This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Amazon redirect

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi, I've followed the "what to do before posting" instructions regarding AVG and ATF Cleaner. I'm am unable to navigate to amazon.com. Updated and ran, spybot, adaware, avg virus scan and spyware scan, all to no avail. Any insight or help is appreciated. Thanks.


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 4:58:18 PM 2/11/2007

+ Scan result:



:mozilla.466:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.279:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.280:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.281:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.282:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.283:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.284:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.285:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.286:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.287:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.290:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.291:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.292:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.293:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.294:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.295:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.296:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.297:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.298:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.299:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.300:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.301:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.302:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.304:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.305:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.306:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.307:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.308:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.309:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.310:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.311:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.312:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.468:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.528:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.609:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.698:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.854:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.495:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.496:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.372:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.373:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.374:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.552:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.553:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.555:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.556:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.375:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.376:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.377:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.378:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.379:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.380:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.24:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.25:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.671:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.672:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.193:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.194:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.195:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.196:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.197:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.33:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.34:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.37:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.177:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.21:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.416:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.7:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.505:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.509:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.456:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.457:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.458:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.459:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.460:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.35:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.36:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.317:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.515:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.120:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.240:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.26:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.417:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.418:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.419:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.639:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.802:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.803:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.531:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.532:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.533:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.534:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.22:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.629:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.630:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.631:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.632:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.188:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.189:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.191:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.192:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.198:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.121:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.591:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.391:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.392:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.393:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.394:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.395:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.537:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.538:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.637:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.641:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.652:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.482:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.567:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.568:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.569:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.23:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.363:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.364:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.100:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.101:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.99:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.514:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.594:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.27:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.28:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.29:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.438:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.439:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.440:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.441:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.442:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.322:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.323:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.366:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.367:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.368:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.900:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.901:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.422:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.423:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.430:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.628:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.326:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.327:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.328:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.329:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.331:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.334:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.14:C:\Documents and Settings\The Bottomless\Application Data\Netscape\NSB\Profiles\t8ll7gt9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.489:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.490:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.491:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.492:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.352:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.623:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.384:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.385:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.386:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.387:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.388:C:\Documents and Settings\The Bottomless\Application Data\Mozilla\Firefox\Profiles\wt9kve95.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end





Logfile of HijackThis v1.99.1
Scan saved at 5:11:31 PM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\hphmon03.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Documents and Settings\The Bottomless\My Documents\My Downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159560141531
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE431134-FF33-4FB8-8861-DC0BD422679D}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{C55D39B9-A4D1-41AF-A6F4-6343E3B4FAFE}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
Clark Griswold :D

Welcome to Tom Coyote, your computer has been hijacked by the lovely people in the Ukraine.

85.255.112.0 - 85.255.127.255
Inhoster hosting company
OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine



You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please download FixWareout from one of these sites:
FixWareout Subratam
FixWareout Lonny
  • Save it to your desktop and run it.
  • Click Next, then Install,
  • Then make sure "Run fixit" is checked and click Finish.
  • The fix will begin; follow the prompts.
  • You will be asked to reboot your computer; please do so.
  • Your system may take longer than usual to load; this is normal.
  • At the end of the fix, you may need to restart your computer again.
Save the contents of the logfile C:\fixwareout\report.txt and post it into your next reply.

Now lets check some settings on your system. For (2000/XP) Only)
  • Go to Start > control panel.
  • If you are using Windows XP's Category View, select the Network and Internet Connections category otherwise double click on Network Connections.
  • Then right click on your default connection, usually local area connection for cable and dsl.
  • Left click on properties.
  • Click the Networking tab.
  • Double-click on the Internet Protocol (TCP/IP) item and select the radio dial that says Obtain DNS servers automatically
  • Press OK twice to get out of the properties screen and reboot if it asks.
    That option might not be available on some systems

  • Next Go start> Run type cmd and hit OK
  • Type in ipconfig /flushdns then hit enter
    (that space between g and / is needed)
  • Type exit hit enter



Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O17 - HKLM\System\CCS\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{AE431134-FF33-4FB8-8861-DC0BD422679D}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\..\{C55D39B9-A4D1-41AF-A6F4-6343E3B4FAFE}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185
O17 - HKLM\System\CS1\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185
O17 - HKLM\System\CS2\Services\Tcpip\..\{126720C3-629A-4BAA-A219-3455B3C58B09}: NameServer = 85.255.115.43,85.255.112.185
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.115.43 85.255.112.185




Post a the Fix Wareout report and a New HJT log please
Wow!! you were fast to respond. Thank you. Per you instructions, below are the requested logs. Thanks.


Fixwareout
Last edited 1/30/2007
Post this report in the forums please
…
Prerun check
»»»»» HKLM run and Winlogon System values

»»»»» System restarted
Reg Entries that were deleted
…
Random Runs removed from HKLM
…

»»»»» Misc files.

»»»»» Checking for older varients.

»»»»» Postrun check
»»»»» HKLM run
»»»»» Winlogon System value
"system"=""
»»»»»

PLEASE NOTE, There CAN be LEGITIMATE FILES LISTED IN THIS SECTION.

This WILL/CAN also list Legit Files, Submit them at Virustotal
Search five digit cs, dm kd and jb files.
»»»»»
»»»»» Current runs

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_10\\bin\\jusched.exe\""
"RecGuard"="C:\\Windows\\SMINST\\RecGuard.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"QUICKCARE"="C:\\Program Files\\Qwest\\QuickCare\\bin\\sprtcmd.exe /P QUICKCARE"
"QPService"="\"C:\\Program Files\\HP\\QuickPlay\\QPService.exe\""
"QlbCtrl"="%ProgramFiles%\\Hewlett-Packard\\HP Quick Launch Buttons\\QlbCtrl.exe /Start"
"nwiz"="nwiz.exe /installquiet /nodetect"
"NWEReboot"=""
"NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit"
"MsmqIntCert"="regsvr32 /s mqrt.dll"
"KernelFaultCheck"="%systemroot%\\system32\\dumprep 0 -k"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSPM"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -scheduler"
"hpWirelessAssistant"="C:\\Program Files\\hpq\\HP Wireless Assistant\\HP Wireless Assistant.exe"
"HP Software Update"="C:\\Program Files\\Hp\\HP Software Update\\HPWuSchd2.exe"
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe"
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"Cpqset"="C:\\Program Files\\Hewlett-Packard\\Default Settings\\cpqset.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"HPHmon03"="C:\\WINDOWS\\system32\\hphmon03.exe"
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"="C:\\Program Files\\Windows Media Player\\WMPNSCFG.exe"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

Hosts file was reset, If you use a custom hosts file please replace it


Logfile of HijackThis v1.99.1
Scan saved at 5:58:18 PM, on 2/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe
C:\Program Files\HP\QuickPlay\QPService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\hphmon03.exe
C:\WINDOWS\system32\HPHipm09.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Documents and Settings\The Bottomless\My Documents\My Downloads\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…n&pf=laptop
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [RecGuard] C:\Windows\SMINST\RecGuard.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [QUICKCARE] C:\Program Files\Qwest\QuickCare\bin\sprtcmd.exe /P QUICKCARE
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /nodetect
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] CHDAudPropShortcut.exe
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [HPHmon03] C:\WINDOWS\system32\hphmon03.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=pavilion&pf=laptop
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1159560141531
O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file:///C:/Program%20Files/AutoCAD%202002/AcDcToday.ocx
O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file:///C:/Program%20Files/AutoCAD%202002/InstBanr.ocx
O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file:///C:/Program%20Files/AutoCAD%202002/InstFred.ocx
O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file:///C:/Program%20Files/AutoCAD%202002/AcPreview.ocx
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AddFiltr - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\AddFiltr.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver - HP - C:\WINDOWS\system32\HPHipm09.exe
System behaves with astounding Awesomeness!! You rule! Thank you for your help, we appreciate it very much. Sincere thanks from the Griswolds.
Thats great :thumbup:

Clark, sometimes these infections bring other things along with it, I would like you to do a few things to make sure your system is clean.

Run this system cleaner
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



You need to clean out your System Restore , the infection we just cleaned is backed up in there and if you ever use it to revert your system to an earlier date you risk reinfecting yourself all over again.

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this
System Restore Tutorial <– If you need it



Now update your Java as it could be leaving a hole for the bad guys to get in.
  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment (JRE) 5.0 Update 11 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future



To make sure its all gone, run this free online virus scanner from Panda and if all is ok, I have some free tools for you to install to help keep you secure on the internet.


Run Panda's ActiveScan from here and perform a full system scan.
  • Once you are on the Panda site click the "Scan your PC" button
  • A new window will open…click the big "Check Now" button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
  • If you are on a slow connection it will take about 15 minuites for the scanner to load.
  • Click on "Local Disks" to start the scan
  • Once scan is done, click "see report" then "save report"
  • Save the log someplace you can find
  • 12. Reboot
  • Post the Panda scan results in your next reply
All I need to see is the Panda log, take your time, its been a long day and I will be back in the AM

Ken :D
As this issue appears resolved and there is no response from the user I am closing this thread.

This topic is being closed due to lack of response, if you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI