This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijack This Log

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Sorry to repost….but I did not want to put a reply in my first post since I thought it would then get ignored…

My problem is that my browser will randomly re-route sites to "adult" material sites. I have run spybot s&d and adaware and my sites are still getting hijacked.

here is my log again..thanks for any help!!

Help Me!!!!

Here is my log:

Logfile of HijackThis v1.99.1
Scan saved at 9:48:29 PM, on 3/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{624FCAA6-19D1-40BD-97D9-6B83609928B8}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{6A8EB451-19DD-44BA-9CE9-6E9C6289C44B}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA00B832-A324-4C14-AA64-4B36F3259426}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hi,stellablue96and welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
dan
Hi stellablue96

You have "BitTorrent"installed". This shows as Clean on the MWR list of P2P programs.
However, these type of programs add an unsecure access route for malware. It is your decision whether to uninstall these or to leave it.

Even when a program like this is not infected itself, it will still bring malware into your system because more than half of all files available for download from peer-to-peer networks have been deliberately infected with some form of malware. I strongly recommend that you remove this program from your system.

WARNING!!! While I am assisting you in removing the malware from your system, do not download anything other than the tools that I ask you to download. Do not indulge in any form of peer-to-peer file sharing. In addition, it is necessary that you stay away from all dubious sites, including MySpace, until we have finished with the clean up. Otherwise, we may be unable to remove the malware from your system.
___________________

Make a folder on the desktop , name it "HJT" locate "HijackThis.exe" copy and paste the file into the new folder you created on the desktop "HJT"
If we need a backup, shoud things not go as we would like, we have our backup.
Please do this before we continue with the fix.

_____________________


You may want to print out these instructions for reference, since you will have to restart your computer during the fix.

Please do not delete anything unless instructed to.


Run hijackthis.
Click Do a System Scan Only. Put a Check in the box on the left side on these:

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O17 - HKLM\System\CCS\Services\Tcpip\..\{624FCAA6-19D1-40BD-97D9-6B83609928B8}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{6A8EB451-19DD-44BA-9CE9-6E9C6289C44B}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\..\{AA00B832-A324-4C14-AA64-4B36F3259426}: NameServer = 85.255.113.206,85.255.112.76
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.113.206 85.255.112.76

Close ALL windows and browsers except HijackThis and click "Fix checked"



Please download FixWareout from one of these sites:
http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

Save it to your desktop and run it. Click Next, then Install, make sure "Run fixit" is checked and click Finish.
The fix will begin; follow the prompts.
You will be asked to reboot your computer; please do so.
Your system may take longer than usual to load; this is normal.

Once the desktop loads a text that will open (report.txt) Please save this file, you'll need to post it with a new HijackThis log.



Next:
Click Start> Run> type in CMD tap enter key
Copy/Paste: ipconfig /flushdns


Now lets check some settings on your system.
Enter your Control Panel and double-click on Network Connections

Then right click on your Default Connection
Usually Local Area Connection for Cable and DSL
Left click on Properties
Double-Click on the Internet Protocol (TCP/IP) item
Select the radio dial that says Obtain DNS Servers Automatically
Press OK twice to get out of the properties screen and reboot if it asks


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two


Reboot and "copy/paste" the text file (report.txt) and a new Hijackthis log

Please include new HJT log in your next post
Thanks dan
hi dan…thanks for the help…

here is the hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 9:55:45 AM, on 4/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\imapi.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_11\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Here is the other log:


Fixwareout Last edited 2/11/2007
Post this report in the forums please
…
»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdhgp.exe"

»»»»» System restarted

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….

Search five digit cs, dm, kd, jb, other, files.
The following files NEED TO BE SUBMITTED to one of the following URL'S for further inspection.



Click browse, find the file then click submit.
http://www.virustotal.com/flash/index_en.html
Or http://virusscan.jotti.org/

»»»»» Other
C:\WINDOWS\Temp\kdhgp.ren 63799 08/04/2004



»»»»» Current runs
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelZeroConfig"="C:\\Program Files\\Intel\\Wireless\\bin\\ZCfgSvc.exe"
"IntelWireless"="C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe /tf Intel PROSet/Wireless"
"NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"avast!"="C:\\PROGRA~1\\ALWILS~1\\Avast4\\ashDisp.exe"
"nwiz"="nwiz.exe /installquiet"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"Aim6"=""
"BitTorrent"="\"C:\\Program Files\\BitTorrent\\bittorrent.exe\" –force_start_minimized"
….
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»
i just looked at some of the sites that were giving me problems before and they are now all working. do I need to do anything else. thank you soooo much!!!
I have some more work to do with your log so don't go to far. I have to work shortly and will be back on your log in the morning. dan
Hi stellablue96

Have you decided to keep bittorrent?

From my first Instruction you still haven't done this:

Make a folder on the desktop , name it "HJT" locate "HijackThis.exe" copy and paste the file into the new folder you created on the desktop "HJT"
If we need a backup, shoud things not go as we would like, we have our backup.
Please do this before we continue with the fix.
__________________

Ewido is now known as ( AVG Anti-Spyware.)

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
Dont use yet!

Re-boot into safe mode

  • Next, please reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
  • Instead of Windows loading as normal, a menu should appear use arrow up to highlight
  • Select the first option, to run Windows in Safe Mode hit enter.
  • For additional help in booting into Safe Mode, see the following site: HERE
Right click start, In the drop down menu click "Explore" Then navigate to:

C:\WINDOWS\Temp\ <========Empty contents of this folder

_________


Run AVG Anti-Spyware

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)

      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
_______________________

please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Your Java is out of date Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of Java Runtime Environment (JRE) 6u1.
  • Scroll down to where it says " Java Runtime Environment (JRE) 6".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
Please include new HJT log, AVG Anti-Spyware log and kaspersky log
in your next post
Thanks dan
Hi again Dan..

So…I think I did the HJT desktop folder correct this time. I also uninstalled Bittorrent…but it still seems to be there?!?!

Here are my logs:

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 9:54:44 PM, on 4/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Kaspersky Log

Sunday, April 01, 2007 9:36:40 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 2/04/2007
Kaspersky Anti-Virus database records: 289783
Scan Settings
Scan using the following antivirus database extended
Scan Archives true
Scan Mail Bases true
Scan Target My Computer
C:\
D:\
Scan Statistics
Total number of scanned objects 47335
Number of viruses found 2
Number of infected objects 3 / 0
Number of suspicious objects 0
Duration of the scan process 01:16:02

Infected Object Name Virus Name Last Action
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cert8.db Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\history.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\key3.db Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\parent.lock Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Eric Gutman\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Identities\{F6F3DEE3-D394-46C0-840E-13AAF12D0924}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx/[Date 7 Mar 2007 00:32:44 -0800]/Buy_Rx_Here.html Infected: Trojan.JS.Redirector.b skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Identities\{F6F3DEE3-D394-46C0-840E-13AAF12D0924}\Microsoft\Outlook Express\Hotmail - Deleted Items.dbx Mail MS Outlook 5: infected - 1 skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Eric Gutman\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Eric Gutman\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Temp\Perflib_Perfdata_2f4.dat Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\aswMaiSv.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log Object is locked skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\master.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\mastlog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\model.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\modellog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdbdata.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\msdblog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\tempdb.mdf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Data\templog.ldf Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\ERRORLOG Object is locked skipped
C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\LOG\log_94.trc Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0B7ABBFE-2EFE-43D1-9155-251D1A5041E7}\RP35\A0037943.exe Infected: Trojan.Win32.DNSChanger.in skipped
C:\System Volume Information\_restore{0B7ABBFE-2EFE-43D1-9155-251D1A5041E7}\RP35\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{78EF7D14-8566-440B-882E-68A7C83F39B9}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\Antivirus.Evt Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\ODiag.evt Object is locked skipped
C:\WINDOWS\system32\config\OSession.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_2a8.dat Object is locked skipped
C:\WINDOWS\Temp\_avast4_\Webshlock.txt Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.


AVG Log


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:08:10 PM 4/1/2007

+ Scan result:



:mozilla.168:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.169:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.170:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.171:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.172:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.173:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.174:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.175:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.176:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.177:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.178:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.179:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.180:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.181:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.182:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.183:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.184:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.185:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.186:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.187:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.188:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.189:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.190:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.191:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.192:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.193:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.194:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.195:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.196:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.197:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.198:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.200:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.201:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.202:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.203:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.204:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.205:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.512:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.537:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.599:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.600:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.640:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.696:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.716:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.774:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.782:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.801:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.809:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Eric Gutman\Cookies\eric_gutman@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.706:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.707:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.222:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.378:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.379:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.380:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.663:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.664:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.665:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.666:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.568:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.569:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.104:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.106:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.107:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.33:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.836:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.82:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.77:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.78:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.81:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.83:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.84:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.449:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.450:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.451:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.452:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.576:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.802:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.548:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.224:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.629:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.708:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.709:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.710:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.711:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.60:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.630:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.310:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.311:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.312:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.313:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.370:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.304:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.305:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.306:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.307:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.308:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.309:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.137:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.377:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.577:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.579:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.609:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.610:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.615:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.878:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.884:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.432:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.433:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.434:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.593:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.678:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.679:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.759:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.760:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.854:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.850:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.851:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.385:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.387:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.388:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.389:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.784:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.785:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.786:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.787:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.823:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.824:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.210:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.211:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.223:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.752:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.685:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.485:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.486:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.487:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.488:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.489:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.845:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.846:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.847:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.61:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.62:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.63:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.64:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.214:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.215:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.216:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.217:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.424:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.288:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.289:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.290:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.291:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.292:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.293:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.294:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.295:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.296:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.297:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Eric Gutman\Cookies\eric_gutman@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.411:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.412:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.413:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.414:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.415:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.416:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.417:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.358:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.359:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.360:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.361:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.362:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.363:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.364:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.365:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.366:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.368:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.369:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.154:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.701:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.73:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.74:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.75:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.76:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.85:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.280:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.281:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.282:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.283:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.284:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.285:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.286:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.287:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.314:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.519:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.436:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.591:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.158:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.159:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.160:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.161:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.162:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.556:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.557:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.558:C:
Hi stellablue96

So…I think I did the HJT desktop folder correct this time


Not quite, but I think I will get you there before we finish.
Go to your desktop and in an open space right click mouse in the menu click new then folder. Name this folder "HJT" now go to this location "C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe"
I want you to find "HijackThis.exe" right click mouse copy or ctrl+c and find the new folder you created and named "HJT" then paste "HijackThis.exe" in to it.
see how you go.

____________________________

Your AVG a-s report cuts off, can you re-send it please.


Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit

Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

C:\Program Files\BitTorrent <==========This foder

Go to outlook express > deleted items click on > file > folder > compact

Let me know how things are now?

Please include new HJT log
in your next post
Thanks dan
Here are my new logs. Everything seems to be running good. When I ran the Kaspersky log (last night) it said i had a trojan in my system…should I be worried about this???

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:08:10 PM 4/1/2007

+ Scan result:



:mozilla.168:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.169:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.170:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.171:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.172:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.173:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.174:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.175:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.176:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.177:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.178:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.179:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.180:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.181:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.182:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.183:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.184:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.185:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.186:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.187:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.188:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.189:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.190:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.191:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.192:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.193:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.194:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.195:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.196:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.197:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.198:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.199:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.200:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.201:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.202:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.203:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.204:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.205:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.512:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.537:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.599:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.600:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.640:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.696:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.716:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.774:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.782:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.801:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.809:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Eric Gutman\Cookies\eric_gutman@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.706:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.707:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.222:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.378:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.379:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.380:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.663:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.664:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.665:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.666:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.568:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.569:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.104:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.105:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.106:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.107:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.108:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.33:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.836:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.82:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.77:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.78:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.81:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.83:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.84:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.449:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.450:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.451:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.452:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.576:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.802:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.548:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.224:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.629:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.708:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.709:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.710:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.711:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.60:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.630:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.310:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.311:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.312:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.313:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.370:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.304:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.305:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.306:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.307:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.308:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.309:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.137:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.377:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.577:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.579:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.609:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.610:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.615:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.878:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.884:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.432:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.433:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.434:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.593:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.678:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.679:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.759:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.760:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.854:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.850:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.851:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.385:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.387:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.388:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.389:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.784:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.785:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.786:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.787:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.823:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.824:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.210:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.211:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.223:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.752:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.685:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.485:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.486:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.487:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.488:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.489:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.845:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.846:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.847:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.61:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.62:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.63:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.64:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.214:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.215:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.216:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.217:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.424:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.288:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.289:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.290:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.291:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.292:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.293:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.294:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.295:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.296:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.297:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Eric Gutman\Cookies\eric_gutman@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.411:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.412:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.413:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.414:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.415:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.416:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.417:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.358:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.359:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.360:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.361:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.362:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.363:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.364:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.365:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.366:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.368:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.369:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.154:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.209:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.701:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.73:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.74:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.75:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.76:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.85:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.280:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.281:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.282:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.283:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.284:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.285:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.286:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.287:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.314:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.519:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.436:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.591:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.158:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.159:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.160:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.161:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.162:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.556:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.557:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.558:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.559:C:\Documents and Settings\Eric Gutman\Application Data\Mozilla\Firefox\Profiles\wiudwowv.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{0B7ABBFE-2EFE-43D1-9155-251D1A5041E7}\RP28\A0028882.exe -> Trojan.DNSChanger.ih : Cleaned.
C:\System Volume Information\_restore{0B7ABBFE-2EFE-43D1-9155-251D1A5041E7}\RP28\A0028883.exe -> Trojan.DNSChanger.ih : Cleaned.


::Report end

HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 1:55:34 PM, on 4/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\PROGRA~1\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

Thanks Dan!

~Sarah
Hi,stellablue96, can I see the kaspersky log also please ;) Hi, Ignore this Instruction I already have your log, will be back with you tomorrow. When I shall deal with little items to tidy up. dan
Hi stellablue96

When I ran the Kaspersky log (last night) it said i had a trojan in my system…should I be worried about this???

We will address this when we reset system restore, just needs flushing nothing to worry about.

Looking over your log, it seems you don't have any evidence of a third party firewall.

As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

1) ZoneAlarm
2) Agnitum
3) Sunbelt/Kerio
4) Comodo

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

After those steps, please post a fresh HijackThis log

You should go here and update Adobe Reader 6.0.1 to the latest version, Adobe Reader® 7.0
______________________
here is the newest hjt log:

Logfile of HijackThis v1.99.1
Scan saved at 8:49:45 PM, on 4/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Documents and Settings\Eric Gutman\Desktop\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SQL Server (MSSMLBIZ) (MSSQL$MSSMLBIZ) - Unknown owner - c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sMSSMLBIZ (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Hi stellablue96


Well done!

This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
    You can find instructions on how to enable and re enable system restore here:

    Windows XP System Restore Guide
    re-enable system restore with instructions from tutorial above.

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialise and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein.

Stand up and be Counted.

NOW is the time you can start to hit back at the people who infected you.
[external image: Posted Image]
Please take the time to go and complain - that forum has a topic for your infection which is ……………. please post as a reply, you do not need to register to do so (but you can if you wish). It will also have a list of other places you can go to to register your complaint, depending on the country you are resident in. Please read the topics and complain, it is only with such complaints to goverment or government agances that something will get done.

Regards dan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI