This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

csrss.exe running at 100% can you help

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

After I start my system the csrss.exe continues to run at 100%. tried getting info from microsoft. Ran virus scans with Norton antivirus 2006 and online scan. Turns up nothing. this is slowing my system down and I need help. I think it's a bug but don't know where to look.




Logfile of HijackThis v1.99.1
Scan saved at 12:23:07 AM, on 1/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\emitray.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\WINDOWS\system\svchost.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Microsoft Windows OneCare Live\WinSSUI.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Larry McRae\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://sms.feedbuk.com/jfaa/68846230?0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C6EAF0F9-89FD-47F6-9DCC-4DA56F725352} - C:\WINDOWS\system32\ratmontr.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [NvEventCenter] C:\WINDOWS\system\svchost.exe /w
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138372990341
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Emagic USB System Tray Service (emitray) - Emagic Soft- und Hardware GmbH - C:\WINDOWS\system32\emitray.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
_________________________________
Welcome to the Forums.

The fixes we will use are specific to your problems and should only be used for this issue on this machine.

Please only use this topic to reply to. Do not start another thread.
If any other issues arise let me know.
The process is not instant. Please continue to review my answers until I tell you your machine is clear. Absence of symptoms does not mean that everything is clear. So lets do this to the end!
Please if you decide to seek help at another forum let us know. There is a shortage of helpers and tying 2 of us up is a waste of time.
If you have any questions about any advice given here please STOP and ask!


system\svchost.exe

It looks like you have been infected by a backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Its very possible that anything could have been installed on your computer by the remote attacker, including opening other backdoors and installing rootkits. While we can attempt to clean what we see in your logs, we can't guarantee that your computer will be completely in the clear since we have no way of knowing that has been done to the computer. Your computer could be completely compromised at this moment. It may be prudent to backup your information, reformat, and reinstall.

More information on Remote Access Trojans can be found
http://antivirus.about.com/library/weekly/aa100400a.htm]here

I suggest you do the following immediately:
  • Call all of your banks, credit card companies, financial institutions and inform them that you may be a victim of identity theft and to put a watch on your accounts or change all your account numbers.
  • From a clean computer, change *all* your online passwords – for email, for banks, financial accounts, PayPal, eBay, online companies, any online forums or groups you belong to.
  • Do NOT change passwords or do any transactions while using the infected computer because the attacker will get the new passords and transaction information.
If, however, you decide that the computer is not used for any sensitive work, or if you do not wish to reformat at this time, I can help you clean your computer to the best of my abilities.

Should you have any questions, please feel free to ask.

Please let me know what you decide to do in your next post.

Should you decide to clean this machine start by doing the following.





______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O4 - HKLM\..\Run: [NvEventCenter] C:\WINDOWS\system\svchost.exe /w


______________________

PLEASE READ THIS PART CAREFULLY

We are about to delete a file that is no good. The file name is svchost.exe The tricky part here is this:
There are good files of this exact name on your computer DO NOT DELETE THEM if you ever see them.
We will use a tool that will delete only what we ask it to
.


____________________________
Please download the Killbox by Option^Explicit

Note: In the event you already have Killbox, this is a new version that I need you to download.
Save it to your desktop.
Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\WINDOWS\system\svchost.exe

Return to Killbox, go to the File menu, and choose Paste from Clipboard.

Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let me know if you receive this message!).


If your computer does not restart automatically, please restart it manually.

If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run Killbox, click here to download and run missingfilesetup.exe. Then try Killbox again.



______________________________
Submit a file to Jotti
Please go here : http://virusscan.jotti.org/
On top of the page there is a field to add the filepath, copy and paste these filepaths: 1 at a time.


C:\WINDOWS\system32\ratmontr.dll



Then hit Submit
The scan will take a while before the result comes up so please be patient.
Then copy the result and post it here in this thread.

If Jotti's service load is too high, you can use the following scanner instead:
http://www.virustotal.com/xhtml/index_en.html





______________________________

Download and install CCleaner from here


If you use either the Firefox or Mozilla browsers, the box to uncheck for Cookies is on the Applications tab, under Firefox/Mozilla.
  • Set Cookie Retention.
    Click on the Options block on the left, then choose Cookies.
    Under the Cookies to delete pane, highlight any cookies you would like to retain permanently (those companies or sites with which you regularly visit or do business), and click the right arrow > to move them to the Cookies to keep pane.
  • Reset Temp File Removal for Regular Use.
    Click on the Options block on the left. Select the Advanced button.
    Check "Only delete files in Windows Temp folders older than 48 hours".


    Now run the program and click on Run Cleaner
    ( Do not use the Issues block to clean anything with this program. It is for experts only and it is risky).
___________________________________
Download AVG Anti-Spyware.
  • Install AVG Anti-Spyware.
  • Launch AVG by double-clicking on the icon.
  • The program will now open to the main screen.
  • You will need to update AVG to the latest definition files.
  • At the top of the main screen click Update.
  • Then in the Manual Update section, click on Start Update.
[*]The update will start and a progress bar will show the updates being installed.

[*]When updates are completed, close AVG.

If you are having problems with the updater, you can use this link to manually update AVG.
AVG manual updates
Do not use it yet.


________________________________________
Safe mode:
Please reboot to safe mode:
After the very first black screen start tapping the
F8 key untill prompted with a list choose safe
mode.




_________________________________________
AVG Part 2
AVG
Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
Click on scanner
Click on Settings
Under How to act
Choose quarintine

Under Reports check automatically create report after every scan.
Now back to the scan tab andClick on Complete system scan

Let the program scan the machine .
When finished click apply all actions.


Exit AVG.
It will save a log in C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports

Reboot normaly.

Post the log from AVG and a new Hijackthis log.


In your next reply I would like to see:
  • A new HJT log
  • The report from Jottis or virus total
  • The report from AVG
These are the results from Jotti's malware scan 2.99-TRANSITION_TO_3.00-R1 Last file scanned at least one scanner reported something about: sxs.exe (MD5: 580c046c676aead42b29f48dff8babd8), detected by: Scanner Malware name AntiVir TR/Dldr.Sma.dat.4.B ArcaVir Trojan.Downloader.Delf.Avo Avast Win32:Qqpass-AK AVG Antivirus Downloader.Generic2.QNT BitDefender Generic.Malware.SPPkg.B417C5B7 ClamAV X Dr.Web Trojan.DownLoader.13881 F-Prot Antivirus W32/Downloader.gen10 F-Secure Anti-Virus Trojan-Downloader.Win32.Delf.avo Fortinet X Kaspersky Anti-Virus Trojan-Downloader.Win32.Delf.avo NOD32 X Norman Virus Control W32/Delf.RZM VirusBuster novirus:Packed/FSG VBA32 Trojan-Downloader.Win32.Delf.avo And these are the results from Virus total Complete scanning result of "ratmontr.dll", received in VirusTotal at 01.25.2007, 06:41:45 (CET). Antivirus Version Update Result AntiVir 7.3.0.26 01.24.2007 ADSPY/Stud.B Authentium 4.93.8 01.24.2007 no virus found Avast 4.7.936.0 01.24.2007 Win32:Trojano-3384 AVG 386 01.24.2007 Adware Generic.LRJ BitDefender 7.2 01.25.2007 no virus found CAT-QuickHeal 9.00 01.24.2007 no virus found ClamAV devel-20060426 01.24.2007 no virus found DrWeb 4.33 01.25.2007 no virus found eSafe 7.0.14.0 01.24.2007 no virus found eTrust-InoculateIT 23.73.123 01.25.2007 no virus found eTrust-Vet 30.3.3347 01.24.2007 no virus found Ewido 4.0 01.24.2007 Adware.Stud Fortinet 2.85.0.0 01.24.2007 no virus found F-Prot 3.16f 01.23.2007 no virus found F-Prot4 4.2.1.29 01.23.2007 no virus found Ikarus T3.1.0.27 01.24.2007 not-a-virus:AdWare.Win32.Stud.b Kaspersky 4.0.2.24 01.25.2007 not-a-virus:AdWare.Win32.Stud.b McAfee 4948 01.24.2007 no virus found Microsoft 1.1904 01.25.2007 no virus found NOD32v2 2004 01.24.2007 a variant of Win32/Adware.BHO.AA Norman 5.80.02 01.24.2007 W32/Stud.D Panda 9.0.0.4 01.25.2007 Adware/KeenValue Prevx1 V2 01.25.2007 no virus found Sophos 4.13.0 01.24.2007 no virus found Sunbelt 2.2.907.0 01.22.2007 no virus found TheHacker 6.0.3.155 01.24.2007 Adware/Stud.b UNA 1.83 01.24.2007 Adware.Stud.FBE0 VBA32 3.11.2 01.24.2007 suspected of Trojan-Downloader.Agent.49 VirusBuster 4.3.19:9 01.24.2007 no virus found
:angry: I left this info out File size: 10383 bytes MD5: c1d284e39eda38ac05d8958b2805f597 SHA1: 63578b6e4279dfc7133a84340e18ab8f9df82d3b packers: UPX packers: UPX packers: UPX packers: UPX
When I first started my system this morning everything seemed to be fine but now after using it for about 30 minutes the csrss.exe is back at 95 %. I had my firewall blocking all access. now that I am allowing access everything appears normal

I have a new scan from totalvirus. It is below also


Logfile of HijackThis v1.99.1
Scan saved at 11:50:06 AM, on 1/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Microsoft Windows OneCare Live\Antivirus\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\emitray.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Microsoft Windows OneCare Live\Firewall\msfwsvc.exe
C:\Program Files\Microsoft Windows OneCare Live\winss.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Program Files\Microsoft Windows OneCare Live\WinSSUI.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Larry McRae\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C6EAF0F9-89FD-47F6-9DCC-4DA56F725352} - C:\WINDOWS\system32\ratmontr.dll (file missing)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [DigidesignMMERefresh] C:\Program Files\Digidesign\Drivers\MMERefresh.exe
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138372990341
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Emagic USB System Tray Service (emitray) - Emagic Soft- und Hardware GmbH - C:\WINDOWS\system32\emitray.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


And these are the results from Virus total

Complete scanning result of "ratmontr.dll", received in VirusTotal at 01.25.2007, 06:41:45 (CET).

Antivirus Version Update Result
AntiVir 7.3.0.26 01.24.2007 ADSPY/Stud.B
Authentium 4.93.8 01.24.2007 no virus found
Avast 4.7.936.0 01.24.2007 Win32:Trojano-3384
AVG 386 01.24.2007 Adware Generic.LRJ
BitDefender 7.2 01.25.2007 no virus found
CAT-QuickHeal 9.00 01.24.2007 no virus found
ClamAV devel-20060426 01.24.2007 no virus found
DrWeb 4.33 01.25.2007 no virus found
eSafe 7.0.14.0 01.24.2007 no virus found
eTrust-InoculateIT 23.73.123 01.25.2007 no virus found
eTrust-Vet 30.3.3347 01.24.2007 no virus found
Ewido 4.0 01.24.2007 Adware.Stud
Fortinet 2.85.0.0 01.24.2007 no virus found
F-Prot 3.16f 01.23.2007 no virus found
F-Prot4 4.2.1.29 01.23.2007 no virus found
Ikarus T3.1.0.27 01.24.2007 not-a-virus:AdWare.Win32.Stud.b
Kaspersky 4.0.2.24 01.25.2007 not-a-virus:AdWare.Win32.Stud.b
McAfee 4948 01.24.2007 no virus found
Microsoft 1.1904 01.25.2007 no virus found
NOD32v2 2004 01.24.2007 a variant of Win32/Adware.BHO.AA
Norman 5.80.02 01.24.2007 W32/Stud.D
Panda 9.0.0.4 01.25.2007 Adware/KeenValue
Prevx1 V2 01.25.2007 no virus found
Sophos 4.13.0 01.24.2007 no virus found
Sunbelt 2.2.907.0 01.22.2007 no virus found
TheHacker 6.0.3.155 01.24.2007 Adware/Stud.b
UNA 1.83 01.24.2007 Adware.Stud.FBE0
VBA32 3.11.2 01.24.2007 suspected of Trojan-Downloader.Agent.49
VirusBuster 4.3.19:9 01.24.2007 no virus found


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:23:01 AM 1/25/2007

+ Scan result:



C:\tdd.exe -> Adware.MaxSearch : No action taken.
C:\WINDOWS\system32\ratmontr.dll -> Adware.Stud : No action taken.
D:\Downloads\Waves Files\Waves IRx v5.2 Crack - Keygen - Serial.zip/crackfix.exe -> Adware.Stud : No action taken.
:mozilla.307:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.308:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.309:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.310:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.311:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.312:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.313:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.314:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.315:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.316:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.317:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.318:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.319:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.320:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.321:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.322:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.323:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.324:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.325:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.326:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.327:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.328:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.329:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.330:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.331:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.332:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.333:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.334:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.368:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.532:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.653:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.689:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.881:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@2o7[3].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten_mcrae@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Kirsten McRae\Local Settings\Temp\Cookies\kirsten mcrae@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
:mozilla.378:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.380:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.381:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.772:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Addynamix : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Addynamix : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@admarketplace[1].txt -> TrackingCookie.Admarketplace : No action taken.
:mozilla.168:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.169:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.170:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.171:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.172:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.173:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.174:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.175:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.701:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.702:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.787:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.827:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.828:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.829:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Adserver : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Adserver : No action taken.
:mozilla.23:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.24:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.25:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.62:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.68:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.69:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten_mcrae@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
:mozilla.106:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.341:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.108:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.95:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.460:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.461:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.462:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.467:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.468:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.10:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.11:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.12:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.13:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.14:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@centrport[2].txt -> TrackingCookie.Centrport : No action taken.
:mozilla.503:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@com[1].txt -> TrackingCookie.Com : No action taken.
:mozilla.182:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Coremetrics : No action taken.
:mozilla.776:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Dbbsrv : No action taken.
:mozilla.26:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.281:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.541:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Local Settings\Temp\Cookies\kirsten mcrae@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.840:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Enhance : No action taken.
:mozilla.165:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.166:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Euroclick : No action taken.
:mozilla.379:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Falkag : No action taken.
:mozilla.102:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.103:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.97:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.98:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.99:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.250:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.251:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.431:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.432:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.433:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.543:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.658:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.659:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.801:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.802:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.803:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.804:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.805:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.846:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.870:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.262:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hitslink : No action taken.
:mozilla.841:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Hotlog : No action taken.
:mozilla.560:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Linksynergy : No action taken.
:mozilla.561:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Linksynergy : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Liveperson : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken.
:mozilla.527:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Masterstats : No action taken.
:mozilla.257:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.258:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.179:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.180:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.181:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.811:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Overture : No action taken.
:mozilla.91:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.92:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.93:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.94:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][1].txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.641:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.643:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Qksrv : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@qksrv[2].txt -> TrackingCookie.Qksrv : No action taken.
:mozilla.135:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.136:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.715:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Revenue : No action taken.
:mozilla.336:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.337:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.338:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.339:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
:mozilla.236:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.237:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.238:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.239:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.240:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.241:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.562:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.387:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.388:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.389:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.390:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.391:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.392:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.393:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.394:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.395:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.396:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.398:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.525:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.526:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.463:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
:mozilla.124:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.125:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.126:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.127:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.128:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.129:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.130:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.131:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.84:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.275:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.276:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.277:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.278:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.279:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.280:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Valuead : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@webstat[2].txt -> TrackingCookie.Web-stat : No action taken.
:mozilla.403:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Webtrendslive : No action taken.
:mozilla.74:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.75:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.76:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.77:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.78:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.79:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.80:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.81:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.82:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten [removed][2].txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.272:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.273:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.274:C:\Documents and Settings\Kirsten McRae\Application Data\Mozilla\Firefox\Profiles\nm3g2rbi.default\cookies.txt -> TrackingCookie.Zedo : No action taken.
C:\Documents and Settings\Kirsten McRae\Cookies\kirsten mcrae@zedo[1].txt -> TrackingCookie.Zedo : No action taken.
C:\FIXWMI.CMD -> Trojan.Zapchast : No action taken.
C:\Program Files\eMule\Incoming\Access Password Recover v1.00 crack.zip/Access Password Recover v1.00 crack.exe/td.exe -> Worm.Agent.v : No action taken.
C:\Program Files\eMule\Incoming\Access Password Recover v1.00 crack.zip/Access Password Recover v1.00 crack.exe/zgo.exe -> Worm.Agent.v : No action taken.
C:\Program Files\eMule\Incoming\NORTON INTERNET crack.zip/NORTON INTE
You are running HJT directly from the desktop.
Create a folder called HJT either in C: or My documents and place the
hijackthis.exe in there.
This will ensure we have back ups made and it doesn't get deleted .






______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked


O2 - BHO: (no name) - {C6EAF0F9-89FD-47F6-9DCC-4DA56F725352} - C:\WINDOWS\system32\ratmontr.dll (file missing)



Were your AVG log says "No action Taken" Should read "Quaruntined"
You'll need to rerun it after setting it up this way.

AVG
Close all open windows/programs/folders. Have nothing else open while ewido performs its scan!
Click on scanner
Click on Settings
Under How to act
Choose quarintine


___________________
__________________

1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


__________________
__________________

_________________________________
Please do an online scan with Kaspersky Online Scanner
Click on Kaspersky Online Scanner
You will be promted to install an ActiveX component from Kaspersky, Click Yes.
The program will launch and then start to download the latest definition files.
Once the scanner is installed and the definitions downloaded, click Next.
Now click on Scan Settings
In the scan settings make sure that the following are selected:
Scan using the following Anti-Virus database:

Extended (If available otherwise Standard)
Scan Options:
Scan Archives
Scan Mail Bases
Click OK

Now under select a target to scan select My Computer

The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.

Now click on the Save as Text button:

Save the file to your desktop.

Copy and paste that information in your next post.


_________________
_________________
In your next reply I would like to see:
  • A new HJT log
  • The report from Combo fix
  • The AVG report..As long as it says Quarintiened you won't need to post it.
  • Was a bit confused about how things are running. Are they running OK now or is it back up to 90+ % ?
So far things have been better. Thanks for the scan tools. There are a couple of things that I am still looking for or should I say on the look out for.

I was surprised that the AVG scan said no action taken because I sellected quarintine. I will do as you have suggested and let you know the results. Thanks so very much for your assistance
Bob, Things look really good now. My system is running very well. There was one thing that I had to do differently from your instructions. The Online scan would not work. The Kaspersky could only be done with a download of the actual virus software. Thanks for letting me know about this site and software.

Opening the Kapersky file, I found that it is 117MB so I will copy the top portion which shows the actions it took against the 2 viruses it found, plus I'll include the file location. if you require more information, please let me know. I plan to delete this file after your next post.

I had recently installed Windows new One Live Software which is their new all in one process, virus , firwall etc. I removed it now that I have the Kapersky. It seems to function much better.

With The AVG software, although it said no action taken, The files had been deleted or moved into quarintine. I was going to try and post the names of those files but the program won't let me copy the names of the quarintined files. Thank you so very much for your help. I will be making a donation to you later today.



Logfile of HijackThis v1.99.1
Scan saved at 2:31:51 PM, on 1/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\Brmfrmps.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\emitray.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\HJT\HijackThis.exe


R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1138505245\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [OneCareUI] "C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe AcPro7_0_8
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: APC UPS Status.lnk = ?
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\scieplugin.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.1\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2ED9BC2B-4DF1-472E-9B5E-55477D2C97F5} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {3451DEDE-631F-421C-8127-FD793AFC6CC8} - https://www-secure.symantec.com/techsupp/as…rl/SymAData.cab
O16 - DPF: {44990200-3C9D-426D-81DF-AAB636FA4345} (Symantec SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {44990301-3C9D-426D-81DF-AAB636FA4345} (Symantec Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138372990341
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - https://www-secure.symantec.com/techsupp/asa/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Kaspersky Anti-Virus 6.0 (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 6.0\avp.exe" -r (file missing)
O23 - Service: Brother Popup Suspend service for Resource manager (brmfrmps) - Unknown owner - C:\WINDOWS\system32\Brmfrmps.exe" -service (file missing)
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Emagic USB System Tray Service (emitray) - Emagic Soft- und Hardware GmbH - C:\WINDOWS\system32\emitray.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.2\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe


"Larry McRae" - 07-01-25 23:48:47 Service Pack 2
ComboFix 07-01-25 - Running from: "C:\Documents and Settings\Larry McRae\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\Program Files\INSTALL.LOG


((((((((((((((((((((((((((((((( Files Created from 2006-12-25 to 2007-01-25 ))))))))))))))))))))))))))))))))))


2007-01-25 18:11 d——– C:\HJT
2007-01-25 01:04 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-25 01:04 d——– C:\Program Files\Grisoft
2007-01-25 00:59 d——– C:\Program Files\CCleaner
2007-01-25 00:29 d——– C:\!KillBox
2007-01-24 17:57 d——– C:\DOCUME~1\LARRYM~1\Application Data\AdobeUM
2007-01-24 17:55 d——– C:\DOCUME~1\LARRYM~1\Application Data\Intuit
2007-01-24 08:43 d——– C:\04e280312eb542e6a8f135a5fd
2007-01-23 23:37 81,024 –a—— C:\WINDOWS\system32\drivers\msfwdrv.sys
2007-01-23 23:36 105,856 –a—— C:\WINDOWS\system32\drivers\msfwhlpr.sys
2007-01-23 23:35 67,784 –a—— C:\WINDOWS\system32\drivers\MpFilter.sys
2007-01-23 23:35 d—-c— C:\WINDOWS\system32\DRVSTORE
2007-01-23 23:34 d——– C:\Program Files\MSXML 4.0
2007-01-23 23:32 d——– C:\Program Files\Microsoft Windows OneCare Live
2007-01-23 23:32 d——– C:\80a1058daa48ab8423
2007-01-23 09:19 28,672 –a—— C:\WINDOWS\system32\drivers\CO_Mon.sys
2007-01-23 01:07 d——– C:\DOCUME~1\LARRYM~1\Application Data\Windows Desktop Search
2007-01-23 01:06 d——– C:\DOCUME~1\LARRYM~1\Application Data\Adobe
2007-01-23 00:00 d——– C:\DOCUME~1\ADMINI~1\Application Data\Adobe
2007-01-22 08:38 0 –a—— C:\CONFIG.SYS
2007-01-22 08:38 0 –a—— C:\AUTOEXEC.BAT
2007-01-22 00:25 d——– C:\Program Files\BFD
2007-01-21 15:44 d——– C:\DOCUME~1\KIRSTE~1\Application Data\Windows Desktop Search
2007-01-21 06:37 d——– C:\c45ef511df726ecf10332cca1f
2007-01-20 11:23 d——– C:\Program Files\Microsoft Small Business
2007-01-20 00:37 d——– C:\Program Files\Microsoft SQL Server
2007-01-19 15:47 d——– C:\Program Files\Microsoft Works
2007-01-19 15:45 d——– C:\Program Files\Microsoft.NET
2007-01-19 15:42 d——– C:\WINDOWS\SHELLNEW
2007-01-19 15:41 dr-h—– C:\MSOCache
2007-01-18 18:38 d——– C:\Program Files\BDD 2007
2007-01-18 18:38 d——– C:\Distribution
2007-01-18 18:37 33,792 ——— C:\WINDOWS\system32\mmcperf.exe
2007-01-18 18:37 184,320 ——— C:\WINDOWS\system32\microsoft.managementconsole.dll
2007-01-18 18:37 106,496 ——— C:\WINDOWS\system32\mmcfxcommon.dll
2007-01-18 18:37 d——– C:\WINDOWS\system32\en
2007-01-18 17:48 d——– C:\audio
2007-01-17 12:07 32 –a—— C:\WINDOWS\system32\msvcsv60.dll
2007-01-17 12:06 d——– C:\Program Files\IK Multimedia
2007-01-17 11:24 d——– C:\Program Files\Common Files\iZotope
2007-01-17 10:44 d——– C:\trakit6
2007-01-17 08:57 d——– C:\Program Files\iZotope
2007-01-15 23:37 d——– C:\Program Files\Runtime Software
2007-01-13 10:07 d——– C:\WINDOWS\ie7updates
2007-01-11 21:42 d——– C:\DOCUME~1\KIRSTE~1\Application Data\Viewpoint
2007-01-10 09:25 d——– C:\Program Files\CoreFTP
2007-01-09 01:53 d——– C:\WINDOWS\WBEM
2007-01-09 01:35 d——– C:\Program Files\PSP Nitro
2007-01-09 01:23 2,949,120 –a—— C:\WINDOWS\system32\PSP 84.dll
2007-01-09 01:23 d——– C:\Program Files\PSP 84
2007-01-09 01:02 286,720 –a—— C:\WINDOWS\iun506.exe
2007-01-09 01:02 d——– C:\Program Files\PSP MasterQ 1.0
2007-01-09 00:59 d——– C:\Program Files\PSP MixPack 1.8
2007-01-08 22:51 d——– C:\Program Files\PSP MixPack 1.8 Demo
2007-01-08 22:47 d——– C:\Program Files\PSP 84(2)
2007-01-08 18:05 d–h-c— C:\WINDOWS\ie7
2007-01-08 18:03 d——– C:\WINDOWS\network diagnostic
2007-01-08 12:23 860,160 –a—— C:\WINDOWS\system32\PSP MixTreble.dll
2007-01-08 12:23 712,704 –a—— C:\WINDOWS\system32\PSP MixPressor.dll
2007-01-08 12:23 647,168 –a—— C:\WINDOWS\system32\PSP MixSaturator.dll
2007-01-08 12:23 483,328 –a—— C:\WINDOWS\system32\PSP MixBass.dll
2007-01-08 00:23 673,610 –a—— C:\WINDOWS\unins000.exe
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\sslibsd.dll
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\sslibree.dll
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\sslibqqe.dll
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\sslibgs.dll
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\slibqqe.dll
2007-01-08 00:23 2,756 –a—— C:\WINDOWS\system32\slibjy.dll
2007-01-08 00:23 d——– C:\Program Files\Sonalksis
2007-01-07 22:36 659,456 –a—— C:\WINDOWS\iun6002.exe
2007-01-07 22:36 d——– C:\Program Files\PSP VintageWarmer 1.6.5
2007-01-07 22:35 6,533,120 –a—— C:\WINDOWS\system32\PSP VintageWarmer.dll
2007-01-07 22:35 2,568,192 –a—— C:\WINDOWS\system32\PSP VintageMeter.dll
2007-01-07 22:29 458,752 –a—— C:\WINDOWS\system32\PSP StereoController.dll
2007-01-07 22:29 450,560 –a—— C:\WINDOWS\system32\PSP StereoAnalyser.dll
2007-01-07 22:29 434,176 –a—— C:\WINDOWS\system32\PSP PseudoStereo.dll
2007-01-07 22:29 372,736 –a—— C:\WINDOWS\system32\pspsedx.dll
2007-01-07 22:29 372,736 –a—— C:\WINDOWS\system32\pspscdx.dll
2007-01-07 22:29 372,736 –a—— C:\WINDOWS\system32\pspsadx.dll
2007-01-07 22:29 372,736 –a—— C:\WINDOWS\system32\psppsdx.dll
2007-01-07 22:29 368,640 –a—— C:\WINDOWS\system32\PSP StereoEnhancer.dll
2007-01-07 22:29 d——– C:\Program Files\PSP
2007-01-07 22:09 d——– C:\WINDOWS\PSP MasterComp
2007-01-07 22:09 d——– C:\Program Files\PSP MasterComp 1.0.0
2007-01-07 22:05 d——– C:\Program Files\Lexicon PSP42
2007-01-06 11:09 d——– C:\Program Files\Common Files\Tmp
2007-01-06 11:04 d——– C:\Program Files\u-he
2007-01-06 11:04 d——– C:\Program Files\Celemony
2007-01-05 17:39 d——– C:\Program Files\PerformanceTest
2007-01-03 10:00 d——– C:\DOCUME~1\LOCALS~1\Application Data\Allume Systems
2007-01-03 09:55 d——– C:\Program Files\Allume
2007-01-03 09:55 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Allume Systems
2006-12-30 08:54 d——– C:\Program Files\iPod
2006-12-28 03:03 d——– C:\DOCUME~1\KIRSTE~1\Application Data\Apple Computer
2006-12-28 02:58 d——– C:\Program Files\Apple Software Update


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-24 17:35 ——– d——– C:\Program Files\mozilla firefox
2007-01-24 13:00 ——– d—s—- C:\DOCUME~1\LARRYM~1\Application Data\microsoft
2007-01-23 23:45 ——– d——– C:\Program Files\norton antivirus
2007-01-23 23:45 ——– d——– C:\Program Files\Common Files\symantec shared
2007-01-23 23:43 ——– d——– C:\Program Files\symantec
2007-01-23 23:37 262 –a—— C:\DOCUME~1\LARRYM~1\Application Data\winsscookie.txt
2007-01-23 02:08 ——– d——– C:\DOCUME~1\LARRYM~1\Application Data\macromedia
2007-01-23 02:00 ——– d——– C:\DOCUME~1\LARRYM~1\Application Data\mozilla
2007-01-23 01:05 ——– d——– C:\Program Files\web publish
2007-01-23 01:04 ——– d——– C:\DOCUME~1\LARRYM~1\Application Data\identities
2007-01-22 23:42 ——– d——– C:\Program Files\registry mechanic
2007-01-22 09:13 ——– d——– C:\Program Files\sony
2007-01-19 16:13 ——– d——– C:\Program Files\windows desktop search
2007-01-19 08:17 ——– d——– C:\Program Files\emule
2007-01-18 18:02 ——– d–h—– C:\Program Files\installshield installation information
2007-01-18 17:46 ——– d——– C:\Program Files\steinberg
2007-01-17 12:03 ——– d——– C:\Program Files\emagic
2007-01-12 01:54 ——– d——– C:\Program Files\waves
2007-01-09 18:33 ——– d——– C:\Program Files\digidesign
2007-01-06 10:33 ——– d——– C:\Program Files\quicken
2007-01-05 16:46 ——– d——– C:\Program Files\java
2006-12-30 08:54 ——– d——– C:\Program Files\quicktime
2006-12-30 08:54 ——– d——– C:\Program Files\itunes
2006-12-19 16:35 ——– d——– C:\Program Files\mtv networks
2006-12-19 16:30 ——– d——– C:\Program Files\Common Files\real
2006-12-19 11:23 ——– d——– C:\Program Files\windows media connect 2
2006-12-12 20:58 ——– d——– C:\Program Files\sampletank 2
2006-12-12 12:14 ——– d——– C:\Program Files\sony setup
2006-12-06 20:49 ——– d——– C:\Program Files\Common Files\adobe
2006-12-06 11:25 1200128 –a—— C:\WINDOWS\system32\cfhd.dll
2006-12-04 13:26 ——– d——– C:\Program Files\windows live local for outlook
2006-12-04 13:22 ——– d——– C:\Program Files\virtual earth 3d
2006-12-03 02:03 ——– d——– C:\Program Files\bibleworks 7
2006-12-01 16:25 ——– d——– C:\Program Files\vstplugins
2006-11-16 19:47 524288 –a—— C:\WINDOWS\opuc.dll
2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-11-07 21:03 6049280 ——— C:\WINDOWS\system32\ieframe.dll
2006-11-07 21:03 50688 ——— C:\WINDOWS\system32\msfeedsbs.dll
2006-11-07 21:03 458752 ——— C:\WINDOWS\system32\msfeeds.dll
2006-11-07 21:03 413696 –a—— C:\WINDOWS\system32\vbscript.dll
2006-11-07 21:03 231424 –a—— C:\WINDOWS\system32\webcheck.dll
2006-11-07 21:03 180736 ——— C:\WINDOWS\system32\ieui.dll
2006-11-07 21:03 156160 –a—— C:\WINDOWS\system32\msls31.dll
2006-11-07 03:27 382976 –a—— C:\WINDOWS\system32\iedkcs32.dll
2006-11-07 03:27 229376 –a—— C:\WINDOWS\system32\ieaksie.dll
2006-11-07 03:26 71680 –a—— C:\WINDOWS\system32\admparse.dll
2006-11-07 03:26 55296 –a—— C:\WINDOWS\system32\iesetup.dll
2006-11-07 03:26 54784 –a—— C:\WINDOWS\system32\ie4uinit.exe
2006-11-07 03:26 43008 –a—— C:\WINDOWS\system32\iernonce.dll
2006-11-07 03:26 152064 –a—— C:\WINDOWS\system32\ieakeng.dll
2006-11-07 03:26 13312 –a—— C:\WINDOWS\system32\ieudinit.exe
2006-11-07 03:26 123904 –a—— C:\WINDOWS\system32\advpack.dll
2006-11-07 03:25 161792 –a—— C:\WINDOWS\system32\ieakui.dll
2006-11-04 20:25 1321744 –a—— C:\WINDOWS\system32\msxml6.dll
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll
2006-10-29 11:33 95048 –a—— C:\WINDOWS\system32\bcmms32.dll
2006-10-26 14:10 33088 –a—— C:\WINDOWS\system32\fm20enu.dll
2006-10-26 14:10 1190688 –a—— C:\WINDOWS\system32\fm20.dll
2006-10-26 13:45 293376 –a—— C:\WINDOWS\system32\wisptis.exe
2006-10-26 13:45 207360 –a—— C:\WINDOWS\system32\inked.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"updateMgr"="C:\\Program Files\\Adobe\\Acrobat 7.0\\Acrobat\\AdobeUpdateManager.exe AcPro7_0_7"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy2ZS\\Surround Mixer\\CTSysVol.exe /r"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"IPHSend"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"nwiz"="nwiz.exe /install"
"CTHelper"="CTHELPER.EXE"
"CTXFIREG"="CTxfiReg.exe"
"HostManager"="C:\\Program Files\\Common Files\\AOL\\1138505245\\ee\\AOLSoftware.exe"
"Acrobat Assistant 7.0"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"GrooveMonitor"="\"C:\\Program Files\\Microsoft Office\\Office12\\GrooveMonitor.exe\""
"OneCareUI"="\"C:\\Program Files\\Microsoft Windows OneCare Live\\winssnotify.exe\""
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
@=""

[HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
"SetDefaultMIDI"="MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\runonce]
"SetDefaultMIDI"="MIDIDEF.EXE /s:'Creative SoundFont Synthesizer' /w:'SB Audigy'"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Acrobat Speed Launcher.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Acrobat Speed Launcher.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\WINDOWS\\Installer\\{AC76BA86-1033-0000-7760-000000000002}\\SC_Acrobat.exe "
"item"="Adobe Acrobat Speed Launcher"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma Loader.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma Loader"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Gamma Loader.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^MiniEYE-MiniREAD Launch.lnk]
"backup"="C:\\WINDOWS\\pss\\MiniEYE-MiniREAD Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\INFINI~1\\eyeQ\\ARLaunch.exe "
"item"="MiniEYE-MiniREAD Launch"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\MiniEYE-MiniREAD Launch.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
"backup"="C:\\WINDOWS\\pss\\QuickBooks Update Agent.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Intuit\\QUICKB~1\\QBUpdate\\qbupdate.exe "
"item"="QuickBooks Update Agent"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\QuickBooks Update Agent.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk]
"backup"="C:\\WINDOWS\\pss\\Quicken Scheduled Updates.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Quicken\\bagent.exe "
"item"="Quicken Scheduled Updates"
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Quicken Scheduled Updates.lnk"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ControlCenter2.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="brctrcen"
"hkey"="HKLM"
"command"="C:\\Program Files\\Brother\\ControlCenter2\\brctrcen.exe /autorun"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSoftware"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1138505245\\ee\\AOLSoftware.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndexSearch]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IndexSearch"
"hkey"="HKLM"
"command"="C:\\Program Files\\ScanSoft\\PaperPort\\IndexSearch.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PaperPort PTD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="pptd40nt"
"hkey"="HKLM"
"command"="C:\\Program Files\\ScanSoft\\PaperPort\\pptd40nt.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SBDrvDet]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SBDrvDet"
"hkey"="HKLM"
"command"="C:\\Program Files\\Creative\\SB Drive Det\\SBDrvDet.exe /r"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SetDefPrt]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="BrStDvPt"
"hkey"="HKLM"
"command"="C:\\Program Files\\Brother\\Brmfl04a\\BrStDvPt.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SSBkgdupdate"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Scansoft Shared\\SSBkgdUpdate\\SSBkgdupdate.exe\" -Embedding -boot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ViewMgr]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ViewMgr"
"hkey"="HKLM"
"command"="C:\\Program Files\\Viewpoint\\Viewpoint Manager\\ViewMgr.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"StuffIt Task Manager"=dword:00000002

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=""
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="Groove GFS Stub Execution Hook"
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\OneCareMP

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0




~ ~ ~ ~ ~ ~ ~ ~ Hijackthis Backups ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

backup-20070125-183817-525
O2 - BHO: (no name) - {C6EAF0F9-89FD-47F6-9DCC-4DA56F725352} - (no file)

Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\MP Scheduled Quick Scan.job
C:\WINDOWS\tasks\MP Scheduled Scan.job
C:\WINDOWS\tasks\MP Scheduled Signature Update.job

Completion time: 07-01-25 23:54:01


Kaspersky

Scan My Computer
—————-
Scanned: 872236
Detected: 2
Untreated: 0
Start time: 1/26/2007 12:51:42 AM
Duration: 12:26:12
Finish time: 1/26/2007 1:17:54 PM


Detected
——–
Status Object
—— ——
deleted: Trojan program Trojan-Spy.HTML.Fraud.gen (modification) Email message body: Outlook\Personal Folders\Top of Personal Folders\Inbox\[From:PayPal][Subject:Message has a suspicious part : Payment confirmation for StarbucksStore][Time:2006/10/17 12:34:25]/HTMLBody
deleted: Trojan program Trojan-Downloader.Win32.IstBar.nj File: C:\Program Files\eMule\Incoming\(Serial) motionartist 3.0.ace//toolBar.exe
______________________________
HJT
Run hijackthis and choose scan only and place a check by the following lines if present.
Close all other windows and browsers except HJT before clicking on Fix Checked

O16 - DPF: {82774781-8F4E-11D1-AB1C-0000F8773BF0} (DLC Class) - https://transfers.ds.microsoft.com/FTM/Tran…ransferCtrl.cab <https://transfers.ds.microsoft.com/FTM/TransferSource/grTransferCtrl.cab>


______________________________________


Ok these 2 folders
C:\80a1058daa48ab8423
C:\c45ef511df726ecf10332cca1f
I have no idea what they could be or contain. But not looking good.
Please do this.

___________________________________
Reconfigure Windows XP to show hidden files::

Click Start. My Computer.
Select the Tools menu Folder Options. Select the View Tab.
Under the Hidden files and folders heading select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (recommended)" option.
Uncheck the "Hide file extensions for known file types" option.
Click Yes to confirm. Click OK.

Have a look in those folders for me and let me know some of the files names inside them.
Especially if they contain an EXE file .
DO NOT CLICK ANY OF THE FILES IN THERE.

C:\80a1058daa48ab8423
C:\c45ef511df726ecf10332cca1f



___________________________________
Search for and remove
Now I want you to search for and delete the following file . If you need help finding it
Click start /search/ all files and folders/ look for More advanced options. once in there select the first 3 boxes.
Please just remove the files/folders I listed in BOLD


C:\Program Files\eMule\Incoming\(Serial) motionartist 3.0.ace/toolBar.exe

EMule itself is a safe program. It is up to you to be carefull what you download with it.




________________________________
I see that Viewpoint may be installed.

Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software,
most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player's components.
Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval
but doesn't spy or do anything "bad". In 2006, this may change, read from here
http://www.clickz.com/showPage.html?page=3561546

I suggest you remove the program now. Go to Start > Settings > Control Panel > Add/Remove Programs and remove the following programs if present:
  • Viewpoint
  • Viewpoint Manager
  • Viewpoint Media Player
If AOL is present, to prevent it from being recreated every time you run the AOL software:
  • Open AOL
  • Go to Help on the toolbar
  • Select About AOL
  • Hit Ctrl D and a secret panel can be accessed which will allow you to disable all desktop and IM features associated with Viewpoint.
Another way to prevent Viewpoint from being recreated every time you run the AOL software is:
  • Click C:\Program Files\AOL 9.0\Jiti (a hidden folder).
  • Rename viewpoint.exe to viewpoint.old.



Go to
Start/control panel/add remove programs ;
And Uninstall

view Point manager


__________________________
Optional fixes




You have iTunesHelper.exe running at Startup. iTunesHelper.exe is a process belonging to Itunes MP3 streaming tool
by Apple which allows you to play MP3's. This process speeds up iTunes when it starts, and the program also monitors
for connected iPod devices. This program is not required to start automatically as you can start it manually if you need it.
It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis.
This is the item to fix in HijackThis:

O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe

nwiz.exe is a part of NVidia's Nview features installable alongside its graphics hardware products. This application will give the user access to additional features which
allow the configuration of up to 32 monitors on a host or to expand the desktop across many monitors. This program is not required to start automatically as you can start it
manually if you need it. It is advised that you disable this program so that it does not take up necessary resources. It may be worthwhile to fix it with HijackThis.
This is the item to fix in HijackThis:

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install


____________________________________

Firewalls

A few words on Microsofts firewall. It only works in one direction. Incoming.
That means if something gets by it you would never know it was trying
to contact the internet.
Example: A bad program installs itself. You would never know it was contacting the internet.
Downloading other nasties and so forth.

If you decide to run one of these you should be certain Microsofts firewall is disabled.
To disable it.

I will list a few free firewalls for you. These are good (free) firewalls:

Never run 2 firwalls together. They will interfere with each other.
So just download and install one!



Zone Alarm Easiest to use
Kerio
Sygate
Outpost



In your next reply I would like to see:
  • Let me know whats inside of those 2 folders please.
____________
Just a note for you.

[From:PayPal][Subject:Message has a suspicious part : Payment confirmation for StarbucksStore]

1. Your inbox for outlook express. Always be extremely care full opening things that say there from from Pay pal. They will always address you with your full name.
This never changes. They will not address you as..Dear customer..dear Paypal user or member and the like.
Never ever click on a link from any Pay pal email ever ever ever…realy bad idea!!!
If you use pay pal always go to their site using internet explorer or such and do what it is you have to that way.
Hello Bob, Did as you requested. The C:\Program Files\eMule\Incoming\(Serial) motionartist 3.0.ace/toolBar.exe was deleted in the Kasersky Scan. These new folders are Windows folders. They may have something to do with their new releases. I am running the new Office 2007 Release Software not the beta. c:\c45ef511df726ecf10332cca1f contains this txt file: msxml6-KB927977-enu-x86 c:\80a1058daa48ab8423 Contains several Windows Live Onecare setup files………this is the software I uninstalled earlier today. c:\ca4cb18a95eb1dc078c0fa contains Windows malicious software removal tool There were no hidden files in any of the folders. I will remove the Viewpoint and itunes apps. this si something my daughter probably did. Of the firewalls that you listed, which is the best or better. the Kaspersky software seems to be good. Any suggestions that you may have would be greatly appreciated. Thanks
:thumbup: Thanks for the info on those folders.


Of the firewalls.. Start with ZoneAlarm as it is the easiest to use. Once you get used to that you can try any of the others. They all can be removed from add\ remove programs before you try another.



Great news ! [external image: Posted Image]

Your log now appears to be clean.

Lets do a few things to tidy up.
Please do these in the order I suggest!


___________________________________
If we have set your computer to see all files and folders we must reprotect them.

UNDO SHOW ALL FILES
click on the My Computer icon.
Select the Tools menu and click Folder Options.
After the new window appears select the View tab.
Deselect in the checkbox labeled Display the contents of system folders.
Deselect the checkbox labeled Show hidden files and folders.
Select the checkmark from the checkbox labeled Hide file extensions for known file types.
Replace the checkmark from the checkbox labeled Hide protected operating system files.
Press the Apply button and then the OK .
Now many important files are safe.


___________________________
Please run the ccleaner program once again.

Then…


___________________________________
Please create a 'clean' System Restore Point:
The reason for doing this is in case you need system restore you don't put back all we just took out.
Right click My Computer
Then Propeties then system restore
Place a check mark by turn off system restore
Click APPLY
Windows will give you a warning click yes
REBOOT

Now go right back to the same place and unchecksystem restore
Click APPLYand OK





___________________________________
A few things to help with possible threats
SpywareBlaster

Install SpywareBlaster

SpywareBlaster will add a large list of programs and sites to your Internet Explorer settings that will protect you from accidentally running or downloading known malicious programs.
After the installation, click Download Latest Protection Updates. When it finishes, click Enable All Protection.


______________________________
SiteHound

http://www.firetrust.com/firetrustsitehound.html

This tool bar will help protect you from.

Over 4,000 fake bank and credit sites.
Tens of thousands of pornographic
and adult sites.
The never ending fake phishing sites.
Malicious sites, which can infect you
with spyware and adware if you visit
them.
Sites to download software which
may infect your computer with
spyware, a virus or adware


___________________________________
Download and keep these updated and run weekly if you don't already have them.

Adaware
Tutorial

spybot seach & destroy
Tutorial




___________________________________
Download and Install a HOSTS File
A Hosts file is a plain text file which prevents your computer from connecting to malware and spyware sites by redirecting the connection request to 127.0.0.1, which is your local address. If you use a proxy server, or if you are on AOL, be sure to read the special instructions.
You can download the MVPS Hosts File and see a HOSTS file tutorial here :
This website also contains useful tips, and links to other resources and utilities.


___________________________________
Make your Internet Explorer more secure
1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click on the Security tab
3. Click the Internet icon so it becomes highlighted.
4. Click on Default Level and click Ok
5. Click on the Custom Level button.

Change the Download signed ActiveX controls to Prompt
Change the Download unsigned ActiveX controls to Disable
Change the Initialise and script ActiveX controls not marked as safe to Disable
Change the Installation of desktop items to Prompt
Change the Launching programs and files in an IFRAME to Prompt
Change the Navigate sub-frames across different domains to Prompt

When all these settings have been made, click on the OK button.
If it prompts you as to whether or not you want to save the settings, press the Yes button.

6. Next press the Apply button and then the OK to exit the Internet Properties page.



Safe and Happy Surfing. :)
Thank You! :rofl: I cannot tell you what this means to me. Will installing the programs that you suggested interfere with Kaspersky Virus Software. I will Definetely add these apps. Just want to be sure that I don't crate any major conflicts. Now I can rest. Thanks :D
Those programs I mentioned should not interfere with Kasperskys. If after installing any of them you do not like them or you think they are causing a problem they will uninstall easily enough through add/remove programs.
On that note did you pay for Kasperskys ? Is it an active anti virus program ? I wasn't aware that they had an active/real time anti virus program .

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI