMotor : Error during cleaning. C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : Cleaned with backup (quarantined). C:\WINDOWS\system32\2236_28.dll -> Backdoor.Agent.adr : Cleaned with backup (quarantined). C:\kybrdff_7.exe -> Downloader.Adload.dl : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\Local Settings\Temp\!update.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined). C:\Documents and Settings\ABray\My Documents\Tаsks\dllhost.exe -> Downloader.PurityScan.cu : Cleaned with backup (quarantined). C:\WINDOWS\temp\42.tmp3072.exe -> Downloader.Small.dcj : Cleaned with backup (quarantined). C:\numbsoftnew.exe -> Dropper.Agent.hl : Cleaned with backup (quarantined). C:\Program Files\iPass\Sprint Remote Access\idialer.exe -> Heuristic.Win32.Dialer : Ignored. C:\Documents and Settings\ABray\Local Settings\Temporary Internet Files\Content.IE5\KCDHRYN0\popup[2].php -> Hijacker.Agent.a : Cleaned with backup (quarantined). C:\quarantine\pre.exe.Vir -> Hijacker.VB.lb : Error during cleaning. C:\quarantine\pre[1].exe.Vir -> Hijacker.VB.lb : Error during cleaning. C:\Documents and Settings\ABray\Local Settings\Temporary Internet Files\Content.IE5\6NXGYH7N\dfndrff_7[1].exe -> Hijacker.VB.ly : Cleaned with backup (quarantined). C:\quarantine\vx1.game.Vir -> Proxy.Xorpix.u : Error during cleaning. C:\quarantine\vx1.game.Vir.0 -> Proxy.Xorpix.u : Error during cleaning. C:\Documents and Settings\ABray\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\ABray\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\ABray\Cookies\abray@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\quarantine\system.exe.Vir -> Trojan.Delf.lm : Error during cleaning. ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 7:41:25 AM, on 8/4/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\SLClient.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\SSC Service Utility\ssc_serv.exe
C:\WINDOWS\System32\wfxqhv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
C:\Program Files\Cirond\Cirond Winc\Winc.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireTray.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\TClock\TClock.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\ABray\Desktop\hijackthis\HijackThis.exe
C:\DOCUME~1\ABray\LOCALS~1\Temp\!update.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.findthewebsiteyouneed.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://my.netzero.net/s/sp?r=al&cf=sp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.mrfindalot.com/search.asp?si=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://www.mrfindalot.com/search.asp?si=
R3 - Default URLSearchHook is missing
O2 - BHO: WhIeHelperObj Class - {c900b400-cdfe-11d3-976a-00e02913a9e0} - C:\Program Files\webHancer\programs\whiehlpr.dll (file missing)
O2 - BHO: Ozbyq Class - {D623BC2F-A58D-4A75-A10D-CC244A702A35} - C:\WINDOWS\System32\xeymi.dll
O2 - BHO: (no name) - {E5E2A3E7-00FE-4D31-A030-A10799DDCA66} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: MyWiki toolbar - {e22e8d11-0f3e-4d46-8fc1-7264b4d5ea01} - C:\Program Files\MyWiki\tbMyW1.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\TBMon.exe"
O4 - HKLM\..\Run: [PRONoMgrWired] C:\Program Files\Intel\PROSetWired\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [EPHD User] "C:\Program Files\PC Guardian\EP Hard Disk\User\LaunchEPHD.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [LapLink Scheduler] C:\Program Files\Common Files\LapLink\Scheduler\llsched.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /s
O4 - HKLM\..\Run: [k6mmN5IOU] "C:\WINDOWS\System32\wfxqhv.exe"
O4 - HKLM\..\Run: [TheMonitor] C:\WINDOWS\SYSC00.exe
O4 - HKLM\..\Run: [xrefc27a] RUNDLL32.EXE w1547363.dll,n 001fc279000000031547363
O4 - HKLM\..\Run: [w54763df.dll] RUNDLL32.EXE w54763df.dll,I2 001fc279054763df
O4 - HKLM\..\Run: [webHancer Agent] C:\Program Files\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [webHancer Survey Companion] C:\Program Files\webHancer\Programs\whsurvey.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /M "Stylus Photo R300" /EF "HKCU"
O4 - HKCU\..\Run: [Ylpqwgwa] C:\Documents and Settings\ABray\Application Data\a?sembly\w?wexec.exe
O4 - HKCU\..\Run: [iouz] C:\PROGRA~1\COMMON~1\iouz\iouzm.exe
O4 - HKCU\..\Run: [CAS2] "C:\Program Files\System Files\System.exe"
O4 - HKCU\..\Run: [TClock.exe] C:\Program Files\TClock\tclock_install.exe
O4 - HKCU\..\Run: [shell] "C:\Program Files\Common Files\Microsoft Shared\Web Folders\ibm00001.exe"
O4 - HKCU\..\Run: [Ltap] "C:\DOCUME~1\ABray\MYDOCU~1\TSKS~1\dllhost.exe" -vt ndrv
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\lwinmpez.exe
O4 - Startup: Z_Start.lnk = C:\WINDOWS\system32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Cirond Winc.lnk = C:\Program Files\Cirond\Cirond Winc\Winc.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: McAfee Desktop Firewall Tray.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O14 - IERESET.INF: START_PAGE_URL=http://my.netzero.net/s/sp?r=al&cf=sp
O15 - Trusted Zone: *.mdmgr.net
O15 - Trusted Zone: *.webmd.net
O15 - Trusted Zone: *.webmdps.net
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://appldnld.m7z.net/content.info.apple…iTunesSetup.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by107fd.bay107.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970307654
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1139970297249
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BAC01377-73DD-4796-854D-2A8997E3D68A} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…ropper1_6us.cab
O16 - DPF: {C130F0B3-CD97-4DFC-B052-2BD17A7B82F5} (Yahoo! Photos Print-at-Home Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/…printathome.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A4262072-BAB4-4CA9-9581-CEF306DC8616}: Domain = mmrd.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = mmrd.com,hs.mdmgr.net,atl.healtheon.com,envoy.net,healtheon.com,mdmgr.net,mdmgrse.com,mmnsonline.com,na.webmd.net,webmd.com,webmd.net,webmdps.net
O18 - Filter: text/html - {B5F86455-BF18-4E12-965A-6642A0AC0549} - C:\WINDOWS\System32\xeymi.dll
O21 - SSODL: DCOM Server 2236 - {2C1CD3D7-86AC-4068-93BC-A02304BB2236} - C:\WINDOWS\System32\2236_28.dll (file missing)
O23 - Service: Microsoft ASPI Manager (aspi113210) - Unknown owner - C:\WINDOWS\System32\aspi25757.exe (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: EphdXlatService - Unknown owner - C:\Program Files\PC Guardian\EP Hard Disk\User\DISrv.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee Desktop Firewall Service (FireSvc) - Networks Associates Technology, Inc. - C:\Program Files\Network Associates\McAfee Desktop Firewall for Windows XP\FireSvc.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PCG Protect - PC Guardian - C:\Program Files\PC Guardian\EP Hard Disk\User\PCGProt.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: ScriptLogic Service (SLClient) - ScriptLogic Corporation - C:\WINDOWS\System32\SLClient.exe
That looks better :thumbup:

With Ewido 4, if you click on the Infections icon, then it will show you all the items in Quarrantine and you can remove them that way. Just click Select All then Remove Finally

Next:
Please go HERE and do a online scan.
Let me know what is found.

After scan, reboot and post a new HijackThis log

Also let me know how the computer is running now.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI