This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Cant change homepage.....cant access a website

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I ca not change my home page..and i cant access a specific website(but i can ping it from the command prompt)
Logfile of HijackThis v1.99.1
Scan saved at 12:05:42 AM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\SYSTEM32\taskmgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\SYSTEM32\CALC.EXE
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Richard Newth\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dfwstangs.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IW_ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - Startup: TASKMGR.lnk = C:\WINDOWS\SYSTEM32\taskmgr.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm824BCUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129245801871
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1129245792371
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {F5078F32-C551-11D3-89B9-0000F81FE221} (XML DOM Document 3.0) - file://C:\Program Files\MUSICMATCH\MUSICMATCH Update\MMJB\msxml3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe (file missing)
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
Hello cobra93teal and Welcome to TomCoyote,

You have hijackthis.exe in a temporary folder \Temp\. Please move it to a permanent folder so that we have backup of entries made when we use it to fix items.

Let's start with some scans to check for malware:

STEP 1.
======
SpySweeper
Download the trial version of Spy Sweeper from Here

Install it using the Standard Install option. (You will be asked for your e-mail address, it is safe to give it. If you receive alerts from your firewall, allow all activities for Spy Sweeper)

If you are taken to the internet page, just close the page.

You will be prompted to check for updated definitions, please do so.
(This may take several minutes)

Click on Options > Sweep Options and check Sweep all Folders on Selected drives. Check Local Disc C. Under What to Sweep, check every box.

Click on Sweep and allow it to fully scan your system.If you are prompted to restart the computer, do so immediately. This is a necessary step to kill the infection!

When the sweep has finished, click Remove. Click Select All and then Next

From 'Results', select the Session Log tab. Click Save to File and save the log somewhere convenient.


STEP 2.
======
The Ewido program’s detection rate is excellent. After the Trial has expired, the auto updates and real time protection stop but you can still update it manually and run scans anytime you want.

First download ewido anti-spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded ewido anti-spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close ewido anti-spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while ewido is scanning, it may interfere with the scanning proccess:
  • Lauch ewido-anti-spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close ewido and reboot your system back into Normal Mode and post the
    results of the ewido report scan.
Empty Recycle Bin
Reboot

Please post the results from SpySweeper, ewido and a new hijackthis log.
ok ran both…hijack this is not temp anymore…
———————————————————
ewido anti-spyware - Scan Report
———————————————————

+ Created at: 11:02:50 AM 8/12/2006

+ Scan result:



G:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP544\A0020430.exe -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Newth\Local Settings\Temp\NewE.tmp\upg_dll.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Newth\Local Settings\Temp\NewE.tmp\upgrade.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc11.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc65.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc66.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc67.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Desktop\NNuninstall.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Local Settings\Temp\NewE.tmp\upg_dll.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Local Settings\Temp\NewE.tmp\upgrade.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Newth\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-458275fd-25a9760b.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loader.jar-458275fd-25a9760b.zip/Dummy.class -> Not-A-Virus.Exploit.ByteVerify : Cleaned with backup (quarantined).
:mozilla.142:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.143:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined).
:mozilla.100:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.101:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.103:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.104:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.105:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.106:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.107:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.108:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.109:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.110:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.111:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.112:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.113:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.279:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.378:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.397:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.441:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.505:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.537:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.596:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.61:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.626:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.629:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.64:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.65:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.68:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.69:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.70:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.71:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.758:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.76:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.78:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.79:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.80:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.81:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.82:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.83:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.84:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.85:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.86:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.87:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.88:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.89:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.90:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.91:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.93:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.94:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.95:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.96:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.97:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.98:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.99:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.164:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.165:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.166:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined).
:mozilla.178:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined).
:mozilla.125:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.126:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.127:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup (quarantined).
:mozilla.177:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.899:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.900:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.901:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.902:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.903:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined).
:mozilla.183:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.184:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined).
:mozilla.26:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.273:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined).
:mozilla.38:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.35:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.36:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.37:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.266:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup (quarantined).
:mozilla.294:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.295:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.296:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.297:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined).
:mozilla.282:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@com[2].txt -> TrackingCookie.Com : Cleaned with backup (quarantined).
:mozilla.288:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.289:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.290:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.291:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.39:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.333:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.334:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.335:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.336:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.337:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.338:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.339:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.340:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.341:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.342:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.343:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.344:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.345:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.346:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.347:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.348:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.349:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.350:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined).
:mozilla.171:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
C:\Documents and Settings\Richard Newth\Cookies\richard [removed][1].txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined).
:mozilla.222:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.223:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.224:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.225:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined).
:mozilla.935:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined).
:mozilla.910:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.911:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.912:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined).
:mozilla.893:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined).
:mozilla.117:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.676:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.677:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
:mozilla.685:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned with backup (quarantined).
:mozilla.179:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.180:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.181:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.182:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined).
:mozilla.703:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.704:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup (quarantined).
:mozilla.707:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.708:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.709:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.361:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.362:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.363:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.364:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined).
:mozilla.255:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.767:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.768:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.769:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.770:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined).
:mozilla.172:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.173:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.174:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.175:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.176:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.781:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.782:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.783:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.784:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.785:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.786:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.787:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.788:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.789:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.790:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.791:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.792:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.793:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.794:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.795:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.796:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.40:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined).
:mozilla.816:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined).
:mozilla.817:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.818:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.819:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.820:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.821:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.822:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.823:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.824:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.825:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined).
:mozilla.122:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.123:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.128:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.729:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.730:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.731:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.732:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.733:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined).
:mozilla.244:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup (quarantined).
:mozilla.853:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.854:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@yadro[2].txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined).
:mozilla.22:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
G:\Documents and Settings\Richard Newth\Cookies\richard newth@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.863:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.864:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.865:C:\Documents and Settings\Richard Newth\Application Data\Mozilla\Firefox\Profiles\8rpkn5ub.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc144.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc145.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc146.zip/Setup.exe -> Worm.VB.an : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1855790860-2883164373-3959644054-1007\Dc148.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined).


::Report end


spy sweeper found 2 things
NAVEXCEL
and some cursor thing… sorry cant find report
Logfile of HijackThis v1.99.1
Scan saved at 11:40:55 AM, on 8/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\WINDOWS\SYSTEM32\taskmgr.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Richard Newth\Desktop\This.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat

6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program

Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe
O4 - HKLM\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - HKLM\..\Run: [VOBID] C:\Program Files\Pinnacle\InstantCDDVD\\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [IW_ControlCenter] C:\Program Files\Pinnacle\InstantCDDVD\InstantWrite\iwctrl.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [SP2 Connection Patcher] "C:\Program Files\SP2 Connection Patcher\SP2ConnPatcher.exe" -n=200
O4 - HKCU\..\Run: [SP2ConnPatcher] "C:\Program Files\SP2 Connection Patcher\sp2connpatcher.exe" -n=200
O4 - HKCU\..\Run: [AWMON] "C:\PROGRA~1\Lavasoft\AD-AWA~2\Ad-Watch.exe"
O4 - Startup: TASKMGR.lnk = C:\WINDOWS\SYSTEM32\taskmgr.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm824BCUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program

Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - blank (file missing)
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) -

http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) -

http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -

http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -

https://www-secure.symantec.com/techsupp/as…rl/LSSupCtl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -

http://update.microsoft.com/microsoftupdat…b?1129245801871
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -

http://update.microsoft.com/microsoftupdat…b?1129245792371
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -

http://messenger.zone.msn.com/binary/Messe…StatsClient.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) -

https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -

http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -

https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {F5078F32-C551-11D3-89B9-0000F81FE221} (XML DOM Document 3.0) - file://C:\Program

Files\MUSICMATCH\MUSICMATCH Update\MMJB\msxml3.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Automatic LiveUpdate Scheduler - Unknown owner - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe

(file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network

Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network

Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network

Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner -

%ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.
Open notepad and copy and paste next bold in it:

regedit /e peek1.txt "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies"
regedit /e peek2.txt "HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components"
regedit /e peek3.txt "HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main"
regedit /e peek4.txt "HKEY_ LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main"
regedit /e peek5.txt "HKEY_USERS\Default\Software\Microsoft\Internet Explorer\Main"
type peek1.txt >> look.txt
type peek2.txt >> look.txt
type peek3.txt >> look.txt
type peek4.txt >> look.txt
type peek5.txt >> look.txt
del peek*.txt
start notepad look.txt


Save this as look.bat , choose to save as *all files and place it on your desktop.
Doubleclick look.bat
Notepad will open with some txt in it. Copy and paste the contents in your next reply.
Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "DisableRegistryTools"=dword:00000000 Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000002 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,de,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,04,00,00,00 "RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\ 00,00,01,00,00,00 Windows Registry Editor Version 5.00 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main] "NoUpdateCheck"=dword:00000000 "NoJITSetup"=dword:00000000 "Disable Script Debugger"="yes" "Show_ChannelBand"="No" "Anchor Underline"="yes" "Cache_Update_Frequency"="Once_Per_Session" "Display Inline Images"="yes" "Do404Search"=hex:01,00,00,00 "Local Page"="C:\\WINDOWS\\system32\\blank.htm" "Save_Session_History_On_Exit"="no" "Show_FullURL"="no" "Show_StatusBar"="yes" "Show_ToolBar"="yes" "Show_URLinStatusBar"="yes" "Show_URLToolBar"="yes" "Start Page"="about:blank" "Use_DlgBox_Colors"="yes" "Search Page"="http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch" "Default_Page_URL"="http://www.dell4me.com/myway" "FullScreen"="no" "Window_Placement"=hex:2c,00,00,00,00,00,00,00,01,00,00,00,ff,ff,ff,ff,ff,ff,\ ff,ff,ff,ff,ff,ff,ff,ff,ff,ff,d9,00,00,00,a6,00,00,00,86,04,00,00,b5,03,00,\ 00 "Use FormSuggest"="no" "NotifyDownloadComplete"="yes" "AddToFavoritesExpanded"=dword:00000000 "Error Dlg Displayed On Every Error"="no" "Error Dlg Details Pane Open"="no" "AutoSearch"=dword:00000005 "Enable Browser Extensions"="yes" "ShowGoButton"="yes" "HistoryTopNSitesView"=dword:00000014 "HistoryViewType"=hex:00,00 "Expand Alt Text"="no" "Move System Caret"="no" "NscSingleExpand"=dword:00000001 "DisableScriptDebuggerIE"="yes" "NoWebJITSetup"=dword:00000000 "Page_Transitions"=dword:00000001 "FavIntelliMenus"="no" "UseThemes"=dword:00000001 "Force Offscreen Composition"=dword:00000000 "AllowWindowReuse"=dword:00000001 "Friendly http errors"="yes" "SmoothScroll"=dword:00000001 "Enable AutoImageResize"="yes" "Enable_MyPics_Hoverbar"="yes" "Play_Animations"="yes" "Play_Background_Sounds"="yes" "Display Inline Videos"="yes" "Show image placeholders"=dword:00000000 "Print_Background"="no" "LastCheckedHi"=dword:01c6b44b "ShowedCheckBrowser"="Yes" "Check_Associations"="No" "Search Bar"="http://ie.search.msn.com/{sub_rfc1766}/srchasst/srchasst.htm" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN] "iexplore.exe"=dword:00000001 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\Settings] "LOCALMACHINE_CD_UNLOCK"=dword:00000000
Please do the following:

STEP 1.
======
Uninstall Manager

Let's see if we can find out what it got installed with.
  • Open HijackThis
  • Click on the configure button on the bottom right
  • Click on the tab "Misc Tools"
  • Click on the Box that says "Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from notepad into your next reply.
STEP 2.
======
WinPFind
Please Download the following tools to assist us in removing this infection! Download WinPFind from http://www.bleepingcomputer.com/files/winpfind.php
  • Right Click the Zip Folder and Select Extract All
  • Extract it somewhere you will remember like the Desktop
  • Don’t do anything with it yet!
Reboot.
When the machine first starts again it will generally list some equipment that is installed in your machine, amount of memory, hard drives installed etc. At this point you should gently tap the F8 key repeatedly until you are presented with a Windows XP Advanced Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode

  • Doubleclick WinPFind.exe
  • Click on Configure Scan Options.
  • Remove all the checkmarks under Folder Options on the left side by clicking the button Remove All, uncheck Run Addon's and click Apply.
  • Click Start Scan
    It will scan the entire System, so please be patient! This scan may take awhile
Once the Scan is Complete
  • Reboot your computer into normal mode.
  • Go to the WinPFind folder
  • Locate WinPFind.txt
  • Copy the results from the WinPFind.txt file and post the results in your next reply.

Please be sure you replied with the Uninstall manager log, and the information WinPFind.txt.

Are you still experiencing problems or did the SpySweeper and ewido change anything?
yup just one www.dfwstangs.net i know the site is up…and i talked to the webmaster and my ip is not blocked(but i still got a new ip) driving me nuts!
Yes I could bring it up in both Firefox and IE. Cars and not horses! Now I understand the cobra in your id! Do you receive any kind of message when you try to access it?
The page cannot be displayed The page you are looking for is currently unavailable. The Web site might be experiencing technical difficulties, or you may need to adjust your browser settings. ——————————————————————————– Please try the following: Click the Refresh button, or try again later. If you typed the page address in the Address bar, make sure that it is spelled correctly. To check your connection settings, click the Tools menu, and then click Internet Options. On the Connections tab, click Settings. The settings should match those provided by your local area network (LAN) administrator or Internet service provider (ISP). See if your Internet connection settings are being detected. You can set Microsoft Windows to examine your network and automatically discover network connection settings (if your network administrator has enabled this setting). Click the Tools menu, and then click Internet Options. On the Connections tab, click LAN Settings. Select Automatically detect settings, and then click OK. Some sites require 128-bit connection security. Click the Help menu and then click About Internet Explorer to determine what strength security you have installed. If you are trying to reach a secure site, make sure your Security settings can support it. Click the Tools menu, and then click Internet Options. On the Advanced tab, scroll to the Security section and check settings for SSL 2.0, SSL 3.0, TLS 1.0, PCT 1.0. Click the Back button to try another link. Cannot find server or DNS Error Internet Explorer
Let's try the following and see if this helps.

STEP 1.
======
Part 1: Optimize Internet Explorer
By optimizing Internet Explorer, you can clear old files and settings that may be causing conflicts and may be preventing you from connecting to the Internet. To optimize Internet Explorer, follow these steps:
1. In Internet Explorer, click Tools, and then click Internet Options.
2. Click the General tab.
3. Under Temporary Internet files, click Delete Files.
4. Click to select the Delete all offline content check box, and then click OK.
5. Click Delete Cookies. When you are prompted to confirm this selection, click OK.
6. Click Settings.
7. Click View Objects.
8. Click View, and then click Details.
9. If Damaged appears in the Status column for any program file, remove that program file.
10. Close the Downloaded Program Files dialog box.
11. In the Settings dialog box, click OK .
12. Under History, click Clear History, and then click Yes when you are prompted to confirm the selection.
13. In the Internet Options dialog box, click OK.
14. Try to browse the Internet.

STEP 2.
======
DelDomains

Download this file to your desktop.
http://www.mvps.org/winhelp2002/DelDomains.inf

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection

STEP 3.
======
Hoster

Please download hoster.
  • Unzip Hoster.zip
  • Open Hoster.exe.
  • Then click on "Restore Original Hosts"
  • Close program when complete.
  • Empty Recycle Bin
Please let me know if this clears up your problem.
Let's try this: check after each step- one may fix it.

STEP 1.
======
Reset Winsock

Please try the following:
1. Click Start, click Run, type netsh winsock reset, and then click OK.
2. When the Command Prompt flashes, restart the computer.

Warning Programs that access or monitor the Internet, such as antivirus programs, firewall programs, and proxy clients, may be negatively affected when you run the netsh winsock reset command. If you have a program that no longer functions correctly after you follow these steps, reinstall the program.

STEP 2.
======
New or Different User Account

Try logging on as a different user and see if you can access the website. Or create a new user account if you need to try this.For more information about how to do this, click the following article number to view the article in the Microsoft Knowledge Base:
279783 (http://support.microsoft.com/kb/279783/) How to create and configure user accounts in Windows XP
http://support.microsoft.com/kb/279783/

STEP 3.
======
System File Checker

start > Run > copy and paste in the bold: (there is a space between the sfc and the /)
sfc /scannow
Click 'OK'
You will need your XP/2000/ME disk. If you don't have it and instead only have a recovery CD, there is a work around. View the following link for a tutorial:

http://www.updatexp.com/scannow-sfc.html

sfc - system file checker, retrieves the correct version of the file from %Systemroot%\System32\Dllcache or the Windows installation source files, and then replaces the incorrect file.

If you want to see what was replaced, right click My Computer > manage, expand event viewer > system.

Let me know if anything helped.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI