Gary -
Attached is the AVG log, HJT logs (prior to AVG and after AVG), and the SD Fix log.
Thanks for your quick reply.
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:51:43 PM 5/28/2007
+ Scan result:
C:\WINDOWS\Downloaded Program Files\turbo.inf -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\WINDOWS\system32\aesss2.dll/bi.dll -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\WINDOWS\system32\aesss2.dll/biprep.exe -> Adware.BiSpy : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/cfg32o.dll.dat/WINDOWS/cfg32o.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/cfg32r.dll.dat/WINDOWS/cfg32r.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/cfg32s.dll.dat/WINDOWS/cfg32s.dll -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/stub_mma1.exe.dat/WINDOWS/stub_mma1.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/cmdinst.exe.dat/Documents and Settings/Dad/Local Settings/Temp/cmdinst.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/installer[1].exe.dat/Documents and Settings/Dad/Local Settings/Temporary Internet Files/Content.IE5/4XYV8P6N/installer[1].exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ezSt3.exe -> Adware.EZula : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ezStub3.exe -> Adware.EZula : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/b122.exe.dat/WINDOWS/b122.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/zwwuc.dll.dat/Program Files/Common Files/zwwu/zwwud/zwwuc.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/b129.exe.dat/WINDOWS/b129.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/webhdll.dll.dat/Documents and Settings/Mom/Local Settings/Temp/temp.fr9EAC/Programs/webhdll.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Management\ARPCache\xupiter -> Adware.Xupiter : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-248915221-793999233-381150471-500\Dc2.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\SDFix\SDFix\backups\backups.zip/backups/dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nkdsregj.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
[2476] C:\WINDOWS\system32\nkdsregj.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/b104.exe.dat/WINDOWS/b104.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/zwwup.exe.dat/Program Files/Common Files/zwwu/zwwup.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zwwu\zwwud\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/zwwua.exe.dat/Program Files/Common Files/zwwu/zwwua.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/zwwum.exe.dat/Program Files/Common Files/zwwu/zwwum.exe -> Downloader.TSUpdate.n : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/b103.exe.dat/WINDOWS/b103.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/zwwul.exe.dat/Program Files/Common Files/zwwu/zwwul.exe -> Downloader.TSUpdate.r : Cleaned with backup (quarantined).
C:\WINDOWS\system32\bi1.exe -> Dropper.Agent.og : Cleaned with backup (quarantined).
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/netmon.exe.dat/Program Files/Network Monitor/netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup (quarantined).
:mozilla.102:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.20:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.21:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.23:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.24:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.25:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.26:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.27:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.28:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.29:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.310:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.32:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.332:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.33:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.342:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.34:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.35:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.38:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@2o7[1].txt.dat/Documents and Settings/Mom/Cookies/mom@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@2o7[2].txt.dat/Documents and Settings/Mom/Cookies/mom@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@buycom.122.2o7[1].txt.dat/Documents and Settings/Mom/Cookies/mom@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@gmgmacfs.112.2o7[1].txt.dat/Documents and Settings/Mom/Cookies/mom@gmgmacfs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@heavycom.122.2o7[1].txt.dat/Documents and Settings/Mom/Cookies/mom@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@arn.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@getmusicfree.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@getmusicfree.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@gatorarcade.aavalue[1].txt.dat/Documents and Settings/Mom/Cookies/mom@gatorarcade.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@gatorarcade.aavalue[2].txt.dat/Documents and Settings/Mom/Cookies/mom@gatorarcade.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
:mozilla.57:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.58:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.59:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@adrevolver[1].txt.dat/Documents and Settings/Mom/Cookies/mom@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.76:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.77:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@advertising[1].txt.dat/Documents and Settings/Dad/Cookies/dad@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@advertising[2].txt.dat/Documents and Settings/Mom/Cookies/mom@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@atdmt[2].txt.dat/Documents and Settings/Dad/Cookies/dad@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@atdmt[1].txt.dat/Documents and Settings/Mom/Cookies/mom@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@atdmt[2].txt.dat/Documents and Settings/Mom/Cookies/mom@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@casalemedia[2].txt.dat/Documents and Settings/Dad/Cookies/dad@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@casalemedia[1].txt.dat/Documents and Settings/Mom/Cookies/mom@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@casalemedia[2].txt.dat/Documents and Settings/Mom/Cookies/mom@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.529:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.130:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@doubleclick[1].txt.dat/Documents and Settings/Dad/Cookies/dad@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@doubleclick[1].txt.dat/Documents and Settings/Mom/Cookies/mom@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@doubleclick[2].txt.dat/Documents and Settings/Mom/Cookies/mom@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.159:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.160:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.161:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.162:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.163:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.164:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.165:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.166:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.167:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.168:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.169:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.170:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.171:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.85:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@fastclick[2].txt.dat/Documents and Settings/Dad/Cookies/dad@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@fastclick[1].txt.dat/Documents and Settings/Mom/Cookies/mom@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@fastclick[2].txt.dat/Documents and Settings/Mom/Cookies/mom@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@media.fastclick[2].txt.dat/Documents and Settings/Mom/Cookies/mom@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@findwhat[1].txt.dat/Documents and Settings/Mom/Cookies/mom@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@fortunecity[1].txt -> TrackingCookie.Fortunecity : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@ehg-maniatv.hitbox[1].txt.dat/Documents and Settings/Mom/Cookies/mom@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@counter2.hitslink[1].txt.dat/Documents and Settings/Mom/Cookies/mom@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.233:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.234:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.566:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.266:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@linksynergy[2].txt.dat/Documents and Settings/Mom/Cookies/mom@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned.
:mozilla.560:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.561:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.562:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.568:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.569:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.570:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.571:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@mediaplex[2].txt.dat/Documents and Settings/Dad/Cookies/dad@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@mediaplex[1].txt.dat/Documents and Settings/Mom/Cookies/mom@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@mediaplex[2].txt.dat/Documents and Settings/Mom/Cookies/mom@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.426:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.323:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.337:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.12:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.70:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.71:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.72:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.73:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@ads.pointroll[2].txt.dat/Documents and Settings/Dad/Cookies/dad@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@ads.pointroll[2].txt.dat/Documents and Settings/Mom/Cookies/mom@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@pro-market[2].txt.dat/Documents and Settings/Mom/Cookies/mom@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.343:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.344:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@qksrv[2].txt.dat/Documents and Settings/Mom/Cookies/mom@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.347:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.348:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@questionmarket[1].txt.dat/Documents and Settings/Mom/Cookies/mom@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.369:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@realmedia[2].txt.dat/Documents and Settings/Dad/Cookies/dad@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@realmedia[1].txt.dat/Documents and Settings/Mom/Cookies/mom@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@realmedia[2].txt.dat/Documents and Settings/Mom/Cookies/mom@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.382:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.383:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.384:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.385:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.386:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.387:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.388:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.389:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.390:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.391:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.392:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.393:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.394:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.531:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.184:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.185:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.186:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.105:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.406:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.407:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.408:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.409:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.410:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.423:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.66:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.67:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.68:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.69:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@try.starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@h.starware[1].txt.dat/Documents and Settings/Mom/Cookies/mom@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@h.starware[2].txt.dat/Documents and Settings/Mom/Cookies/mom@h.starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@try.starware[2].txt.dat/Documents and Settings/Mom/Cookies/mom@try.starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@statcounter[1].txt.dat/Documents and Settings/Mom/Cookies/mom@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.438:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.439:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.440:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.441:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.534:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.536:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@targetnet[1].txt.dat/Documents and Settings/Mom/Cookies/mom@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Dad\Cookies\dad@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.461:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.462:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@trafficmp[1].txt.dat/Documents and Settings/Mom/Cookies/mom@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@trafficmp[2].txt.dat/Documents and Settings/Mom/Cookies/mom@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.463:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.467:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@tribalfusion[2].txt.dat/Documents and Settings/Dad/Cookies/dad@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@tribalfusion[1].txt.dat/Documents and Settings/Mom/Cookies/mom@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@tribalfusion[2].txt.dat/Documents and Settings/Mom/Cookies/mom@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.370:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.371:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.372:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.373:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.374:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.473:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.556:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.526:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.527:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.528:C:\Documents and Settings\Dad\Application Data\Mozilla\Firefox\Profiles\p7bhgrwh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@ad.yieldmanager[1].txt.dat/Documents and Settings/Dad/Cookies/dad@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@ad.yieldmanager[1].txt.dat/Documents and Settings/Mom/Cookies/mom@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@ad.yieldmanager[2].txt.dat/Documents and Settings/Mom/Cookies/mom@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mom\Cookies\mom@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/dad@zedo[1].txt.dat/Documents and Settings/Dad/Cookies/dad@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@c5.zedo[2].txt.dat/Documents and Settings/Mom/Cookies/mom@c5.zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@zedo[1].txt.dat/Documents and Settings/Mom/Cookies/mom@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/mom@zedo[2].txt.dat/Documents and Settings/Mom/Cookies/mom@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SpyH5169.BUD/Program Files/Enigma Software Group/SpyHunter/Backup/uninstall_nmon.vbs.dat/WINDOWS/uninstall_nmon.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\TW9t\nq6Q.vbs -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ovbolao\sold.exe -> Worm.Pytica : Cleaned with backup (quarantined).
::Report end
HJT Before
Logfile of HijackThis v1.99.1
Scan saved at 10:57:44 PM, on 5/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\CRW\shwicon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ShowIcon_The Company_CRW Series Driver v1.16e058] "C:\Program Files\CRW\shwicon.exe" -t"The Company\CRW Series Driver v1.16e058"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinlodu.exe CHD001
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\nkdsregj.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinlodu.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exe
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius....tiveXPlugin.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
HJT After AVG
Logfile of HijackThis v1.99.1
Scan saved at 10:57:44 PM, on 5/28/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16441)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\CRW\shwicon.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [CTStartup] C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE /run
O4 - HKLM\..\Run: [ShowIcon_The Company_CRW Series Driver v1.16e058] "C:\Program Files\CRW\shwicon.exe" -t"The Company\CRW Series Driver v1.16e058"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\qwinlodu.exe CHD001
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - Startup: TA_Start.lnk = C:\WINDOWS\system32\nkdsregj.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\qwinlodu.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akama...meInstaller.exe
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} (ScorchPlugin Class) -
http://www.sibelius....tiveXPlugin.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
And - SDFix log
SDFix: Version 1.85
Run by Mom - Mon 05/28/2007 - 21:29:57.29
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix\SDFix
Safe Mode:
Checking Services:
Name:
Client IP-IPX
core
ImagePath:
"" -e te-110-12-0000282
system32\drivers\core.sys
Client IP-IPX - Deleted
core - Deleted
Restoring Windows Registry Values
Restoring Windows Default Hosts File
Rebooting...
Normal Mode:
Checking Files:
Below files will be copied to Backups folder then removed:
C:\WINDOWS\system32\drivers\core.cache.dsk - Deleted
C:\WINDOWS\system32\drivers\core.sys - Deleted
C:\WINDOWS\system32\dwdsregt.exe - Deleted
C:\WINDOWS\system32\msnav32.ax - Deleted
Removing Temp Files...
ADS Check:
Checking if ADS is attached to system32 Folder
C:\WINDOWS\system32
No streams found.
Checking if ADS is attached to svchost.exe
C:\WINDOWS\system32\svchost.exe
No streams found.
Final Check:
Remaining Services:
------------------
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\The All-Seeing Eye\\eye.exe"="C:\\Program Files\\The All-Seeing Eye\\eye.exe:*:Enabled:The All-Seeing Eye"
"C:\\Program Files\\Quake III Arena\\quake3.exe"="C:\\Program Files\\Quake III Arena\\quake3.exe:*:Enabled:quake3"
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe"="C:\\Program Files\\Wolfenstein - Enemy Territory\\ET.exe:*:Disabled:ET"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\backWeb-7288971.exe:*:Enabled:backWeb-7288971"
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"="C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"="C:\\Program Files\\Real\\RealPlayer\\realplay.exe:*:Enabled:RealPlayer"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"C:\\WINDOWS\\system32\\dpvsetup.exe"="C:\\WINDOWS\\system32\\dpvsetup.exe:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\\Program Files\\Messenger\\msmsgs.exe"="C:\\Program Files\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\GameHouse\\Solitaire\\Solitaire.exe"="C:\\Program Files\\GameHouse\\Solitaire\\Solitaire.exe:*:Enabled:Super Solitaire"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:MSN Messenger 7.5"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files:
---------------
Backups Folder: - C:\SDFix\SDFix\backups\backups.zip
Checking For Files with Hidden Attributes:
C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
C:\WINDOWS\system32\ovbolao\csrss.exe
Finished