This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

HJT Log for reviewal

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here she is… I also have a questions about SVCHOST.EXE in my task manager… it's sucking up a lot of memory..

Logfile of HijackThis v1.99.1
Scan saved at 8:00:07 PM, on 11/13/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\WgaTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Security Task Manager\taskman.exe
C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nwmissouri.edu/students/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: web compressor - {23FB5ADD-DA37-4a40-9FC0-B0E2384CDE92} - C:\WINDOWS\System32\nsn16.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [kbddap] C:\WINDOWS\System32\kbddap.exe
O4 - HKCU\..\Run: [zqiq] C:\PROGRA~1\COMMON~1\zqiq\zqiqm.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinrsag.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…ZSzed029DJUS_ZS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: www.archiviosex.net
O15 - Trusted Zone: http://*.billingnow.com
O15 - Trusted Zone: www.redfunny.com
O15 - Trusted Zone: http://*.reliablestats.com
O15 - Trusted Zone: www.skymasters.biz
O15 - Trusted Zone: http://*.winantispyware.com
O15 - Trusted Zone: http://*.winantivirus.com
O15 - Trusted Zone: http://*.winantiviruspro.com
O15 - Trusted Zone: http://*.winnanny.com
O15 - Trusted Zone: http://*.winsoftware.com
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potg_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…tup1.0.0.15.cab
O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://198.209.246.36/v3rdpchk.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1134355779593
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://198.209.246.36/msrdp.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} (elitectl.DemoCtl) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O20 - AppInit_DLLs:
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\n62u0gf9e62.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\S2F0aHkgUGFvbmVzc2E\command.exe (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Adam :D

Welcome to Tom Coyote

SVCHOST.EXE <– To have multiple instances of this running is perfectly normal, what's sucking up your resources and memory are all the worms, trojans and malware that you have on your system. This is one heavily infected computer :angry:


We have some work ahead of us to remove it all, print this out as we will be offline for part of the fix. This is a mouthful, don't let it intimidate you, take your time and follow all the instructions in order.

C:\Program Files\Save or WhenUsave <– If this is present in the Add-Remove Programs list, uninstall it.



We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.



We need to stop two bad services so that we can delete them.
  • Go to Start> Run and type in services.msc then press Enter
  • Scroll down to Command Service
  • Double Click that service to open it.
  • Click on Stop Service.
  • Then change the Startup Type to Disabled.
  • Scroll down to Hardware Clock Driver
  • Double Click that service to open it.
  • Click on Stop Service.
  • Then change the Startup Type to Disabled.
  • OK your way out of the program.
  • Open HJT > Misc Tools > Delete an NT Service
  • Type in cmdService
  • Then click on OK, it will ask you to reboot, do so.
Do it again for this one.
  • Open HJT > Misc Tools > Delete an NT Service
  • Type in hwclock
  • Then click on OK, it will ask you to reboot, do so.
Open HJT Scan Only, close your browser and all open windows, check these and click on Fix Checked

O2 - BHO: web compressor - {23FB5ADD-DA37-4a40-9FC0-B0E2384CDE92} - C:\WINDOWS\System32\nsn16.dll
O2 - BHO: CVirtualDNSObj Object - {86C510E9-97EF-4749-914F-0280247BE3A6} - C:\WINDOWS\VirtualDNS.dll

O4 - HKCU\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
O4 - HKCU\..\Run: [kbddap] C:\WINDOWS\System32\kbddap.exe
O4 - HKCU\..\Run: [zqiq] C:\PROGRA~1\COMMON~1\zqiq\zqiqm.exe
O4 - Startup: Zeno.lnk = C:\WINDOWS\system32\pwinrsag.exe

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…ZSzed029DJUS_ZS

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwe…tup1.0.0.15.cab
O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} (Mirar_Dummy_ATS1 Class) - http://awbeta.net-nucleus.com/FIX/WinATS.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} (elitectl.DemoCtl) - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://download.games.yahoo.com/games/web_…aploader_v6.cab

O20 - AppInit_DLLs:
O20 - Winlogon Notify: ModuleUsage - C:\WINDOWS\system32\n62u0gf9e62.dll (file missing)

O23 - Service: Command Service (cmdService) - Unknown owner - C:\WINDOWS\S2F0aHkgUGFvbmVzc2E\command.exe (file missing)
O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing)




Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5

Still in Safemode, make sure these files are gone, delete them if still present.


C:\Program Files\Save

C:\WINDOWS\S2F0aHkgUGFvbmVzc2E
C:\WINDOWS\VirtualDNS.dll

C:\WINDOWS\System32\hwclock.exe
C:\WINDOWS\System32\kbddap.exe
C:\WINDOWS\System32\nsn16.dll
C:\WINDOWS\system32\n62u0gf9e62.dll
C:\WINDOWS\system32\pwinrsag.exe



Reboot normally

Download: DelDomains and save it to the desktop.
  • Close all open windows and your browser
  • Right Click DelDomains.inf and select > Install
  • Reboot your computer
Run this system cleaner

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up



I need to see the AVG Report and a New HJT log.
Here's the HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 5:45:08 PM, on 11/16/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nwmissouri.edu/students/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potg_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://198.209.246.36/v3rdpchk.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1134355779593
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://198.209.246.36/msrdp.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/sis/mjolauncher.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
And the AVG ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 5:27:05 PM 11/16/2006 + Scan result: C:\Documents and Settings\kathy paonessa\Local Settings\Temp\cd_clint.dll -> Adware.Cydoor : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052395.exe/cd_clint.dll -> Adware.Cydoor : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052395.exe/cd_htm.dll -> Adware.Cydoor : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052398.dll -> Adware.Cydoor : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052399.dll -> Adware.Cydoor : Cleaned with backup (quarantined). HKLM\SOFTWARE\Cydoor -> Adware.Cydoor : Cleaned with backup (quarantined). HKU\S-1-5-21-1960408961-796845957-725345543-1004\Software\Cydoor -> Adware.Cydoor : Cleaned with backup (quarantined). C:\Documents and Settings\home\Local Settings\Temp\uninstall.exe -> Adware.EliteBar : Cleaned with backup (quarantined). C:\WINDOWS\eliteunstall.exe -> Adware.EliteMedia : Cleaned with backup (quarantined). C:\Program Files\Common Files\WinFixer 2005\uwappchk.dll -> Adware.ErrorSafe : Cleaned with backup (quarantined). C:\WINDOWS\justin.exe -> Adware.EZula : Cleaned with backup (quarantined). C:\FOUND.002\FILE0068.CHK -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\c8002idmg80a2.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\dn6m01j1e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\e6jm0g11e6.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\enjml1111.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\fpjs0317e.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\hr6205joe.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\i6600gjme6oa0.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\j06m0aj1edo.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\l62slgf7162.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\o2ro0c93ef.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\system32\q8ps0i77e8.dll -> Adware.Look2Me : Cleaned with backup (quarantined). C:\installer.exe -> Adware.Look2Me : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\elite.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\backups\backup-20061113-202549-181.dll -> Adware.Mirar : Cleaned with backup (quarantined). C:\FOUND.002\FILE0014.CHK/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined). C:\FOUND.002\FILE0022.CHK/NNBar_VCSetup_876029.exe -> Adware.Mirar : Cleaned with backup (quarantined). C:\FOUND.002\FILE0023.CHK -> Adware.Mirar : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052402.dll -> Adware.Mirar : Cleaned with backup (quarantined). C:\WINDOWS\876057.exe -> Adware.Mirar : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP242\A0029863.dll -> Adware.NewDotNet : Cleaned with backup (quarantined). HKLM\SOFTWARE\ClickSpring -> Adware.PurityScan : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Start Menu\Programs\WhenU -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Start Menu\Programs\WhenU\Learn More About WhenU Save.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Start Menu\Programs\WhenU\Learn More About WhenU SaveNow.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Start Menu\Programs\WhenU\WhenU.com Website.url -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.002\FILE0034.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.002\FILE0036.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.002\FILE0051.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.002\FILE0054.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.002\FILE0056.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.003\FILE0055.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\FOUND.003\FILE0056.CHK -> Adware.SaveNow : Cleaned with backup (quarantined). C:\Program Files\imgiant\VVSNInst.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\WINDOWS\system32\guninst.exe -> Adware.Serpo : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\backups\backup-20061113-202548-165.dll -> Adware.SideFind : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052400.dll -> Adware.SideFind : Cleaned with backup (quarantined). C:\Program Files\Common Files\zqiq\zqiqd\zqiqc.dll -> Adware.TargetServer : Cleaned with backup (quarantined). C:\Downloads\PlantasiaSetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\backups\backup-20061113-202548-925.dll -> Adware.Webdir : Cleaned with backup (quarantined). C:\System Volume Information\_restore{47CE2A67-47A0-4102-ACF1-6E7F4CF28282}\RP516\A0052401.dll -> Adware.Webdir : Cleaned with backup (quarantined). C:\FOUND.002\FILE0035.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.002\FILE0037.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.002\FILE0038.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.002\FILE0040.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.002\FILE0041.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.003\FILE0049.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.003\FILE0050.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.003\FILE0051.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.003\FILE0053.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\FOUND.003\FILE0054.CHK -> Adware.WebHancer : Cleaned with backup (quarantined). C:\Program Files\WinAntiVirus Pro 2006 -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\Program Files\WinAntiVirus Pro 2006\history.db -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\Program Files\WinAntiVirus Pro 2006\plugins -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\Program Files\WinAntiVirus Pro 2006\plugins\e_spyw.ivd -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\WINDOWS\system32\SpOrder.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SOFTWARE\WinAntiVirus Pro 2006 -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKU\S-1-5-21-1960408961-796845957-725345543-1004\Software\WinAntiVirus Pro 2006 -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKU\S-1-5-21-1960408961-796845957-725345543-1004\Software\WinAntiVirus Pro 2006\Settings -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\Program Files\Common Files\WinSoftware\_WFF.exe -> Adware.Winfixer : Cleaned with backup (quarantined). C:\WINDOWS\system32\drivers\_WFF.sys -> Adware.Winfixer : Cleaned with backup (quarantined). C:\WINDOWS\ZIFI002.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\inst_FI002.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\bak\pwinrsag.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\owinmsaw.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\pwinrsai.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\pwinrsap.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\rldsregp.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\WINDOWS\system32\rqdsregq.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined). C:\Documents and Settings\home\Local Settings\Temp\196714_3104_2164_3220_63.41.tmp -> Downloader.Agent.tv : Cleaned with backup (quarantined). C:\Documents and Settings\home\Local Settings\Temp\65818_3104_2164_3412_63.41.tmp -> Downloader.Agent.tv : Cleaned with backup (quarantined). C:\Documents and Settings\home\Local Settings\Temp\65922_3092_2972_2044_63.41.tmp -> Downloader.Agent.tv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP312\A0034926.exe -> Downloader.Agent.tv : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP312\A0034933.exe -> Downloader.Agent.tv : Cleaned with backup (quarantined). C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\4P6N05EZ\drsmartload_js[1].htm -> Downloader.IstBar.j : Cleaned with backup (quarantined). C:\Program Files\Common Files\zqiq\zqiqd\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined). C:\Documents and Settings\Guest\Local Settings\Temporary Internet Files\Content.IE5\GXMVOXIR\popup[2].php -> Hijacker.Agent.a : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Local Settings\Temporary Internet Files\Content.IE5\L7BF1LWE\popup[2].php -> Hijacker.Agent.a : Cleaned with backup (quarantined). C:\WINDOWS\IEMonitor.ocx -> Hijacker.Small : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\backups\backup-20061116-143450-913.dll -> Not-A-Virus.Downloader.Win32.PopCap.b : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N68M2301NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.18:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.277:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.30:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.318:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.32:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.33:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.34:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.35:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.36:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.37:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.38:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.39:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.40:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.41:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\home\Cookies\home@northwestairlines.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@2o7[3].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@cbs.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@embarq.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@libertymutual.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@adbrite[3].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Addynamix : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Addynamix : Cleaned. :mozilla.243:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.244:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.245:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.246:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.247:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.248:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned. :mozilla.200:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.201:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.202:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.203:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.204:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@adrevolver[4].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@adrevolver[7].txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.230:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.231:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.232:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.233:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.29:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.31:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.33:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Adserver : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Adserver : Cleaned. :mozilla.10:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.34:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.35:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.36:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.37:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.38:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.55:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.56:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.57:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.58:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.59:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.6:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.7:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.8:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.9:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@advertising[1].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@advertising[3].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@advertising[1].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@advertising[3].txt -> TrackingCookie.Advertising : Cleaned. :mozilla.301:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Adviva : Cleaned. :mozilla.19:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.22:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.27:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.83:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@bfast[1].txt -> TrackingCookie.Bfast : Cleaned. :mozilla.237:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.260:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][2].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.128:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.124:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.125:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.239:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.240:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.19:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.20:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.21:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.97:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.98:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.99:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@casalemedia[3].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@centrport[1].txt -> TrackingCookie.Centrport : Cleaned. :mozilla.193:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.29:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.30:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\home\Cookies\home@com[2].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@com[2].txt -> TrackingCookie.Com : Cleaned. :mozilla.249:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.11:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.24:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.43:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.44:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Enhance : Cleaned. :mozilla.152:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.153:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.154:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.155:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.156:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.39:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.40:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.41:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.42:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][4].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Falkag : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Falkag : Cleaned. :mozilla.101:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.103:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.30:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.32:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.59:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.62:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.63:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@fastclick[3].txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.346:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.347:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.64:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.65:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.66:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.67:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.68:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@hitbox[4].txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.171:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.172:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.173:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.174:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.323:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned. C:\WINDOWS\Temp\Cookies\kathy paonessa@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.105:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.130:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.131:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.19:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.191:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.192:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.10:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.141:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.6:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.72:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.9:C:\Documents and Settings\home\Application Data\Mozilla\Firefox\Profiles\xlsm6a41.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@overture[2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned. C:\WINDOWS\Temp\Cookies\kathy paonessa@paypopup[1].txt -> TrackingCookie.Paypopup : Cleaned. :mozilla.208:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.209:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.210:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.211:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][4].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned. :mozilla.254:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.255:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.28:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.29:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.74:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.75:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@questionmarket[3].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.189:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Revenue : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@revenue[2].txt -> TrackingCookie.Revenue : Cleaned. :mozilla.151:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@edge.ru4[3].txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.108:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.109:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.110:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.111:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.112:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.283:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.284:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.285:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.286:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@serving-sys[3].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Sexcounter : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@sexlist[2].txt -> TrackingCookie.Sexlist : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Sextracker : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@sextracker[1].txt -> TrackingCookie.Sextracker : Cleaned. :mozilla.222:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@starware[2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Starware : Cleaned. :mozilla.278:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.279:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.280:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.281:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
The rest of the AVG report C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@statcounter[3].txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.122:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.123:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Targetnet : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.223:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.23:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tradedoubler[3].txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.110:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.111:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.35:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.36:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.37:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.38:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.39:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.40:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.41:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.42:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.77:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.78:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.79:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.80:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.81:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.82:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.83:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@trafficmp[3].txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.101:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.112:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.60:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.61:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\w3j72ntd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Kyle\Cookies\kyle@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tribalfusion[4].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.310:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.311:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.312:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.313:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.314:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.315:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Valuead : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned. :mozilla.265:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@yadro[2].txt -> TrackingCookie.Yadro : Cleaned. :mozilla.100:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.91:C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.98:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.99:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Kyle\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][3].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][4].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][5].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][6].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][7].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][8].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][9].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\WINDOWS\Temp\Cookies\kathy [removed][10].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\WINDOWS\Temp\Cookies\kathy [removed][9].txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.224:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.225:C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\Guest\Cookies\guest@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@zedo[2].txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@zedo[3].txt -> TrackingCookie.Zedo : Cleaned. C:\WINDOWS\sigldr.exe -> Trojan.Dialer.hh : Cleaned with backup (quarantined). C:\Documents and Settings\home\Local Settings\Temporary Internet Files\Content.IE5\CLMJST6J\proxy_inst[1].exe -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP312\A0034924.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP312\A0034936.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP313\A0034970.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP316\A0035974.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP319\A0037162.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP320\A0037178.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037216.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037246.exe -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037284.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037319.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037500.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037512.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP321\A0037542.dll -> Trojan.EliteBar.a : Cleaned with backup (quarantined). C:\FOUND.002\FILE0015.CHK/mrjj.exe -> Trojan.LowZones.am : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\My Documents\My Music\microsoft windows key gen 2003 or xp pro or office-xp keygen(1).exe/hen3_2_017\HentaII3D-017-004-(AMD-ONLY!)-hotfix\HentaII3D-017.004-start.exe -> Trojan.QQPass.ly : Cleaned with backup (quarantined). C:\Documents and Settings\kathy paonessa\My Documents\My Music\microsoft windows key gen 2003 or xp pro or office-xp keygen(1).exe/svil2_017\3DSexVilla-017-001-(AMD-ONLY!)-hotfix\3DSexVilla-017-001-start.exe -> Trojan.QQPass.ly : Cleaned with backup (quarantined). ::Report end
Adam :D

Your log looks fine :thumbup: but I am a little concerned about some of the entries that were found and deleted in the AVG scan. Lets check and make sure the rest of those entries are gone. Lets do a few things.

You did a very good job of following my instructions by the way :D


Update your JAVA as it could be leaving a hole for this crapola to install
  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Java website and download and install the update.
  • Java Runtime Environment (JRE) 5.0 Update 9 <–This is what you need to download and install.
  • Then after install you can verify your installation here Sun Java Verify



Please download ComboFix by sUBs from either of these two locations

BleepingComputerComboFix
TechSupportForumComboFix
  • Double click combofix.exe & follow the prompts.
  • When finished, it shall produce a log for you. Post that log in your next reply along with a new HJT log please.
Do not mouseclick combofix's window whilst it's running. That may cause it to stall.


Let me see the Combofix log and a new HJT log please.
I couldn't get combofix to work.. It loaded then went blue and shut down



Logfile of HijackThis v1.99.1
Scan saved at 8:07:34 PM, on 11/16/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\CTSvcCDA.EXE
C:\WINDOWS\System32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Ares\Ares.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\WINDOWS\Twain_32\CA561A\SnapDetect.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\WgaTray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\msiexec.exe
C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nwmissouri.edu/students/index.htm
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Icatch(VI) SnapDetect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (file missing)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: Yahoo! Blackjack - http://download.games.yahoo.com/games/clients/y/jt0_x.cab
O16 - DPF: Yahoo! Canasta - http://download.games.yahoo.com/games/clients/y/yt1_x.cab
O16 - DPF: Yahoo! Cribbage - http://download.games.yahoo.com/games/clients/y/it1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potg_x.cab
O16 - DPF: Yahoo! Spades - http://download.games.yahoo.com/games/clients/y/st2_x.cab
O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://198.209.246.36/v3rdpchk.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1134355779593
O16 - DPF: {7584C670-2274-4EFB-B00B-D6AABA6D3850} (Microsoft RDP Client Control (redist)) - http://198.209.246.36/msrdp.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://www.shockwave.com/content/luxor/sis/mjolauncher.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTSvcCDA.EXE
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Adam,

Try running it in Safemode. Something has to be wrong someplace, I have never run into someone not being able to run it. Try disabling your AVG free program, also when you installed the trial of AVG Anti Spyware, make sure you disabled the background guard.

What Anti Virus programs do you have on your system? I am looking at AVG Free ( which is about to discontinue this program to the public very soon ) and also Norton Security Suite. You need to uninstall one of these programs, running two AV programs are going to give you boat loads of problems.


Run this free online virus scanner from Panda, it may pick up some bad entires that are not showing up on your HJT log. It's important that I see the log so copy and paste it into your next reply.
Panda ActiveScan <—-Accept default settings
Panda Report




Incident Status Location

Dialer:dialer.akd Not disinfected C:\Documents and Settings\kathy paonessa\Start Menu\Programs\WinMoviePlugIn.lnk
Adware:adware/hotoffers Not disinfected c:\windows\system32\MP3.ico
Potentially unwanted tool:application/winfixer2005 Not disinfected c:\program files\common files\WinSoftware
Potentially unwanted tool:application/winantivirus2006 Not disinfected c:\program files\common files\WinAntiVirus Pro 2006
Spyware:spyware/media-motor Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
Adware:adware/mirar Not disinfected Windows Registry
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[whAgent.inf]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[WhAgent.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[whInstaller.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[WhSurvey.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[Webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0008.CHK[whiehlpr.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[whAgent.inf]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[WhAgent.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[whInstaller.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[WhSurvey.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[Webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0011.CHK[whiehlpr.dll]
Spyware:Cookie/Media-motor Not disinfected C:\FOUND.003\FILE0014.CHK
Adware:Adware/WebHancer Not disinfected C:\FOUND.003\FILE0048.CHK
Adware:Adware/ClockSync Not disinfected C:\FOUND.003\FILE0058.CHK[VVSNInst.exe]
Adware:Adware/ClockSync Not disinfected C:\FOUND.003\FILE0059.CHK[VVSNInst.exe]
Potentially unwanted tool:Application/FunWeb Not disinfected C:\Documents and Settings\kathy paonessa\Desktop\hijackthis\backups\backup-20061113-202548-488.inf
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@mediaplex[1].txt
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@2o7[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@atdmt[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@advertising[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@doubleclick[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@trafficmp[2].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@questionmarket[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@casalemedia[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@tribalfusion[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@realmedia[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy [removed][2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\kathy paonessa\Cookies\kathy paonessa@fastclick[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\kathy paonessa\Application Data\Mozilla\Firefox\Profiles\m5702guy.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Kyle\Cookies\[removed][2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Kyle\Application Data\Mozilla\Firefox\Profiles\9ho573hb.default\cookies.txt[.go.com/]
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\WinAntiVirus Pro 2006\WapCHK.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK.dll
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\compwiz.exe
Potentially unwanted tool:Application/Winantivirus2006 Not disinfected C:\Program Files\Common Files\Companion Wizard\WapCHK{857FB4C0-199B-4A83-8559-FAD408C1CD9C}.dll
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\Install.exe
Potentially unwanted tool:Application/ErrorSafe Not disinfected C:\Program Files\WinFixer\FRec.dll
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\WFShell.dll
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\prcheck.dll
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\srp.exe
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\support.exe
Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Program Files\WinFixer\bak\wfxcwr.exe
Adware:Adware/Megasearch Not disinfected C:\System Volume Information\_restore{F6064AA9-DBED-4B46-9064-0C5D59DC0D70}\RP242\A0029862.dll
Spyware:Cookie/Media-motor Not disinfected C:\FOUND.002\FILE0009.CHK
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[whAgent.inf]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[WhAgent.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[whInstaller.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[WhSurvey.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[Webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0019.CHK[whiehlpr.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[whAgent.inf]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[WhAgent.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[whInstaller.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[WhSurvey.exe]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[Webhdll.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0020.CHK[whiehlpr.dll]
Adware:Adware/WebHancer Not disinfected C:\FOUND.002\FILE0033.CHK
Virus:Trj/Qhost.Y Disinfected C:\FOUND.004\FILE0000.CHK
Spyware:Cookie/Media-motor Not disinfected C:\FOUND.004\FILE0005.CHK
Spyware:Cookie/WinFixer Not disinfected C:\FOUND.006\FILE0013.CHK
Spyware:Cookie/Doubleclick Not disinfected C:\FOUND.006\FILE0019.CHK
Spyware:Cookie/Valueclick Not disinfected C:\FOUND.006\FILE0020.CHK
Spyware:Cookie/Traffic Marketplace Not disinfected C:\FOUND.006\FILE0025.CHK
Virus:Trj/Qhost.Y Disinfected C:\FOUND.005\FILE0001.CHK
Combo Fix Report

kathy paonessa - 06-11-16 22:56:45.68 Service Pack 1
ComboFix 06.11.9 - Running from: "C:\Documents and Settings\kathy paonessa\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\YOINSI.exe


((((((((((((((((((((((((((((((( Files Created from 2006-10-16 to 2006-11-16 ))))))))))))))))))))))))))))))))))


2006-11-16 14:40 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-11-09 12:57 13,952 –a—— C:\WINDOWS\system32\drivers\kbdhid.sys
2006-11-09 12:56 9,600 –a—— C:\WINDOWS\system32\drivers\hidusb.sys
2006-11-09 12:56 34,560 –a—— C:\WINDOWS\system32\drivers\hidclass.sys
2006-11-09 12:56 23,680 –a—— C:\WINDOWS\system32\drivers\hidparse.sys
2006-11-09 12:55 5,600 –a—— C:\WINDOWS\system32\drivers\WmVirHid.sys
2006-11-09 12:55 45,504 –a—— C:\WINDOWS\system32\drivers\WmXlCore.sys
2006-11-09 12:55 22,240 –a—— C:\WINDOWS\system32\drivers\WmFilter.sys
2006-11-09 12:55 159,744 –a—— C:\WINDOWS\system32\WmJoyFrc.dll
2006-11-09 12:55 10,144 –a—— C:\WINDOWS\system32\drivers\WmBEnum.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-11-14 13:46 ——– d——– C:\Documents and Settings\kathy paonessa\Application Data\DivX
2006-11-13 19:34 ——– d——– C:\Program Files\Security Task Manager
2006-11-09 12:55 ——– d——– C:\Program Files\Logitech
2006-10-10 09:10 737 –a—— C:\WINDOWS\system32\nt68rrtc12.sys
2006-10-03 15:49 ——– d——– C:\Program Files\iPod
2006-10-03 15:49 ——– d——– C:\Documents and Settings\kathy paonessa\Application Data\Apple Computer
2006-10-03 15:48 ——– d——– C:\Program Files\iTunes
2006-10-03 15:47 ——– d——– C:\Program Files\Apple Software Update
2006-10-02 13:04 806912 –a—— C:\WINDOWS\system32\divx_xx0c.dll
2006-10-02 13:04 806912 –a—— C:\WINDOWS\system32\divx_xx07.dll
2006-10-02 13:04 790528 –a—— C:\WINDOWS\system32\divx_xx11.dll
2006-10-02 13:04 635486 –a—— C:\WINDOWS\system32\DivX.dll
2006-10-01 23:13 ——– d——– C:\Program Files\triCerat
2006-10-01 22:44 54240 –a—— C:\Documents and Settings\kathy paonessa\Application Data\GDIPFONTCACHEV1.DAT
2006-09-29 13:17 ——– d——– C:\Program Files\BitTorrent
2006-09-29 02:46 ——– d——– C:\Program Files\MicroCase


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"MsnMsgr"="\"C:\\Program Files\\MSN Messenger\\MsnMsgr.Exe\" /background"
"ares"="\"C:\\Program Files\\Ares\\Ares.exe\" -h"
"Yahoo! Pager"="\"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet"
"BitTorrent"="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" –force_start_minimized"
"Microsoft Works Update Detection"="C:\\Program Files\\Microsoft Works\\WkDetect.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000004

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,a0,00,00,00,00,00,00,00,80,02,00,00,3a,02,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]
"kbddap"="C:\\WINDOWS\\System32\\kbddap.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\d_kmd.sys

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 06-11-16 22:57:41.98
C:\ComboFix.txt … 06-11-16 22:57



End
Adam,

Like I said in my first post, this started out to be a very heavily infected system. I was concerned about Look2me that AVG found and cleaned and Combofix would have detected it if it was present, and it is not. :thumbup:

Adam, AVG Free Anti Virus is about to be discontinued, very shortly, not sure when, if you want to keep it you may have to upgrade to the paid version. I also see an entry in your log for Norton Security Suite, do you still have this on your system or did you uninstall it. If you uninstalled it then we are going to have to remove the service. Please keep in mind that I am on a computer most likely 1000s of miles away from you and not sitting down in front of your PC, I can't help you unless you help me by answering some of the questions I ask you.

Panda picked up some bad programs, not sure if all or parts of it are still present.


Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply along with a new HJT log.
This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI