This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

please check log

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I got spyware again and I need help getting rid of it. Please help.

Logfile of HijackThis v1.99.1
Scan saved at 11:43:06 PM, on 08/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
D:\Program Files\Valve\Steam\Steam.exe
D:\Program Files\Hijack This\HijackThis[1].exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.excite.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Documents and Settings\Tonia\Favorites\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: @Home - {2BF1D1A7-5E21-4B1B-9FF2-B895EF933D15} - http://home.excite.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.excite.com/
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37390.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
a_dim_wit,

We meet again :D

Open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=:0





  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous (jre) installations.
  • Reboot your system.
  • Then go to the Sun Java website and download and install the update.
  • Java Runtime Environment (JRE) 5.0 Update 8 <–This is what you need to download and install.
  • Then after install you can verify your installation here Sun Java Verify



The rest of your log looks ok, what specific issues are you having????
When I posted the log I had a lot of trouble using the internet. It would only stay connected for about 15 minutes and then disconnect. I scanned my computer with Ewido and it found a lot of spyware and it would come back after a few hours. Now the internet still disconnects but only after an hour.

Here's another log

Logfile of HijackThis v1.99.1
Scan saved at 9:51:38 AM, on 08/19/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
D:\Program Files\Hijack This\HijackThis[1].exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.excite.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\npjpi150_08.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: @Home - {2BF1D1A7-5E21-4B1B-9FF2-B895EF933D15} - http://home.excite.com (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://home.excite.com/
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37390.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido security suite control - ewido networks - D:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Still not looking at anything bad on your log, remove these with HJT.

O9 - Extra button: @Home - {2BF1D1A7-5E21-4B1B-9FF2-B895EF933D15} - http://home.excite.com (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://home.excite.com/



Run Ewido in Safemode and let me see the report. Run it this way.

* Once you have downloaded Ewido Anti-Spyware, locate the icon on the desktop and double-click it to launch the set up program.
* Once the setup is complete you will need run Ewido and update the definition files.
* On the main screen select the icon Update then select the Update now link.
* Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
* Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
* Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
* Under Reports
* Select Automatically generate report after every scan
* Un-Select Only if threats were found
* Close Ewido Anti-Spyware <– Do not run the scan yet.

Boot your computer into Safemode

* Go to Start> Shut Off your Computer> Restart
* As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
this will bring up a menu.
* Use the Up and Down Arrow Keys to scroll up to SAFEMODE
* Then press the Enter on your Keyboard

IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning proccess:

* Lauch Ewido-Anti-Spyware by double-clicking the icon on your desktop.
* Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
* Ewido will now begin the scanning process, be patient this may take a little time.
* Once the scan is complete do the following:
* If you have any infections you will prompted, then select Apply all actions
* Next select the Reports icon at the top.
* Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
*** make sure to remember where you saved that file, this is important
* Close Ewido



Then run Blacklight to see if it picks up any bad files.

Download and Save Blacklight to your desktop:

Double-click blbeta.exe then accept the agreement, leave [X]scan through Windows Explorer checked, click > scan then > next

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"



Let me see the reports from Ewido and Blacklight
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 1:39:06 PM 08/21/2006 + Scan result: C:\My Downloads\US Ulead CD & DVD PictureShow 4 All Builds crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined). C:\Program Files\US Ulead CD & DVD PictureShow 4 All Builds crack.exe -> Downloader.IstBar.is : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.67:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.68:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.69:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.70:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.71:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.181:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.54:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.55:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.56:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.57:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.58:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.73:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.74:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.51:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.53:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.24:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup (quarantined). :mozilla.59:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup (quarantined). :mozilla.13:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.14:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.91:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.92:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.93:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.95:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined). :mozilla.11:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.13:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.144:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.145:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.146:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.147:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.51:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.88:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.89:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.90:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined). :mozilla.129:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.130:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.131:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.132:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.58:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.60:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.61:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup (quarantined). :mozilla.119:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.16:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.17:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.80:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.113:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup (quarantined). :mozilla.108:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.109:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.110:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.111:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.112:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.113:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.114:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.85:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.86:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.87:C:\Documents and Settings\Justin\Application Data\Mozilla\Firefox\Profiles\4muoy1o0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.12:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.8:C:\Documents and Settings\Tony\Application Data\Mozilla\Firefox\Profiles\juncdjvm.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Courtney\Application Data\Mozilla\Firefox\Profiles\jxajgwih.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\n4aqubeq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). ::Report end 08/21/06 13:43:16 [Info]: BlackLight Engine 1.0.46 initialized 08/21/06 13:43:16 [Info]: OS: 5.1 build 2600 (Service Pack 2) 08/21/06 13:43:17 [Note]: 7019 4 08/21/06 13:43:17 [Note]: 7005 0 08/21/06 13:44:45 [Note]: 7006 0 08/21/06 13:44:45 [Note]: 7011 1924 08/21/06 13:44:45 [Note]: 7026 0 08/21/06 13:44:45 [Note]: 7026 0 08/21/06 13:45:01 [Note]: FSRAW library version 1.7.1019 08/21/06 13:53:14 [Note]: 7007 0
First run this tool, you may still have parts of this infection present.
FxIstbar
Then do this
* Start Internet Explorer.
* Click Tools > Internet Options.
* In the Temporary Internet Files section, then click the Delete Files button.
* Check Delete all offline content, and then click OK.


Then
* Click Start > Settings > Control Panel
* Select Internet Options
* Select the Programs tab
* Click Reset Web Settings
* Click OK
* Exit Control Panel



Run this cleaner

Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main - choose: Select All
Click the Empty Selected button.


Post a new log and let me know if it made a difference.
Can't tell if it made a difference.

Logfile of HijackThis v1.99.1
Scan saved at 9:30:39 PM, on 08/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\System32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
D:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Citrix\ICA Client\ssonsvr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ezSP_Px.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
D:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
D:\Program Files\Hijack This\HijackThis[1].exe
C:\Program Files\Mozilla Firefox\firefox.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.excite.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\Micro Innovations\Optical Scroll\mouse32a.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [!ewido] "D:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKCU\..\Run: [InstantTray] C:\Program Files\Pinnacle\Shared Files\InstantCDDVD\PCLETray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Documents and Settings\Tonia\Favorites\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct2_x.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {2871FC9B-5E34-4AAE-9E9C-EBD1652D5C92} (Rhapsody Player Engine) - http://forms.real.com/real/player/download…ne_Inst_Win.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…01/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by103fd.bay103.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7F8C8173-AD80-4807-AA75-5672F22B4582} (ICSScanner Class) - http://download.zonelabs.com/bin/promotion…canner37390.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - D:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
a_dim_wit,

Nothing bad on your log :thumbup: You may want to call your ISP and let them know what your experiencing, it may be a problem on there end.


Here are some free programs and tips for keeping your system up to date, and to help keep all the riff raff out of your system.

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your
system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points

Turn off System Restore.

* Right-click My Computer.
* Click Properties.
* Click the System Restore tab.
* Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

Reboot your System

Turn ON System Restore.

* Right-click My Computer.
* ClickProperties.
* Click the System Restore tab.
* UN-Check Turn off System Restore on all Drives.
* Click Apply, and then click OK.

* Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this
MAKE SURE YOU CREATE A NEW RESTORE POINT



Download and Install CCleaner
* Click on Run Cleaner
Tutorial for CCleaner



* Go to C:\windows\prefetch and delete all thats in that folder, but not the prefetch folder itself, you should be in Safemode to remove it all.


* Open INTERNET EXPLORER
* Click on the TOOLS MENU
* Then INTERNET OPTIONS
* At the GENERAL TAB (which should be the first tab you are currently on),
* click on the DELETE FILES BUTTON and put a checkmark in DELETE ALL OFFLINE CONTENT.
* Then press the OK BUTTON . This may take quite a while, so do not be alarmed with how long it takes.
* When it is done, your Temporary Internet Files will now be deleted.


Now Empty your Recycle Bin




* Make sure that your ANTI-VIRUS SOFTWARE is up to date and run a full scan at least once aweek.

* Here are Free Anti-Virus Programs if you need one
AVG Free Edition
AntVir Personal Edition



* Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.


* Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.


* Spyware Blaster It will prevent most spyware from ever being installed.


* Spyware Guard It offers realtime protection from spyware installation attempts.


* Win Patrol This program will warn you when any changes are being made to your system and
give you the option to deny the change.


* IE- Spyad IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents downloads and (cookies etc) from the sites listed, although you will still be able to connect to the sites.


* Firefox Browser
It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both. When it asks you if you want it to be your default browser, say NO and take the checkmark out of the box to ask you again. After you use this for awhile, you will want to make it your default.


* Thunderbird Mail There companion mail program was highly favored in PCWorld Magazine, this has a good spam filter and is more secure than Outlook Express.


* Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.


* WINDOWS UPDATES - Enable Automatic Updates
Right click on MY COMPUTER/Click on PROPERTIES/ AUTOMATIC UPDATES and put a mark in the radio button
DOWNLOAD UPDATES FOR ME BUT LET ME CHOOSE WHEN TO INSTALL THEM.

* Go to START/ CONTROL PANEL> PERFORMANCE AND MAINTENANCE> REARRANGE ITEMS ON YOUR HARD DISK TO MAKE PROGRAMS RUN FASTER
This is the Windows Disk Defragger, run this maybe once or twice a month to keep your system running good. The first time you run it, it may take awhile.


Ken :D
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI