This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Virut.A has my system tied up

159 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello euqruob,

Little eagle has been helping me and will be directly handling your log after this.
Please do the following:

Step 1
Please be sure that your system restore is turned off.
1. Right-click My Computer and then click Properties.
2. On the Performance tab, click File System
3. On the Troubleshooting tab, click to select Disable System Restore
4. Click OK twice
5. Restart your computer.

Step 2.
Please rename ewido.exe to ewido2.exe.

Step 3.
Run ATF Cleaner

Step 4
Reboot into safe mode with networking
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the option, to run Windows in Safe Mode with Networking .

Step 5
Run house call
http://housecall.trendmicro.com/
Please post the results from housecall.
Then run ewido and post the ewido report.
I have system restore turned off on all drives, but on my XP I go to properties then to system restore then disable system restore on all drives. There is no performance tab and file systems and troubleshooting tab. Also, the trendmicro online scan has never worked, it always goes halfway through then shuts down, I will try again however. Also, there was no ewido.exe file out there, so I installed ewido then changed the name of the .exe file. ATF Cleaner, I assume you wanted all selected…. doing the rest now.
I ran the trend micro then went off to work, I came home and it was gone, no report. It gets to a certain point, then shuts down the browser. I tried the Trend Micro last night running off of portable Firefox which is running on my USB U3 drive, and it did the same thing. Do you still want me to run ewido? As for internet, except for this response in IE, I will surf via the U3 drive which has its own Firefox, and its own Avast anti-virus monitor running on it, so it is safe.
Reboot your computer in safe mode. Run ewido and Avast. Post both logs here when done. Of course, you know, we are probably beating a dead horse ;)
Here is the ewido results, I'll run Avast from the thumb drive this morning while I'm at work. ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 7:21:25 AM 9/26/2006 + Scan result: C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025784.dll -> Adware.CASClient : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025785.dll -> Adware.CASClient : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0013406.EXE -> Adware.CommAd : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016110.EXE -> Adware.CommAd : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025237.EXE -> Adware.CommAd : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0033005.EXE -> Adware.CommAd : No action taken. HKLM\SOFTWARE\Classes\CLSID\{CFBFAE00-17A6-11D0-99CB-00C04FD64497} -> Adware.DeluxeCommunications : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025794.0CX -> Adware.MediaMotor : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025792.dll -> Adware.Mirar : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025786.exe -> Adware.WebHancer : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025349.EXE -> Adware.ZenoSearch : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025409.EXE/drxvp.exe -> Downloader.Adload.ep : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025334.0XE -> Downloader.Dyfuca.fb : No action taken. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025429.0XE -> Dropper.Small.qn : No action taken. :mozilla.5:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.247realmedia : No action taken. :mozilla.10:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.11:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.12:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.13:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.14:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.15:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.16:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.174:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.17:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.185:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.18:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.19:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.20:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.21:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.22:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.236:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.23:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.24:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.25:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.26:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.27:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.28:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.29:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.30:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.31:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.32:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.33:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.34:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.35:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.364:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.36:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.37:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.48:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.49:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.50:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.51:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.528:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.6:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.7:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.8:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.9:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\administrator@2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\administrator@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@anm.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. :mozilla.61:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.62:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.65:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.66:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken. :mozilla.64:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Addynamix : No action taken. :mozilla.73:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Admarketplace : No action taken. :mozilla.677:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.678:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.679:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.680:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.681:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.81:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.82:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.625:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adserver : No action taken. :mozilla.626:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adserver : No action taken. :mozilla.87:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adtech : No action taken. :mozilla.88:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Adtech : No action taken. :mozilla.44:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.45:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.46:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.47:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Advertising : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@advertising[2].txt -> TrackingCookie.Advertising : No action taken. :mozilla.22:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. :mozilla.727:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken. :mozilla.142:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.728:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Burstnet : No action taken. :mozilla.189:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.190:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.191:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.192:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.193:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Com : No action taken. :mozilla.19:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\administrator@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Cookies\neil bourque@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. :mozilla.216:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Esomniture : No action taken. :mozilla.217:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Esomniture : No action taken. :mozilla.218:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Esomniture : No action taken. :mozilla.219:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Esomniture : No action taken. :mozilla.74:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.75:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.76:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Euroclick : No action taken. :mozilla.108:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.109:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.110:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.111:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.643:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.644:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.645:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.646:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. :mozilla.647:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Falkag : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Falkag : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken. :mozilla.249:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Findwhat : No action taken. :mozilla.746:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@hitbox[1].txt -> TrackingCookie.Hitbox : No action taken. :mozilla.136:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.137:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.138:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.139:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\administrator@mediaplex[2].txt -> TrackingCookie.Mediaplex : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@mediaplex[2].txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.122:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken. :mozilla.606:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][2].txt -> TrackingCookie.Myaffiliateprogram : No action taken. :mozilla.706:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Onestat : No action taken. :mozilla.707:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Onestat : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][2].txt -> TrackingCookie.Onestat : No action taken. :mozilla.102:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.435:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Overture : No action taken. :mozilla.83:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.84:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.85:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.86:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. C:\Documents and Settings\Administrator.NEIL.000\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Pointroll : No action taken. :mozilla.103:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.104:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.448:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.449:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.450:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.230:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.231:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.232:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.233:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.234:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.235:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.493:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.494:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.495:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.496:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.497:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.26:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.27:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.28:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.29:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.30:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.77:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.78:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.79:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. :mozilla.80:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Specificclick : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Specificclick : No action taken. :mozilla.517:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.518:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.519:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.520:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.521:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.522:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.523:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.524:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.525:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.526:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. :mozilla.527:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Statcounter : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken. :mozilla.115:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.116:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.117:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.118:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.119:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.120:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.536:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.537:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.538:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.539:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.642:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken. :mozilla.554:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken. :mozilla.555:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken. :mozilla.556:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.557:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.558:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.559:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.560:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.561:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.562:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.563:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.121:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Trafic : No action taken. :mozilla.20:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.21:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.23:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.25:C:\Documents and Settings\Bourque\Application Data\Mozilla\Firefox\Profiles\rznqzchz.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.566:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.567:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.568:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.569:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.570:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.571:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.572:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.573:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.574:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.575:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.576:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Cookies\neil bourque@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken. :mozilla.467:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.468:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.469:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.470:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.471:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Valuead : No action taken. :mozilla.623:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.631:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.632:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.633:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil [removed][1].txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.627:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.628:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.629:C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Mozilla\Firefox\Profiles\6qbzqq5p.default\cookies.txt -> TrackingCookie.Zedo : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Local Settings\Temp\Cookies\neil bourque@zedo[2].txt -> TrackingCookie.Zedo : No action taken. ::Report end

C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025784.dll ->

It looks like system resore is still on ??

Can you post the other log?
No, system restore has been off all this time, turning it off was just different than the way you said to do it. On mine you right click My Computer, properties and the System Restore tab and click Turn off System Restore on all drives. As for the other report, here it is, I stopped it after 13 hours, it was near the end of the D: drive and there is only one area there that is corrupted (plus, I needed to use my computer, its been unavailable all day) Here is the results from Avast working on the usb thumb drive. ;****** ;Avast! Antivirus U3 Edition ;VPS file version: September 25, 2006 - [0639-1] ;Params: C:\ D:\ Scan: Full files, All files, Ignore targeting, Archive: ARJ, MIME, EXE, ZIP, Stream, RAR, CAB, GZ, TAR, ;Columns: File name Status [OK,INFECTED,ERROR] ;****** C:\Program Files\Outlook Express\msimn.exe INFECTED: Win32:Virut-B C:\Program Files\Real\RealPlayer\realplay.exe INFECTED: Win32:Virut-B C:\Program Files\Real\RealOne Player\realplay.exe INFECTED: Win32:Virut-B C:\Program Files\Microsoft Office\Office\SBCMSTRT.EXE INFECTED: Win32:Virut-B C:\Program Files\Microsoft Office\Office\SBT\DMM\directmail.exe INFECTED: Win32:Virut-B C:\Program Files\CD-Writer Plus\diagnose\Toolbox.exe INFECTED: Win32:Virut-B C:\Program Files\Return to Castle Wolfenstein\BACKUP\pak0.pk3\maps\tram.bsp ERROR: ZIP archive is corrupted. C:\Program Files\Return to Castle Wolfenstein\BACKUP\pak0.pk3\models\mapobjects\vacum\wzom_helm1.tga ERROR: ZIP archive is corrupted. C:\Program Files\Return to Castle Wolfenstein\BACKUP\pak0.pk3\sprites\twiltb2_lg\spr015.jpg ERROR: ZIP archive is corrupted. C:\Program Files\Return to Castle Wolfenstein\BACKUP\pak0.pk3\textures\stone\mxrock3aa.jpg ERROR: ZIP archive is corrupted. C:\Program Files\Return to Castle Wolfenstein\BACKUP\pak0.pk3\textures\town_wall\burntest.jpg ERROR: ZIP archive is corrupted. C:\Program Files\Return to Castle Wolfenstein\BACKUP\sp_pak1.pk3\video\wolfintro.RoQ ERROR: ZIP archive is corrupted. C:\Program Files\ewido anti-spyware 4.0\Quarantine\fil95502E99.dat\fil95502E99 INFECTED: Win32:Adloader-AZ [Trj] C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\Ad-Aware SE Default.skn ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow1.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\arrow2.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bck1.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt11.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt12.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt13.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt21.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt22.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt23.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt31.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt32.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt33.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt41.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt42.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt43.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt51.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt52.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt53.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt61.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\bt62.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox1.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox2.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox3.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\checkbox4.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn1.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn2.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\defbtn3.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph1.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph2.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph3.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph4.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph5.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph6.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\glyph7.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\main.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\preview.bmp ERROR: Archive is password protected. C:\Program Files\Lavasoft\Ad-Aware SE Personal\Skins\Ad-Aware SE default.ask\sprite1.bmp ERROR: Archive is password protected. C:\Program Files\Creative\Product Registration\English\INETREG.EXE INFECTED: Win32:Virut-B C:\Program Files\Ubisoft\Crytek\Far Cry\Levels\Cooler\level.pak\terrain\cover.ctc ERROR: ZIP archive is corrupted. C:\Program Files\LucasFan Games\MMD\autorun.apm\ams_xml_pl.xml ERROR: Archive is password protected. C:\Program Files\LucasFan Games\MMD\autorun.apm\ams_xml_temp.xml ERROR: Archive is password protected. C:\WINDOWS\system32\mobsync.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\magnify.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\dxdiag.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\ActiveScan\pskavs.dll INFECTED: Win32:CTX C:\WINDOWS\system32\cmd.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\utilman.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\tourstart.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\rcimlby.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\osk.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\notepad.exe INFECTED: Win32:Virut-B C:\WINDOWS\system32\narrator.exe INFECTED: Win32:Virut-B C:\WINDOWS\notepad.exe INFECTED: Win32:Virut-B C:\WINDOWS\WindowsUpdate.log INFECTED: Win32:Virut-B C:\WINDOWS\Internet Logs\BACKUP.RDB INFECTED: Win32:Virut-B C:\WINDOWS\Internet Logs\IAMDB.RDB INFECTED: Win32:Virut-B C:\undo\backup.cab\\Device\Harddisk0\Partition1\WINDOWS\History\History.IE5\index.dat INFECTED: Win32:Delf-FT [Trj] C:\undo\backup.cab\\Device\Harddisk0\Partition1\WINDOWS\History\History.IE5\MSHist012001090220010903\index.dat INFECTED: Win32:Delf-FT [Trj] C:\undo\backup.cab INFECTED: Win32:Delf-FT [Trj] C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.reg ERROR: Archive is password protected. C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\WindowsSecurityCenterAntiVirusOverride.zip\sbRecovery.ini ERROR: Archive is password protected. C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AdsAlert.zip\sbRecovery.reg ERROR: Archive is password protected. C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AdsAlert.zip\sbRecovery.ini ERROR: Archive is password protected. C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HotsearchBar.zip\sbRecovery.ini ERROR: Archive is password protected. C:\Documents and Settings\Neil Bourque.NEIL.000\Application Data\Real\RealPlayer\ErrorLogs\log1.dmp INFECTED: Win32:Virut C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP44\A0010028.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010306.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010310.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0010317.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011278.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011282.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP45\A0011289.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011745.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011846.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011850.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP46\A0011857.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016109.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP47\A0016973.exe\QuickTimeInstaller.exe ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022756.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0022841.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0024179.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025232.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025236.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025246.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP51\A0025922.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP58\A0026774.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0031959.exe\files.dat ERROR: RAR archive is corrupted. C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032001.exe INFECTED: Win32:Trojan-gen. {Other} C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032002.exe INFECTED: Win32:VB-MT [Wrm] C:\System Volume Information\_restore{74883764-FDBD-4B3F-927C-16E8F55CABF3}\RP59\A0032008.exe INFECTED: Win32:Trojan-gen. {Other} C:\Hijack This\uninstall.exe INFECTED: Win32:Virut-B C:\Hijack This\Cleanup.exe INFECTED: Win32:Virut-B D:\Documents and Settings\NEIL BOURQUE\Local Settings\Temp\agreement.html INFECTED: Win32:VB-HF [Wrm] D:\Documents and Settings\NEIL BOURQUE\Local Settings\History\History.IE5\index (1).dat INFECTED: Win32:Delf-FT [Trj] D:\Documents and Settings\NEIL BOURQUE\Local Settings\Temporary Internet Files\Content.IE5\7XDFSQ4M\de_DE-1218438-n[1].jpg\de_DE-1218438-n[1] ERROR: Archive is corrupted. D:\Documents and Settings\Neil Bourque.NEIL\Local Settings\Temp\_CTIN2a70720_\CrazyTalk.cab\crazytalk.dll ERROR: CAB archive is corrupted. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip\neil@bfast[2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\BFast.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip\neil@advertising[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Advertisingcom1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip\neil@atdmt[2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\FastClick.zip\neil@fastclick[2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\FastClick.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip\neil@qksrv[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\CommissionJunction.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics.zip\[removed][2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\CoreMetrics.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick.zip\neil@doubleclick[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\DoubleClick.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Gator.zip\neil@gator[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\Gator.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox.zip\[removed][2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox1.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox2.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox2.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox3.zip\neil@hitbox[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox3.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox4.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox4.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox5.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox5.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox6.zip\[removed][2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox6.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox7.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox7.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitsLink.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitsLink.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitsLink1.zip\[removed][2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitsLink1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\MediaPlex.zip\neil@mediaplex[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\MediaPlex.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexList.zip\neil@sexlist[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexList.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip\neil@bfast[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\BFast1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\ValueClick.zip\neil@valueclick[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\ValueClick.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip\neil@atdmt[2].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\AvenueAInc1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox8.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox8.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\FastClick1.zip\neil@fastclick[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\FastClick1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox9.zip\neil@hitbox[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox9.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox10.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\HitBox10.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\TargetNet.zip\neil@targetnet[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\TargetNet.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker1.zip\[removed][1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker1.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker2.zip\neil@sextracker[1].txt ERROR: Archive is password protected. D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy\Recovery\SexTracker2.zip\sbRecovery.ini ERROR: Archive is password protected. D:\Program Files\EA SPORTS\Madden NFL 07\Support\EasyInfo.exe INFECTED: Win32:Virut-B D:\Program Files\EA SPORTS\Madden NFL 07\Support\EReg.exe INFECTED: Win32:Virut-B D:\Program Files\EA SPORTS\Madden NFL 07\eauninstall.exe INFECTED: Win32:Virut-B D:\Program Files\EA SPORTS\Madden NFL 07\Madden07.exe INFECTED: Win32:Virut-B D:\Program Files\Tierra\KQVGA\kqmenu.apm\ams_xml_pl.xml ERROR: Archive is password protected. D:\Program Files\Tierra\KQVGA\kqmenu.apm\ams_xml_temp.xml ERROR: Archive is password protected. ;****** ;Commands ;Columns: File name Command Return code Custom parameter 1 Custom parameter 2 ;****** ;****** ;End of commands ;****** ;****** ;Commands ;Columns: File name Command Return code Custom parameter 1 Custom parameter 2 ;****** ;****** ;End of commands ;******
hijack this log regular mode

Logfile of HijackThis v1.99.1
Scan saved at 6:51:26 AM, on 9/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\ewido anti-spyware 4.0\ewido2.exe.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\wscntfy.exe
H:\FirefoxPortable\App\firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido2.exe.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/…ivex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1157241948859
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\system32\MsPMSPSv.exe (file missing)
Hijack this safe mode report:

(also, I notice every time I re-boot, I have to go back and change my mouse settings to the way I want, it never saves the settings after any reboot)

file of HijackThis v1.99.1
Scan saved at 6:55:02 AM, on 9/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.drudgereport.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido2.exe.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://eu-housecall.trendmicro-europe.com/…ivex/hcImpl.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1157241948859
O16 - DPF: {9732FB42-C321-11D1-836F-00A0C993F125} (mhLabel Class) - http://www.pcpitstop.com/mhLbl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols3/fscax.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - Unknown owner - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe (file missing)
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZONELABS\vsmon.exe
O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\system32\MsPMSPSv.exe (file missing)
Close all Browser and Program Windows and have HijackThis fix the following.
Do this by checking the box beside each and then clicking on Fix checked.

O23 - Service: WMDM PMSP Service - Unknown owner - C:\WINDOWS\system32\MsPMSPSv.exe (file missing)

Download Pocket Killbox and unzip it; save it to your Desktop.

Run it, and click the radio button that says Delete a file on reboot.Then paste

C:\WINDOWS\system32\MsPMSPSv.exe (file missing)

them one at a time into the full path of file to delete box and click the red circle with a white cross in it.

The program will ask you if you want to reboot; answer Yes.

Let the system reboot in safe mode and run ewido.
When I run killbox with the info pasted in, I get this message PendingFileRenameOperations Registry Data has been removed by External Process! I click OK and back to Killbox, it doesn't ask to reboot. So, I am going to reboot it manually, bring back into safe mode and run ewido. Note, Ewidow takes a long time on my system in safe mode, over 12 hours, I will run it a bit later tonite. I am doing all my surfing via a thumb drive that is protected with Avast. I'll most likely have the ewido report in the morning. Thanks
——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 6:47:20 AM 9/29/2006 + Scan result: C:\Documents and Settings\Neil Bourque.NEIL.000\Cookies\neil bourque@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Neil Bourque.NEIL.000\Cookies\neil bourque@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken. ::Report end
Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI