Next to the time (lower right corner of my monitor), is a 'circle' question mark which changes to a 'do-not' red symbol w/the diagonal line through it. Every five minutes or so it a pop up window extends from it saying
System Alert! and when you click on it it brings you to a webpage: Spydawn.com. Running Spybot and HighjackThis reveals a harddrive infected w/Trojans, etc. Any fixes around? Here are the logs that may help. I am not computer savvy.
thanks for any help
Michael
Logfile of HijackThis v1.99.1
Scan saved at 11:20:46 AM, on 3/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Michael\Desktop\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKCU\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O21 - SSODL: eitheror - {2016a466-91a2-43c6-97d8-2fd380f065ef} - C:\WINDOWS\system32\higehsg.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\Wrapper.conf (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
mnschur
Welcome to
Tom Coyote . I need you to run this quick scan for me . Post the results of the scan.
Please download
SmitfraudFix
Extract the content (a folder named
SmitfraudFix ) to your Desktop.
Open the
SmitfraudFix folder and double-click
smitfraudfix.cmd
Select option #1 -
Search by typing
1 and press "
Enter "; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
when doubleclicking the smithfraudfix.cmd folder, a box comes up with the following….and when i press any key….nothing happens.
Please advise
SmithFraudFix v2.157
Fichier Process.exe absent!
Dezippez la totalite de l'archive dans un dossier.
Process. exe file missing!
Unzip all the archive in a folder.
Press any key to continue…
You just didn't extract it correctly so the part of the program is missing.
Download it to your desktop and click on it to
extract the program to your desktop. Then on your
desktop you will have the
setup icon that you downloaded and also a folder named
Smitfraudfix . Open the folder and and double click on the
smitfraudfix icon ( it looks like a little gear ) and that will start the program going then follow the rest of the instructions.
Please download
SmitfraudFix
Extract the content (a folder named
SmitfraudFix ) to your Desktop.
Open the
SmitfraudFix folder and double-click
smitfraudfix.cmd
Select option #1 -
Search by typing
1 and press "
Enter "; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
ok…i think i did it correctly….here it is:
SmitFraudFix v2.157
Scan done at 18:51:14.62, Mon 03/26/2007
Run from C:\Documents and Settings\Michael\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode
»»»»»»»»»»»»»»»»»»»»»»»» Process
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\TurboTax\Deluxe 2006\32bit\ttax.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\cmd.exe
»»»»»»»»»»»»»»»»»»»»»»»» hosts
»»»»»»»»»»»»»»»»»»»»»»»» C:\
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web
»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32
C:\WINDOWS\system32\higehsg.dll FOUND !
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Michael
»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Michael\Application Data
»»»»»»»»»»»»»»»»»»»»»»»» Start Menu
»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Michael\FAVORI~1
»»»»»»»»»»»»»»»»»»»»»»»» Desktop
»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files
»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys
»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2016a466-91a2-43c6-97d8-2fd380f065ef}"="eitheror"
[HKEY_CLASSES_ROOT\CLSID\{2016a466-91a2-43c6-97d8-2fd380f065ef}\InProcServer32]
@="C:\WINDOWS\system32\higehsg.dll"
[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2016a466-91a2-43c6-97d8-2fd380f065ef}\InProcServer32]
@="C:\WINDOWS\system32\higehsg.dll"
»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""
»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""
»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32
»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection
»»»»»»»»»»»»»»»»»»»»»»»» End
ok you got it!
i am a friend of mnschur..
making sure he is ok
thanksa lot for your help.
Ok, I just wanted to confirm that your were infected with Smitfraud , which you are, SpyDawn is part of the Smitfraud family of trojans.
You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.
Download
SmitfraudFix
Extract the content (a folder named
SmitfraudFix ) to your Desktop. <– In case you have deleted it
Download and install the 30 day trial of
AVG Anti-Spyware 7.5 to your desktop.
Once you have downloaded AVG Anti-Spyware 7.5 , locate the icon on the desktop and double-click it to launch the set up program. Once the setup is complete you will need run Ewido and update the definition files. On the main screen select the icon Update then select the Update now link. Next select the Start Update button, the update will start and a progress bar will show the updates being installed. Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab. Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this Under Reports Select Automatically generate report after every scan Un-Select Only if threats were found Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode Go to Start> Shut Off your Computer> Restart As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly. This will bring up a menu. Use the Up and Down Arrow Keys to scroll up to SAFEMODE Then press the Enter on your Keyboard
Tutorial if you need it
How to boot into Safemode
Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd Select option #2 - Clean by typing 2 and press "Enter " to delete infected files. You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection. The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter". The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log. The report can also be found at the root of the system drive, usually at
C:\rapport.txt
Clean out your Temporary Internet files. Proceed like this: Quit Internet Explorer and quit any instances of Windows Explorer. Click Start> Control Panel and then double-click Internet Options. On the General tab , click Delete Files under Temporary Internet Files. In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK. On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK. Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop. Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan . AVG will now begin the scanning process, be patient this may take a little time. Once the scan is complete do the following: If you have any infections you will prompted, then select Apply all actions Next select the Reports icon at the top. Select the Save report as button in the lower left hand of the screen and save it to a text file on your system make sure to remember where you saved that file, this is important Close AVG Anti-Spyware 7.5 IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:
Reboot normally.
Open the SmitfraudFix folder and double-click smitfraudfix.cmd Select option #3 - Delete Trusted zone by typing 3 and press Enter Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter. Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.
Post the log from Smitfraud fix, the AVG Spyware log and a New HJT log please
the anti spy scan took an hour. 254 bugs found. when i re-ran the smithfraud scan and chose option #3, there was no log created. I hope that's a good sign….then i re-ran the Highjack This scan. here are the AVG spyware and Hijack logs:
Logfile of HijackThis v1.99.1
Scan saved at 11:07:17 PM, on 3/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTSVCCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\jre\bin\java.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Michael\Desktop\HijackThis.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [nTrayFw] C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe
O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTSVCCDA.EXE
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcAppFlt.exe
O23 - Service: Forceware Web Interface (ForcewareWebInterface) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe" -k runservice (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Maya 7 PLE Documentation Server (mple7docserver) - Unknown owner - C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\wrapper.exe" -s "C:\Program Files\Alias\Maya 7.0 Personal Learning Edition\docs\Wrapper.conf (file missing)
O23 - Service: ForceWare IP service (nSvcIp) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 10:48:46 PM 3/26/2007
+ Scan result:
C:\System Volume Information\_restore{CBDB666D-63E8-40D1-B41E-73E89354042E}\RP100\A0035225.ini -> Adware.Qworke : Cleaned.
C:\System Volume Information\_restore{CBDB666D-63E8-40D1-B41E-73E89354042E}\RP112\A0036436.exe -> Adware.SpyDawn : Cleaned.
C:\Documents and Settings\paul\Local Settings\Temp\laf73.tmp -> Adware.WorldSecurityOnline : Cleaned.
C:\System Volume Information\_restore{CBDB666D-63E8-40D1-B41E-73E89354042E}\RP114\A0036663.dll -> Adware.WorldSecurityOnline : Cleaned.
C:\System Volume Information\_restore{CBDB666D-63E8-40D1-B41E-73E89354042E}\RP100\A0035209.dll -> Downloader.Zlob.bom : Cleaned.
:mozilla.540:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.541:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.542:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.100:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.101:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.102:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.336:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.520:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.544:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.547:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.657:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.71:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.72:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.80:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.81:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.82:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.83:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.84:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.85:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.86:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.88:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.89:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.90:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.91:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.92:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.93:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.94:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.96:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.97:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.98:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.99:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@wpni.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\paul\Cookies\paul@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.452:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.453:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.415:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.838:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.839:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.840:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.699:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.443:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.444:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.446:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.447:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.448:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.449:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.48:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.49:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.114:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.115:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.116:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.117:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.118:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.124:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.45:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.643:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.738:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.739:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.248:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.253:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.254:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.255:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.256:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.147:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.151:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.152:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.154:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.758:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.287:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.430:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.48:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.25:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Estat : Cleaned.
:mozilla.610:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.442:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.445:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.46:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.100:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.383:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.384:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.385:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.391:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.418:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.460:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.462:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.633:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.668:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.674:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.213:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.214:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.748:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.749:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.37:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.38:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.39:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.40:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.41:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.42:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.789:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.791:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.792:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.91:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.92:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.93:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.35:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.39:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.322:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.211:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.212:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.284:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.285:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.286:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.339:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.111:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.33:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.477:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.47:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.49:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.50:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.51:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.52:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Guest\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.696:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.697:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.369:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.370:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.578:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.579:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.580:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.581:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.43:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.44:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.450:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.47:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.55:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.56:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.57:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.58:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.59:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.65:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.66:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.67:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.68:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.69:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.70:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.76:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.77:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.78:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.79:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.85:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.53:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.54:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.55:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.56:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.57:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.58:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.12:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.205:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.206:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.207:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.208:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.209:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.210:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.59:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.60:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.61:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.62:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.63:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.23:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.24:C:\Documents and Settings\paul\Application Data\Mozilla\Firefox\Profiles\5nywbr32.default\cookies.txt -> TrackingCookie.Sextracker : Cleaned.
:mozilla.648:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.652:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Skype : Cleaned.
:mozilla.277:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.278:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.279:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.280:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.281:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.282:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.283:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.480:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.481:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.482:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.483:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.484:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.485:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.486:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.487:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.488:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.249:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.250:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.251:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.252:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.454:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Guest\Cookies\guest@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.797:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.834:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.267:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.268:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.269:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.270:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.271:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.272:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.273:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.274:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.275:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.276:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.14:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.75:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\46uf62v3.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.682:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.590:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.345:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.148:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.149:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.150:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.153:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.243:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.244:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.245:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.246:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.247:C:\Documents and Settings\Michael\Application Data\Mozilla\Firefox\Profiles\p6d3fnty.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
::Report end
mnschur
You did very well
Spydawn is gone
There is no log with Option # 3 so not to worry. The rest of your log looks fine, but lets do a few things to clean you up.
AVG Anti Spyware is a trial and one of the best programs on the internet to clean your system, its yours to keep after the trial, you can still
Check for Updates ,
run the scan and remove what it finds, you will just lose the background guard feature after the trial. All it found where a couple of registry entries for Spydawn and removed them along with Cookies. Open
AVG and go to the
Quarantine folder and remove it all, nothing in there you want to keep on your system.
I need you to go to the
System Restore Program and flush it all out because Spydawn is backed up in that program and if you ever have to use it to revert your system to an earlier date you can reinfect yourself all over again. I can't stress enough how important it is to
Create a New Restore Point.
System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points
Turn off System Restore.
Right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore on all Drives. Click Apply , and then click OK.
Reboot your System
Turn ON System Restore.
Right-click My Computer. ClickProperties. Click the System Restore tab. UN-Check Turn off System Restore on all Drives. Click Apply, and then click OK.
Create a new Restore Point <– Very Important Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this System Restore Tutorial <– If you need it
Now I need you to update your Java as it is leaving a hole in your system that lets this garbage in.
Your Java is out of date and leaving your system vulnerable. Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment) It should have an icon next to it:
[external image: Posted Image]
Select it and click Remove. Reboot your system. Then go to the Sun Microsystems and install the update Java Runtime Environment (JRE) 5.0 Update 11 <–This is what you need to download and install.If you chose the online installation, it will prompt you to run the program. If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it. Then after install you can verify your installation here Sun Java Verify I like to to do the offline installation and save the setup file in case I may need it in the future
The rest of your log looks fine
How is your system running now??
The system is running fine (it never didn't, except for the constant pop-up from the icon near the time display.) Thank you , SO MUCH!
I will continue to follow the post-spydawn directions you gave me.
Glad all is well
Malware Complaints
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.
How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.Tom Coyote TonyKlein CastleCops Grinler BleepingComputer Geeks To Go Dslreports
Here are some free programs to install, don't leave home without them Spybot Search and Destroy 1.4
Check for Updates/ Immunize and run a Full System Scan on a regular basis.
Ad-Aware SE Personal 1.06
Check for Updates and run a Full System Scan on a regular basis.
Spyware Blaster It will prevent most spyware from ever being installed.
Spyware Guard It offers realtime protection from spyware installation attempts.
Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
IE-Spyad
IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
Zone Alarm Here is a free Firewall from Zone Labs , I wouldn't access the internet without it.
Thanks for stopping by
Tom Coyote , I'm glad I was able to help you.
Glad we could be of assistance.
This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.
Coyote's Installed programs for prevention:
http://forums.tomcoyote.org/index.php?showtopic=31418
The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.
Visit the CoyoteStore
http://TomCoyote.org/coyotestore.php