This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Hijackthis Log

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

my desktop keeps filling up with ie icons. I am a computer noob so forgive any unintentional breaches of protocol.

below is the hijackthis log

Logfile of HijackThis v1.99.1
Scan saved at 21:11:05, on 10/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\notepad.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\USER\Desktop\HijackThis.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://uk.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Protection Bar - {5d4831e0-5a7c-4a46-afd5-a79ab8ce36c2} - C:\Program Files\Video ActiveX Object\iesplugin.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [seekmo] "c:\program files\seekmo\seekmo.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?89510723a45b481a88c7c96885f1b836
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?89510723a45b481a88c7c96885f1b836
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://www.uclan.ac.uk/other/iss/remote/wficat.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\Windowblinds\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe


here is a screenshot of my desktop, don't know if this helps

[external image: Posted Image]
Hi,mrniceand welcome to Tom Coyote forums

I am currently looking over your log. As I am an Undergraduate, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Thanks for your patience!
dan
Hi mrnice

Please download SmitfraudFix (by S!Ri)

Double-click SmitfraudFix.exe.
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

**If the tool fails to launch from the Desktop, please move SmitfraudFix.exe directly to the root of the system drive (usually C:), and launch from there.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm

post the report
Thanks dan
thanks Dan, here the log thing SmitFraudFix v2.166 Scan done at 11:01:24.60, 11/04/2007 Run from C:\Program Files\Mozilla Firefox\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe C:\Program Files\MSN Messenger\usnsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\USER »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\USER\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\USER\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="wbsys.dll" "LoadAppInit_DLLs"=dword:00000001 »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: VIA Rhine II Fast Ethernet Adapter - Packet Scheduler Miniport DNS Server Search Order: 62.31.64.39 DNS Server Search Order: 62.31.112.39 DNS Server Search Order: 62.31.144.39 HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Hi mrnice

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Download ATF Cleaner by Atribune and save it to your Desktop.
Do not use yet!

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Reminder!
You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, please reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.
Once in Safe Mode, double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.
______________________________

Run ATF cleaner
  • Double click ATF-Cleaner.exe to run the program.
  • Check the following boxes:
    • Windows Temp
    • Current User Temp
    • All Users Temp
    • Temporary Internet Files
    • Prefetch
    • Recycle Bin
    • Java Cache
  • The rest are optional - if you want to remove the lot, check Select All.
  • Now click Empty Selected.
  • When you get the Done Cleaning message, click OK.
  • If you use Firefox browser.
    • Click Firefox at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
  • If you use Opera browser.
    • Click Opera at the top and choose: Select All
    • If you would like to keep your saved passwords, please click No at the prompt.
    • Click the Empty Selected button.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________

Please post:
  • c:\rapport.txt
  • AVG Anti-Spyware report
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
Thanks dan
SmitFraudFix v2.166 Scan done at 2:37:35.04, 12/04/2007 Run from C:\Documents and Settings\USER\My Documents\ICQ Lite\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url Deleted C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
SmitFraudFix v2.166 Scan done at 2:37:35.04, 12/04/2007 Run from C:\Documents and Settings\USER\My Documents\ICQ Lite\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Online Security Guide.url Deleted C:\DOCUME~1\ALLUSE~1.WIN\STARTM~1\Security Troubleshooting.url Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{6C0C0140-6195-4D4D-A6F0-0779661B29F6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 03:22:07 12/04/2007 + Scan result: HKU\S-1-5-21-839522115-583907252-725345543-1003\Software\Microsoft\Internet Explorer\Explorer Bars\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Cleaned with backup (quarantined). HKU\S-1-5-21-839522115-583907252-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5D4831E0-5A7C-4A46-AFD5-A79AB8CE36C2} -> Adware.Generic : Cleaned with backup (quarantined). C:\Program Files\Emblaze\SyncTool\program\RD1_SyncTool.exe -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined). :mozilla.522:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.101:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.102:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.103:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.104:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.105:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.107:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.108:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.110:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.111:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.112:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.119:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.120:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.122:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.123:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.125:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.126:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.127:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.128:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.129:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.137:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.156:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.179:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.183:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.276:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.303:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.337:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.348:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.383:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.42:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.43:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.44:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.45:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.47:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.48:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.49:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.50:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.50:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.51:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.52:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.52:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.53:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.53:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.54:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.54:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.55:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.55:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.56:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.57:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.58:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.59:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.60:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.61:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.62:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.230:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.7search : Cleaned. :mozilla.231:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.7search : Cleaned. :mozilla.214:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.215:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.216:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.217:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.218:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.219:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.220:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.221:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.409:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.411:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.421:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.119:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.120:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.357:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.358:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.359:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.384:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.385:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.474:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.475:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.476:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.477:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.478:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.130:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.21:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.41:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.454:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.108:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.197:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.248:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.338:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned. :mozilla.272:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.332:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.333:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.334:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.335:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.347:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.133:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.59:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned. :mozilla.60:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned. :mozilla.155:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.194:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.79:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.198:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.319:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.41:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.49:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.51:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.83:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.84:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.109:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.198:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.199:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.388:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.389:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.390:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.162:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.163:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Gemius : Cleaned. :mozilla.14:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.78:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.10:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.11:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.12:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.13:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.14:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.15:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.16:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.17:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.18:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.19:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.20:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.226:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.227:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.228:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.229:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.230:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.231:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.232:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.233:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.234:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.235:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.236:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.237:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.238:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.239:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.243:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.244:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.245:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.275:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.295:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.296:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.307:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.308:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.378:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.379:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.66:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.74:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.75:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.76:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.77:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.78:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned. :mozilla.118:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.121:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.287:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.288:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.87:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.88:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.177:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned. :mozilla.389:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned. :mozilla.205:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.206:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.405:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.453:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.454:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.455:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.465:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.466:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.467:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.492:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.493:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.70:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.71:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.72:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.107:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.339:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.485:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.540:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.541:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.542:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.122:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Netflame : Cleaned. :mozilla.174:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.175:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.132:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.187:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.188:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.189:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.192:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.367:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.368:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.369:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.178:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.491:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.52:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.353:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.354:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.355:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.356:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.260:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.261:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.403:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.404:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned. :mozilla.184:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.185:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.483:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.484:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.405:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.480:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.343:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.316:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.317:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.154:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.371:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.89:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.90:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.91:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.92:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.93:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.222:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.223:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.224:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.225:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.200:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned. :mozilla.140:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.158:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.275:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.471:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.501:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned. :mozilla.502:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned. :mozilla.504:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned. :mozilla.285:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.287:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.288:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.289:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.290:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.291:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.292:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.293:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.306:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.310:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.82:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.83:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.84:C:\Documents and Settings\Guest\Application Data\Mozilla\Firefox\Profiles\6m4l89j9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.152:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.153:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.536:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.537:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.228:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Toplist : Cleaned. :mozilla.130:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.131:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.132:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.213:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.214:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.215:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned. :mozilla.429:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.445:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.460:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.11:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.55:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.184:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.185:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.449:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.450:C:\Documents and Settings\sean\Application Data\Mozilla\Firefox\Profiles\msph7udz.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.479:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.481:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.482:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.221:C:\Documents and Settings\lauren\Application Data\Mozilla\Firefox\Profiles5qnorlr.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Program Files\LimeWire Download Client\Downloads\Adobe Photoshop CS2 9 0 Final + keygen zip.zip/Setup.exe -> Worm.VB.dw : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 03:42:01, on 12/04/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\USER\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [seekmo] "c:\program files\seekmo\seekmo.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Download with GetRight Pro - C:\Program Files\GetRight\GRdownload.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/229?89510723a45b481a88c7c96885f1b836
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-gb\msntabres.dll.mui/230?89510723a45b481a88c7c96885f1b836
O8 - Extra context menu item: Open with GetRight Pro Browser - C:\Program Files\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineS…er.cab31267.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WBSrv - C:\Program Files\Stardock\Object Desktop\Windowblinds\wbsrv.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
i think its still not right Dan

[external image: Posted Image]

i lost my desktop background but not the rogue icons
Thanks Dan, the dodgy icons have gone now. How do I get my desktop to have a picture on it again?

[external image: Posted Image]

I dumped all the rogue icons in my recycle bin, is there anything else that I need to do?
We still have some work to do yet, did you just dump them into th recycle bin? were they shortcuts or copies of files. only don't empty the recycle bin just yet till we know for sure. catch you soon. dan
Hi mrnice

Not sure why you lost your wallpaper… thats easy enough to remedy though. You just need to choose a new picture you want and apply it as the background.

How long have these icons been on your desktop, can you remember what programs you were running when they first appeared?
___________

Can you create a foder on your desktop, if you have room! and name it "HJT" locate "HijackThis.exe" copy and paste it into the new folder you just created.
we do this because it needs it's own permanant folder to create backups should we need them.
Please do this before we continue.
___________

You are running "BitTorrent" a P2P filesharing programme.
  • Many of these programmes come with unwanted components bundled with them.
  • If you wish to find out whether the one you're using does click here.

Please note: Even if you are using a "safe" P2P programme, it is only the programme that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.


My recommendation is you uninstall it.
___________________

Make a uninstall list using HijackThis
To access the Uninstall Manager you would do the following:

1. Start HijackThis
2. Click on the Config button
3. Click on the Misc Tools button
4. Click on the Open Uninstall Manager button.

You will now be presented with a screen similar to the one below:

[external image: Posted Image]

5. Click on the Save list… button and specify where you would like to save this file. When you press Save button a notepad will open with the contents of that file. Simply copy and paste the contents of that notepad here on your next reply.

Delete program
  • Click Start
  • Go to Control Panel
  • Go to Add/Remove Programs
  • Find and click Remove for the following (if present). It could be that they have a space or something between it , but it has to look like it:
  • seekmo
**Take care when answering any questions posed by an uninstaller. Some questions may be worded to deceive you into keeping the program.

___________

You need to disable a few realtime protections. These may interfere with our cleaning process.
We'll enable these when you're clean…

Disable AVG Anti-Spyware guard.
  • Open AVG Anti-Spyware
  • Click Shield
  • Click under "resident shield is"
  • Change it to inactive
  • Close the program

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [seekmo] "c:\program files\seekmo\seekmo.exe"


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit

Right click start, In the drop down menu click "Explore" Then navigate to each file\ folder in the left hand pane, which will reveal its content in the right hand pane, highlight file or folder right click and Delete, if present:

c:\program files\seekmo < ====This folder


please do an online scan with Kaspersky Online Scanner

Click on Kaspersky Online Scanner

You will be prompted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
  • Scan using the following Anti-Virus database:
  • Extended (If available otherwise Standard)
  • Scan Options:
  • Scan Archives
  • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Please include new HJT log, kaspersky log
in your next post
Thanks dan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI