This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help With Teenage Son's Computer

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello friends,
Here is my log from another system in my house. Please review. Things have started to move very slow.

Thank you
Mark

Logfile of HijackThis v1.99.1
Scan saved at 11:58:37 PM, on 5/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\System32\hphmon05.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://count.exitexchange.com/exit/1121848
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [strtas] lockx.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunServices: [strtas] lockx.exe
O4 - HKCU\..\Run: [strtas] lockx.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {a80f2db2-80a9-4834-8f5a-4ab70f4ef4c3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {a80f2db2-80a9-4834-8f5a-4ab70f4ef4c3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136135752149
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Hello MEK :)

Copy and Paste this 'Fix' into either Notepad or Wordpad for future reference as you will be required to closed down you browser when following these steps.


Step 1

Please download and run Aimfix by Jay Loden from:
http://www.jayloden.com/AIMFix.exe


Step 2

Download AVG Anti-Spyware 7.5

The program should launch automatically after installation. If not, double-click the desktop icon.

Deactivate the "Resident Shield" as this may prevent changes to the registry.
To do this, click "Change State" to the right of the Resident Shield option in the main window.
You will clearly see the status change to Inactive if you have done this correctly.

Now Update AVG Anti-Spyware 7.5
click the "Update" icon from the main menu.
Then click the "Start Update" button.
When you receive the "Update successful" prompt, close AVG AS.
Note: If you have any problems with the updater, you can Update AVG Anti-Spyware 7.5 Manually.
Do not Scan with this yet!

Please Reboot your System into Safe Mode Shut down your system, then Restart your computer
as soon as it starts booting up again continuously tap F8 from the menu select the option to enter Safe Mode

Reopen AVG Anti-Spyware 7.5 and click the "Scanner" icon from the main menu.
Click "Complete System Scan" to start scanning.
When the scan completes, click "Recommended action" beneath the results window and select "Quarantine".
Then click the "Apply all actions" button to quarantine everything detected.
Then click Save report > Save report as and save the AVG Report-Scan.txt to your desktop.
Then Reboot back into Normal Mode

In your next reply please post:

A new HijackThis log
The AVG Anti-Spyware 7.5 Report-Scan.txt

Thank you.
Hello ourwilly and thank you ….

Here re the 2 files you asked for. I have also run the Aimfix program.

Logfile of HijackThis v1.99.1
Scan saved at 8:43:55 PM, on 5/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\ehome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\ehome\ehtray.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\System32\hphmon05.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\HP\KBD\KBD.EXE
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe
C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
C:\Program Files\Symantec\LiveUpdate\AUPDATE.EXE
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe
C:\Program Files\Symantec\LiveUpdate\LuCallbackProxy.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://count.exitexchange.com/exit/1121848
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\NppBho.dll
O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\Logitech\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LVCOMSX] "C:\Program Files\Common Files\Logitech\LComMgr\LVComSX.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKCU\..\Run: [strtas] lockx.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {a80f2db2-80a9-4834-8f5a-4ab70f4ef4c3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: IMI - {a80f2db2-80a9-4834-8f5a-4ab70f4ef4c3} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www.snapfish.com/SnapfishActivia.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1136135752149
O16 - DPF: {88D8E8B7-A33B-4417-A385-8373484D43ED} (InstallHelper Class) - file://C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\ThereInstallHelper.dll
O16 - DPF: {8B486EF6-6B2A-4A1E-BB0D-236CB2DBB8D2} (There Voice Trainer) - file://c:\Program Files\There\ThereClient\ThereVoiceTrainer.dll
O16 - DPF: {AAF421E6-7914-430A-9981-72B31AFF3BF4} (There Launcher) - file://c:\Program Files\There\ThereClient\ThereLauncher.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: LiveUpdate Notice Service - Unknown owner - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PifEng.dll (file missing)
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 8:35:14 PM 5/28/2007

+ Scan result:



:mozilla.50:C:\Documents and Settings\Nikki\Application Data\Mozilla\Firefox\Profiles\kfap7fho.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.51:C:\Documents and Settings\Nikki\Application Data\Mozilla\Firefox\Profiles\kfap7fho.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.234:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.235:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.405:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adengage : Cleaned.
:mozilla.302:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.303:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.304:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.325:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.326:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.327:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.328:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Nikki\Cookies\nikki@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.42:C:\Documents and Settings\Nikki\Application Data\Mozilla\Firefox\Profiles\kfap7fho.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Nikki\Cookies\nikki@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.159:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.162:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.163:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.164:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.39:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.40:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.43:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.44:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.45:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.46:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.47:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.318:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Daniel Kanefsky.MEDIA\Cookies\daniel_kanefsky@com[1].txt -> TrackingCookie.Com : Cleaned.
:mozilla.352:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.353:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.354:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.355:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.356:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.357:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned.
:mozilla.19:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Nikki\Cookies\nikki@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.286:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.287:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.288:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.289:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.290:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.202:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.351:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.369:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.379:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.380:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.118:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.121:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.310:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.311:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.312:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.313:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.314:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.315:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.316:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.119:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.120:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.111:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Nikki\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.10:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.11:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.6:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.7:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.8:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.9:C:\Documents and Settings\Mark.MEDIA\Application Data\Mozilla\Firefox\Profiles\wsxz63h4.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.263:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.264:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.29:C:\Documents and Settings\Nikki\Application Data\Mozilla\Firefox\Profiles\kfap7fho.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.43:C:\Documents and Settings\Nikki\Application Data\Mozilla\Firefox\Profiles\kfap7fho.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.56:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.57:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.58:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.59:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.60:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.61:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Daniel Kanefsky.MEDIA\Cookies\daniel_kanefsky@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Nikki\Cookies\nikki@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.329:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.330:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.331:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.332:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.333:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.334:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.175:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.176:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.179:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.180:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.181:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.182:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Daniel Kanefsky.MEDIA\Cookies\daniel_kanefsky@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.165:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.167:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.168:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.169:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.170:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.171:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.307:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.14:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.15:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.16:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.17:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.18:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.19:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.20:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.6:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.7:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Daniel Kanefsky.MEDIA\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.127:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.128:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.129:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.130:C:\Documents and Settings\Daniel Kanefsky.MEDIA\Application Data\Mozilla\Firefox\Profiles\kgs3z5el.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end
Hello MEK

Copy and Paste this 'Fix' into either Notepad or Wordpad for future reference as you will be required to closed down you browser when following these steps.

Step 1

Go to Start > Control Panel > Add/Remove Programs and Uninstall the following:

Freeprod Toolbar <– If listed

Please Re-open HijackThis and select "Do a System Scan only" and place a checkmark in the boxes before the following entries:

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKCU\..\Run: [strtas] lockx.exe
O9 - Extra button: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)
O9 - Extra 'Tools' menuitem: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - (no file)

Close any Explorer windows which may be open and click the "Fix Checked" button.


Step 2

Download the OTMoveIt from here:
http://download.bleepingcomputer.com/oldtimer/OTMoveIt.exe
Save it to your desktop.

Please double-click OTMoveIt.exe to run it.
Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\Windows\System32\lockx.exe

Return to OTMoveIt, right click on the "Paste List of Files/Folders to be moved" window and choose Paste.
Click the red Moveit! button.
Close OTMoveIt

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.


Step 3

Download and Install CCleaner
Now Open CCleaner and select: Cleaner | Analyze | Run Cleaner
Then close

Then please use Internet Explorer and Run the Kaspersky On-line Scanner
http://www.kaspersky.com/service?chapter=161739400

Accept the Active X object and download the latest definitions.
When the scanner is ready, click Scan Settings.
Select the Extended anti-virus database.
Select Scan Archives & Scan Mail Bases and then ok.
Click My Computer to run a full system scan.
When complete, save the log to your desktop.

Please now Re-scan with HijackThis and post:

A new HJT Log
The kaspersky scan log result's

Thank You.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI