This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Ridiculous Popups

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi LISH,

Thanks for posting logs. Your doing a fine job. This is next.

To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Click Start, then select My Computer)
  • Select the Tools (at top of opened screen in menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.
—————————————————-

Run HijackThis, select Do a system scan only and place checks against the following entries (if they are still present):
O2 - BHO: (no name) - {092428B9-FC13-48FA-895C-E183BFE53CFC} - C:\WINDOWS\system32\mljji.dll (file missing)
O2 - BHO: (no name) - {0D655062-1646-432E-BA69-73E1296BE4B0} - (no file)
O2 - BHO: (no name) - {6F2BDD91-5B5C-439A-BC19-A4E2F1301249} - C:\WINDOWS\system32\awvtt.dll (file missing)
O2 - BHO: msdn_lib.msdn_hlp - {7C2F2C76-1489-450D-B8FB-0B9692D788F9} - C:\WINDOWS\system32\msdn_lib.dll
O2 - BHO: (no name) - {93BC1AA7-8169-4029-8D1B-313203816343} - C:\Program Files\Common Files\hoket.dll (file missing)
O2 - BHO: (no name) - {AF3A3664-20CD-4D82-BB17-CC12BF6E19D0} - C:\WINDOWS\system32\sstqr.dll (file missing)
O2 - BHO: (no name) - {F8949656-53DB-48F3-AA61-3C3DD3177334} - C:\WINDOWS\system32\jkkjh.dll (file missing)
O20 - Winlogon Notify: gebcy - C:\WINDOWS\system32\gebcy.dll (file missing)


WITH ALL OTHER WINDOWS CLOSED Click on Fix Checked and exit HijackThis.

——————————————————–

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
———————————————————–

Need to check to make sure this process is not running in safemode.

End malicious processes: (if they are present)
  • Press the CTRL+ALT+DEL keys simultaneously to open Task Manager
  • Click on the Processes tab to show running processes
  • Find tmrsrv32.exe and click on it. (if present)
  • Click End Process
  • Close Task Manager
———————————————————-

Use Explorer to navigate to and delete the following file (if it is present) just what is in red:

Files:
  • C:\WINDOWS\system32\tmrsrv32.exe
  • C:\WINDOWS\system32\msdn_lib.dll

Instuction on how to find files listed above:
  • Click Start
  • Click on MyComputer
  • Double-Click C drive
  • Now look for WINDOWS folder when found double click on it to open.
  • Now look for system32 folder when found double click on it to open.
  • Now look for tmrsrv32.exe file when you find this file right-click on it and choose delete.
  • Look for msdn_lib.dll and delete ,too.
  • done close all open windows.
Now Reboot computer

——————————————————-

Now this is next:


Please do the following:
Here we are going to clean out cookies and temp files from your computer.

*NOTE* CCleaner deletes EVERYTHING out of temp/temporary folders. If you have anything in a temp folder, back it up or move it to a permanent folder prior to running CCleaner!

Download CCleaner from here It will start to download automatically. If ask if you want to download let it. Save to your Desktop.
Note: If you get and Error page from this link.
Try again you will see this message Your download of CCleaner will automatically start in 5 seconds. Click here if it does not do not wait go ahead and click on it.
  • Double click on the file to start the installation of the program.
  • Select your language and click OK, then next.
  • Follow prompts to install finish to complete installation.
  • Double click the CCleaner shortcut on the desktop to start the program.
  • On the Windows tab, under Internet Explorer,
  • All Boxes should have a check mark. (You will need to reenter your passwords at all sites where a cookie is used to recognize you when you visit).
  • On the Windows tab, under Windows Explorer,
  • All Boxes should have a check mark.
  • On the Windows tab, under System,
  • All Boxes should have a check mark.
  • On the Windows tab, under Advanced,
  • NO check marks
[*]If you use either the Firefox or Mozilla browsers, the box to put check in for "Cookies" is on the Applications tab, under Firefox/Mozilla. If already checked move to next step.

[*]Click on the "Options" icon at the left side of the window, then click on "Advanced."

deselect "Only delete files in Windows Temp folders older than 48 hours."
[*]Click on the "Cleaner" icon on the left side of the window, then click Run Cleaner to run the program.

[*]Caution: It is not recommended that you use the "Issues" feature unless you are very familiar with the registry as it has been known to find legitimate items.

[*]After CCleaner has completed its process, click Exit.

[*]You will need to reboot here if not ask to do so.

_______________________________

Please print out or copy these instructions/tutorial to Notepad as the internet will not be (while in Safe Mode) available to you at certain points of the removal process. Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.

Here we are going to just make sure this tool is setup correctly Do not run scan yet.
Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to the words Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
    • Click on Scanner on the toolbar at top of this screen.
    • Click on the Settings tab.
      • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Close AVG Anti-Spyware without running yet.
Now disable (turn off AVG Anti-Spyware)
  • Right-click the AVG Anti-Spyware Tray Icon (Bottom right corner of computer screen near clock) and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update AVG Anti-Spyware.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.
______________________________

Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________

Double-click on SmitfraudFix.exe
Select option #2 - Clean by typing 2 and press Enter.
Wait for the tool to complete and disk cleanup to finish.
You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will also check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.
______________________________

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
Note: If AVG Anti-Spyware screen does not fit your monitor screen Hold down the Alt button on keyboard then tap spacebar, menu should pop up then choose maximize. AVG Anti-Spyware screen should fix screen a little better.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
[external image: Posted Image]

IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
  • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
  • At the bottom of the window click on the Apply all Actions button.(3)
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop. I will need you to post this in your next reply.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.
______________________________


Please post:
  • c:\rapport.txt
  • AVG Anti-Spyware log
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.
sorry..i'm completely busy from friday morning until sunday afternoon (dayjob + DJing friday and saturday night) …i'm a few beers deep at the moment but i will follow the last instructions tomorrow morning…sorry for the delayed response..
SmitFraudFix v2.184 Scan done at 12:43:03.64, Mon 06/04/2007 Run from C:\Documents and Settings\LISH.PIMPSHIT\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\susp.exe Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{78335D0F-BEF4-4C1A-B661-91BE08ED513C}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{78335D0F-BEF4-4C1A-B661-91BE08ED513C}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\..\{78335D0F-BEF4-4C1A-B661-91BE08ED513C}: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=192.168.1.1 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 1:55:55 PM 6/4/2007 + Scan result: C:\QooBox\Quarantine\C\WINDOWS\system32\gmkjwucx.dll.vir -> Adware.BHO : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\iaecoeqf.dll.vir -> Adware.BHO : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\sqmpbefk.dll.vir -> Adware.BHO : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\vsiehfaa.dll.vir -> Adware.BHO : Cleaned with backup (quarantined). C:\Program Files\Hijackthis\backups\backup-20070517-210034-427.dll -> Adware.Gdown : Cleaned with backup (quarantined). HKU\S-1-5-21-4096547285-2772875797-96554950-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38} -> Adware.Generic : Cleaned with backup (quarantined). C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined). C:\Documents and Settings\LISH.PIMPSHIT\Desktop\OiUninstaller.exe -> Adware.PurityScan : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free\Data -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free\Data\Abbr -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free\Data\ActivationCode -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free\Data\HOURS -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\Documents and Settings\All Users\Application Data\ErrorProtector Free\Data\ProductCode -> Adware.RogueSuspect : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\VTTC.exe.vir -> Adware.TTC : Cleaned with backup (quarantined). C:\VundoFix Backups\hoket.dll.bad -> Adware.TTC : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lb66.exe.vir/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lb66.exe.vir/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lb66.exe.vir/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\awtstus.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\byxwwxx.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\iifgfed.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\ljjkkig.dll.vir -> Adware.Virtumonde : Cleaned with backup (quarantined). C:\WINDOWS\b129.exe -> Adware.WebHancer : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lib67.exe.vir -> Adware.ZQuest : Cleaned with backup (quarantined). J:\Apps\NERO.7.ULTRA.EDITION.PROPER-ADDICTION\Ahead_Nero_v7.0_KeyGen_Only-PARADOX\pdxnero7.zip/Nero7Keygen.zip/Nero7Keygen.exe -> Backdoor.Hupigon : Cleaned with backup (quarantined). J:\Apps\NERO.7.ULTRA.EDITION.PROPER-ADDICTION\Ahead_Nero_v7.0_KeyGen_Only-PARADOX\pdxnero7\Nero7Keygen.zip/Nero7Keygen.exe -> Backdoor.Hupigon : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lib06.exe.vir -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/retadpu1000106.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined). C:\Program Files\Common Files\wiru\wirud\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined). C:\Program Files\Hijackthis\backups\backup-20070524-214754-962.dll -> Downloader.VB.apq : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP523\A0089182.dll -> Downloader.VB.apq : Cleaned with backup (quarantined). C:\WINDOWS\system32\wmvds32.dll -> Downloader.VB.asx : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/~.exe -> Downloader.VB.att : Cleaned with backup (quarantined). C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP523\A0089620.exe -> Downloader.VB.avl : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/xloadnet.exe -> Downloader.VB.wz : Cleaned with backup (quarantined). C:\QooBox\Quarantine\C\Program Files\Windows Media Player\lavunab.dll.vir -> Hijacker.StartPage : Cleaned with backup (quarantined). C:\WINDOWS\system32\msorcl32.exe -> Not-A-Virus.Hoax.Win32.Renos.fn : Cleaned with backup (quarantined). C:\SDFix\backups\backups.zip/backups/core.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined). :mozilla.83:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.84:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.256:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.257:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.258:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.259:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.260:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.261:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.262:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.263:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.264:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.265:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.506:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.534:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.558:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.59:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.60:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\LISH\Cookies\lish@2o7[2].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.367:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.688:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.72:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.73:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.74:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.75:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.457:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.458:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.459:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.460:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.461:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.462:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.463:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.145:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.148:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.149:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.150:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.153:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.30:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.9:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\LISH.PIMPSHIT\Cookies\lish@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.412:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned. :mozilla.478:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.479:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.480:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.61:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.66:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.63:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.64:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.65:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.70:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.71:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.120:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.121:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.122:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.123:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.124:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.125:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.126:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.127:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.128:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.511:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.167:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.543:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.602:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.603:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.604:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.605:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.48:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.62:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.64:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.65:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\LISH\Cookies\lish@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.302:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.303:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.304:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.305:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.306:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.307:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.212:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.213:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.214:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.215:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.216:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.217:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.220:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.221:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.434:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.518:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.535:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.536:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.537:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.563:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.564:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.565:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.566:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.567:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.568:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.569:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.570:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.571:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.572:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.573:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.654:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.391:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned. :mozilla.455:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.456:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.132:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.241:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.242:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.243:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.413:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.254:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.57:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. :mozilla.297:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.298:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.299:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.300:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.301:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.349:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.350:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.351:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.352:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.77:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned. :mozilla.78:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Realcastmedia : Cleaned. :mozilla.81:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.95:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.96:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.97:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.98:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.176:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.178:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.179:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.180:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.181:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.182:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.183:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.308:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.246:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.249:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.155:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.156:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.157:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.158:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.159:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.160:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.18:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.19:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.20:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.21:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.22:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.273:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.274:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.275:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.276:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.426:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.427:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.477:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.66:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.67:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.68:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.68:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.69:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.69:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.70:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.71:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.110:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.111:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.112:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.113:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.114:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.116:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.117:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.118:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.119:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.47:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.49:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.50:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.51:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.52:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.53:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.54:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.223:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.185:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned. :mozilla.39:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned. :mozilla.392:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.395:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yadro : Cleaned. :mozilla.129:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.130:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.131:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.133:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.134:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.135:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.33:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.34:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.43:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.44:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.45:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.46:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.161:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.162:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.163:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.164:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.165:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.166:C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.17:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.23:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.24:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.25:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.26:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.27:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.28:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.29:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.30:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.31:C:\Documents and Settings\LISH\Application Data\Mozilla\Firefox\Profiles\obd663o4.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. C:\Documents and Settings\LISH\Cookies\lish@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. C:\QooBox\Quarantine\C\WINDOWS\system32\smpi1\lb5.exe.vir -> Trojan.Agent : Cleaned with backup (quarantined). ::Report end
Logfile of HijackThis v1.99.1
Scan saved at 2:08:07 PM, on 6/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\AOL\1135820447\ee\AOLSoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O6 "USB003" /M "PictureMate"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135820447\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [wiru] C:\PROGRA~1\COMMON~1\wiru\wirum.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Epson printer Registration.lnk = D:\E_reg\EPSONREG.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {804F9BC5-0EAB-4150-8065-0DF485420670} (InstallShield Setup Player V11.5) - http://www.nextelnoob.com/G2/setup.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" –ntservice (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - - c:\program files\transcode360\transcode360.exe
Hi LISH,

Thanks for posting logs.

These tools I had you download are of no longer any use as they update so frequently that fresh copies have to be downloaded when needed.

Delete tools:
SmitFraudFix and SmitFraudFix's Folder
SDFix.exe and C:\SDFix
VundoFix.exe
combofix.exe and C:\QooBox


——————————————————-

Your version of Java is now outdated. Java vulnerabilites are commonly exploited by viruses. You need to update.

Download the latest version of Java Runtime Environment (JRE) 6u1
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u 1".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Click Start then Control Panel > then Add/Remove Programs and remove all older versions of Java.
  • Remove any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed to complete uninstall.
  • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.
————————————————————–

This is next:

Run Panda's ActiveScan from here and perform a full system scan.
NOTE* You must use Internet Explorer for this scan to work.

1. Once you are on the Panda site scroll to the bottom of page and click the "Scan your PC" button NOTE: If you have a popblocker enable you will have to allow popup here.
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes. You may have to reboot here and start back with step 1. I did.)
10. Click on "Local Disks" to start the scan
11. Post Panda scan results in your next reply with others requested.

————————————————————–

Please post in next reply:
Panda's scan report
New HJT log
Incident Status Location Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\LISH\Cookies\lish@atwola[1].txt Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.2o7.net/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.atdmt.com/] Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.overture.com/] Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.hitbox.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.advertising.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.mediaplex.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.casalemedia.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.burstnet.com/] Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[www.burstbeacon.com/] Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.trafficmp.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.realmedia.com/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.apmebf.com/] Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.qksrv.net/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.statcounter.com/] Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.ads.pointroll.com/] Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[citi.bridgetrack.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.bs.serving-sys.com/] Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.serving-sys.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.com.com/] Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.zedo.com/] Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.questionmarket.com/] Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.247realmedia.com/] Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.bluestreak.com/] Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.cdfreaks.com/] Spyware:Cookie/Cd Freaks Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.club.cdfreaks.com/] Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.bravenet.com/] Spyware:Cookie/Target Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.target.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Application Data\Mozilla\Firefox\Profiles\x552je17.default\cookies.txt[.go.com/] Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\LISH.PIMPSHIT\Cookies\lish@2o7[2].txt Potentially unwanted tool:Application/PRScheduler Not disinfected C:\Program Files\Hijackthis\backups\backup-20070517-210550-606-PowerReg Scheduler V3.exe Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\ehtwxmqm.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\ndbcddds.dll.vir Spyware:Spyware/Virtumonde Not disinfected C:\QooBox\Quarantine\C\WINDOWS\system32\uydrwgxm.dll.vir Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-4096547285-2772875797-96554950-1005\Dc11.exe[SDFix\apps\Process.exe] Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-4096547285-2772875797-96554950-1005\Dc12.exe[SDFix\apps\Process.exe] Virus:Malware Generic Disinfected C:\RECYCLER\S-1-5-21-4096547285-2772875797-96554950-1005\Dc15.exe Potentially unwanted tool:Application/Processor Not disinfected C:\RECYCLER\S-1-5-21-4096547285-2772875797-96554950-1005\Dc17\Process.exe Virus:Trj/Shutdown.Z Disinfected C:\RECYCLER\S-1-5-21-4096547285-2772875797-96554950-1005\Dc17\restart.exe Potentially unwanted tool:Application/Processor Not disinfected C:\SDFix\apps\Process.exe Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\sxsmvhpb.dll.bad Spyware:Spyware/Virtumonde Not disinfected C:\VundoFix Backups\xyyjvfhv.dll.bad Adware:adware/ncase Not disinfected C:\WINDOWS\180ax.exe Spyware:spyware/betterinet Not disinfected C:\WINDOWS\bi.dll Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\WINDOWS\nircmd.exe Adware:adware/twain-tech Not disinfected C:\WINDOWS\satmat.exe Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe Virus:Trj/Downloader.OJW Disinfected C:\WINDOWS\system32\SBO\SB1065.exe Adware:adware/topconvert Not disinfected C:\WINDOWS\updatetc.exe
Logfile of HijackThis v1.99.1
Scan saved at 8:54:59 AM, on 6/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE
C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe
C:\Program Files\Common Files\AOL\1135820447\ee\AOLSoftware.exe
C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\VIA\RAID\raid_tool.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\EPSON Print CD\EPSONCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\vso\ConvertXtoDVD\ConvertXtoDvd.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Windows NT\Accessories\wordpad.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300"
O4 - HKLM\..\Run: [EPSON PictureMate] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2P1.EXE /P17 "EPSON PictureMate" /O6 "USB003" /M "PictureMate"
O4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1135820447\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [H2O] C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [wiru] C:\PROGRA~1\COMMON~1\wiru\wirum.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: Epson printer Registration.lnk = D:\E_reg\EPSONREG.EXE
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {804F9BC5-0EAB-4150-8065-0DF485420670} (InstallShield Setup Player V11.5) - http://www.nextelnoob.com/G2/setup.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe" –ntservice (file missing)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Transcoding and Broadcast Service (Transcode360) - - c:\program files\transcode360\transcode360.exe
Hi LISH,

Your panda scan show infected files will need to rerun tool Please do the following:

Open AVG Anti-Spyware:

Please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Close AVG Anti-Spyware without running yet.
Now disable (turn off AVG Anti-Spyware)
  • Right-click the AVG Anti-Spyware Tray Icon again and select Exit. Confirm by clicking Yes.
______________________________


Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
______________________________


Open AVG Anti-Spyware program.
  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button (*** This must done before saving the report ***)
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Tray Icon and select Exit.
Restart computer back into normal mode.

———————————————————–

Post these in next reply:
AVG Anti-Spyware report
New HJT log

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI