This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Warez P2P trojan

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having issues with this trojan. I have tried to run spybot after a restart to grab the malware, but it never seems to clean my system completely. I continue to see the two iexplorers running in the background so I know it's still there. Below is my log, and any help would greatly be appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 12:34:48 AM, on 10/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\JR\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_02\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [dupe amok gram atom] C:\Documents and Settings\All Users\Application Data\Once Dog Dupe Amok\Cast Dupe.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176234984750
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE
Hi Runic112 and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
———————————————————

We are going to use HJT to create a list of your currently installed programs.1. Open HijackThis and click on the Config… button in the "Other stuff" section (lower right hand corner).
2. Click on the Misc Tools button.
3. Click on the Open Uninstall Manager… button.
4. Click on the Save list… button.
5. Save the file uninstall_list.txt to a convinient location. This should open Notepad with the list.
6. Please Copy and Paste the list into your next reply.
———————————————————

Please Download NoLop to your desktop from one of the links below…
Link 1
Link 2
Link 3
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it.
  • Now click the button labelled "Search and Destroy"
    <>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should popup from NoLop. If not, double click the program again and it will finish Please Post the contents of C:\NoLop.log along with a fresh HijackThis log
–If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to your system32 folder then rerun the program.–
Thanks in advance for all your help Dave! Here is the NoLop Log NoLop! Log by Skate_Punk_21 Fix running from: C:\Program Files\Mozilla Firefox [10/4/2007] [7:25:57 PM] —Infection Files Found/Removed— C:\WINDOWS\tasks\699A136927158BC1.job Beginning Removal… Rebooting… Removing Lop's Leftover Files/Folders… Editing Registry… **Fix Complete!** —Listing AppData sub directories— C:\Documents and Settings\All Users\Application Data\Adobe C:\Documents and Settings\All Users\Application Data\Aol C:\Documents and Settings\All Users\Application Data\Aol Downloads C:\Documents and Settings\All Users\Application Data\Aol Ocp C:\Documents and Settings\All Users\Application Data\Apple C:\Documents and Settings\All Users\Application Data\Apple Computer C:\Documents and Settings\All Users\Application Data\Corel C:\Documents and Settings\All Users\Application Data\Cyberlink C:\Documents and Settings\All Users\Application Data\Dell C:\Documents and Settings\All Users\Application Data\Google C:\Documents and Settings\All Users\Application Data\Gtek C:\Documents and Settings\All Users\Application Data\Installshield C:\Documents and Settings\All Users\Application Data\Mcafee C:\Documents and Settings\All Users\Application Data\Microsoft C:\Documents and Settings\All Users\Application Data\Once Dog Dupe Amok C:\Documents and Settings\All Users\Application Data\Sbsi C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy C:\Documents and Settings\All Users\Application Data\Viewpoint C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage C:\Documents and Settings\Default User\Application Data\Ati C:\Documents and Settings\Default User\Application Data\Gtek C:\Documents and Settings\Default User\Application Data\Identities C:\Documents and Settings\Default User\Application Data\Microsoft C:\Documents and Settings\Jr\Application Data\Acccore C:\Documents and Settings\Jr\Application Data\Adobe C:\Documents and Settings\Jr\Application Data\Adobeum – EMPTY Directory C:\Documents and Settings\Jr\Application Data\Apple Computer C:\Documents and Settings\Jr\Application Data\Ati C:\Documents and Settings\Jr\Application Data\Bittorrent C:\Documents and Settings\Jr\Application Data\Corel C:\Documents and Settings\Jr\Application Data\Cyberlink C:\Documents and Settings\Jr\Application Data\Divx C:\Documents and Settings\Jr\Application Data\Downloadbinwindow C:\Documents and Settings\Jr\Application Data\Dvdcss C:\Documents and Settings\Jr\Application Data\Google C:\Documents and Settings\Jr\Application Data\Gtek C:\Documents and Settings\Jr\Application Data\Identities C:\Documents and Settings\Jr\Application Data\Macromedia C:\Documents and Settings\Jr\Application Data\Microsoft C:\Documents and Settings\Jr\Application Data\Move Networks C:\Documents and Settings\Jr\Application Data\Mozilla C:\Documents and Settings\Jr\Application Data\Real C:\Documents and Settings\Jr\Application Data\Sun C:\Documents and Settings\Jr\Application Data\Talkback C:\Documents and Settings\Jr\Application Data\Viewpoint C:\Documents and Settings\Jr\Application Data\Vlc C:\Documents and Settings\Jr\Application Data\Winrar – EMPTY Directory C:\Documents and Settings\Localservice\Application Data\Microsoft C:\Documents and Settings\Networkservice\Application Data\Microsoft And here is the HJT list you asked for Adobe Flash Player 9 ActiveX Adobe Reader 7.0.8 AIM 6 Apple Mobile Device Support Apple Software Update ATI Catalyst Control Center ATI Display Driver BitTorrent 5.0.8 Broadcom Management Programs Conexant HDA D110 MDC V.92 Modem Corel Paint Shop Pro Photo XI Corel Snapfire Plus Dell Support 3.2.1 Dell Wireless WLAN Card Digital Content Portal Digital Line Detect DivX Codec DivX Content Uploader DivX Converter DivX Player DivX Web Player Google Earth Google Gmail Notifier Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer High Definition Audio Driver Package - KB835221 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) InterActual Player iTunes J2SE Runtime Environment 5.0 Update 6 Java™ 6 Update 2 Java™ SE Runtime Environment 6 Update 1 McAfee AntiSpyware Enterprise Module McAfee VirusScan Enterprise MCU MediaDirect Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Professional Edition 2003 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft User-Mode Driver Framework Feature Pack 1.0 Modem Helper Mozilla Firefox (2.0.0.7) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) NetWaiting Oblivion OutlookAddinSetup QuickSet QuickTime RealPlayer SearchAssist Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB928090) Security Update for Windows Internet Explorer 7 (KB931768) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB938829) Sonic Audio module Sonic DLA Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Spybot - Search & Destroy Synaptics Pointing Device Driver Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) URL Assistant VideoLAN VLC media player 0.8.6c Viewpoint Media Player WIDCOMM Bluetooth Software Windows Internet Explorer 7 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 WinRAR archiver World of Warcraft
Hi Runic,

P2P PROGRAMS

IMPORTANT I notice there are signs of one or more P2P (Person to Person) File Sharing Programs on your computer.

BitTorrent 5.0.8

I'd like you to read the Guidelines for P2P Programs where we explain why it's not a good idea to have them.

My recommendation is you go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

If you wish to keep them, please do not use them until your computer is cleaned.

———————————————–

Update Java Runtime:

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version. For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system. The most current version of Sun Java is: Java Runtime Environment Version 6 Update 3.
  • Go to http://java.sun.com/javase/downloads/index.jsp
  • Click on the link named Java Runtime Environment (JRE) 6 Update 3
  • Click on the radio button to Accept License Agreement
  • Click on Windows Offline Installation, Multi-language and save the downloaded file to your hard disk
  • Go to Start => Control Panel => Add or Remove Programs
  • Uninstall all old versions of Java (Java 2 Runtime Environment, JRE or JSE)
  • Reboot your computer
  • Delete the folder C:\Program Files\Java if present
  • Install the new version by running the newly-downloaded file, and follow the on-screen instructions.
  • Reboot your computer

———————————————–

I see that Viewpoint is installed. Viewpoint, Viewpoint Manager, Viewpoint Media Player are Viewpoint components which are installed as a side effect of installing other software, most notably AOL and AOL Instant Messenger (AIM). Viewpoint Manager is responsible for managing and updating Viewpoint Media Player’s components. You can disable this using the Viewpoint Manager Control Panel found in the Windows Control Panel menu. By selecting Disable auto‑updating for the Viewpoint Manager ‑‑ the player will no longer attempt to check for updates. Anything that is installed without your consent is suspect. Read what Viewpoint says and make your own decision.

To provide a satisfying consumer experience and to operate effectively, the Viewpoint Media Player periodically sends information to servers at Viewpoint. Each installation of the Viewpoint Media Player is identifiable to Viewpoint via a Customer Unique Identifier (CUID), an alphanumeric identifier embedded in the Viewpoint Media Player. The Viewpoint Media Player randomly generates the CUID during installation and uses it to indicate a unique installation of the product. A CUID is never connected to a user's name, email address, or other personal contact information. CUIDs are used for the sole purpose of filtering redundant information. Each of these information exchanges occurs anonymously.

Viewpoint Manager is considered as foistware instead of malware since it is installed without user's approval but doesn't spy or do anything "bad". This may change, read Viewpoint to Plunge Into Adware.
I recommend that you remove the Viewpoint products; however, decide for yourself. To uninstall the the Viewpoint components (Viewpoint, Viewpoint Manager, Viewpoint Media Player):
  • Click Start, point to Settings, and then click Control Panel.
  • In Control Panel, double-click Add or Remove Programs.
  • In Add or Remove Programs, highlight >>Viewpoint component<< , click Remove.
  • Do the same for each Viewpoint component.
Post a fresh HJT log for review and let me know how it's running now.
I do need help. I apologize for my absence, I have been busy with work and school and lost track of this link. You ask to add remove the programs marked in red, but all that I see in your post is the phrase "P2P PROGRAMS" in red. Not sure if I am missing something or do you want me to locate the peer to peer programs I have installed and remove them before moving forward. Thanks, Jordan
Sorry about that. The bb code formatting wasn't correct. The program in question is this:

BitTorrent 5.0.8


It's up to you whether or not you want to keep it or not. We just ask that you do not use it while we are cleaning you up. I will say that probably 8 or 9 out of every 10 people who come into these forums with an infected computer have been infected by using some form of file sharing program. I don't have hard data to back that up…just seen lots of logs.
Here is the new Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:51:34 PM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\Documents and Settings\JR\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [Barb Sect] C:\DOCUME~1\JR\APPLIC~1\DOWNLO~1\Delete Trust Pop.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176234984750
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

I haven't noticed the pop ups, and I don't see the dual iexplorer running in the background at the moment. I did just restart before I installed the new java though; could still be there just waiting to load up.
Well, this entry in HJT tells me LOP infection is still present, or returned. Tough to tell because of the delay between posts. I would advise you to run the LOP fix again from my earlier post and post a fresh HJT log after rebooting.
NoLop! Log by Skate_Punk_21

Please Note: any existing old logs will have now been renamed to NoLop!OLD.log

Fix running from: C:\Documents and Settings\[removed]\Desktop
[10/10/2007]
[9:08:21 PM]

—Infection Files Found/Removed—
NO INFECTION FILES FOUND - Cleaning Aborted.

—Listing AppData sub directories—

C:\Documents and Settings\All Users\Application Data\Adobe
C:\Documents and Settings\All Users\Application Data\Aol
C:\Documents and Settings\All Users\Application Data\Aol Downloads
C:\Documents and Settings\All Users\Application Data\Aol Ocp
C:\Documents and Settings\All Users\Application Data\Apple
C:\Documents and Settings\All Users\Application Data\Apple Computer
C:\Documents and Settings\All Users\Application Data\Corel
C:\Documents and Settings\All Users\Application Data\Cyberlink
C:\Documents and Settings\All Users\Application Data\Dell
C:\Documents and Settings\All Users\Application Data\Google
C:\Documents and Settings\All Users\Application Data\Gtek
C:\Documents and Settings\All Users\Application Data\Installshield
C:\Documents and Settings\All Users\Application Data\Mcafee
C:\Documents and Settings\All Users\Application Data\Microsoft
C:\Documents and Settings\All Users\Application Data\Once Dog Dupe Amok – EMPTY Directory
C:\Documents and Settings\All Users\Application Data\Sbsi
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
C:\Documents and Settings\All Users\Application Data\Viewpoint
C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
C:\Documents and Settings\Default User\Application Data\Ati
C:\Documents and Settings\Default User\Application Data\Gtek
C:\Documents and Settings\Default User\Application Data\Identities
C:\Documents and Settings\Default User\Application Data\Microsoft
C:\Documents and Settings\Jr\Application Data\Acccore
C:\Documents and Settings\Jr\Application Data\Adobe
C:\Documents and Settings\Jr\Application Data\Adobeum – EMPTY Directory
C:\Documents and Settings\Jr\Application Data\Apple Computer
C:\Documents and Settings\Jr\Application Data\Ati
C:\Documents and Settings\Jr\Application Data\Bittorrent
C:\Documents and Settings\Jr\Application Data\Corel
C:\Documents and Settings\Jr\Application Data\Cyberlink
C:\Documents and Settings\Jr\Application Data\Divx
C:\Documents and Settings\Jr\Application Data\Downloadbinwindow
C:\Documents and Settings\Jr\Application Data\Dvdcss
C:\Documents and Settings\Jr\Application Data\Google
C:\Documents and Settings\Jr\Application Data\Gtek
C:\Documents and Settings\Jr\Application Data\Identities
C:\Documents and Settings\Jr\Application Data\Macromedia
C:\Documents and Settings\Jr\Application Data\Microsoft
C:\Documents and Settings\Jr\Application Data\Move Networks
C:\Documents and Settings\Jr\Application Data\Mozilla
C:\Documents and Settings\Jr\Application Data\Real
C:\Documents and Settings\Jr\Application Data\Sun
C:\Documents and Settings\Jr\Application Data\Talkback
C:\Documents and Settings\Jr\Application Data\Viewpoint
C:\Documents and Settings\Jr\Application Data\Vlc
C:\Documents and Settings\Jr\Application Data\Winrar – EMPTY Directory
C:\Documents and Settings\Localservice\Application Data\Microsoft
C:\Documents and Settings\Networkservice\Application Data\Microsoft

Logfile of HijackThis v1.99.1
Scan saved at 9:15:41 PM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\JR\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=1070323
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk-rel&channel;=us&ibd;=1070323
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google; - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [Barb Sect] C:\DOCUME~1\JR\APPLIC~1\DOWNLO~1\Delete Trust Pop.exe
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth; Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176234984750
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

Here ya go. The Lop fix found nothing :(.
I see it found nothing, but I'm pretty sure that's LOP.

Run HijackThis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on this:

O4 - HKCU\..\Run: [Barb Sect] C:\DOCUME~1\JR\APPLIC~1\DOWNLO~1\Delete Trust Pop.exe

Then close all windows except this one and press Fix checked.

Using Windows Explorer delete that file (note, because of the way it's displayed the path may be slightly different):

C:\DOCUMENTS AND SETTINGS\JR\APPLICATION DATA\DOWNLOADS\Delete Trust Pop.exe

You can also do a search for that file if you cannot identify the path.

Then:

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG

  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.

Restart into normal mode and post the AVG Log and a new HJT Log. Also how are things now
I am having trouble finding the file via windows explorer. I think the file is hidden, and thus I can't just click through the files to find it.
Yes good point. Search by doing the following: Click Start > Search > All Files And Folders Under More Advanced Options, make sure the following are checked: *Search system folders *Search hidden files and folders *Search subfolders Enter the file and click Search
Alrighty, that took a while. Here ya go.

Logfile of HijackThis v1.99.1
Scan saved at 11:18:33 PM, on 10/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16512)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\JR\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=1070323
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176234984750
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - C:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\vstskmgr.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:12:52 PM 10/10/2007

+ Scan result:



C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP152\A0013396.dll -> Adware.WinZix : Cleaned with backup (quarantined).
:mozilla.100:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.101:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.102:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.103:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.104:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.121:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.122:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.123:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.124:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.125:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.126:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.128:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.129:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.482:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.683:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.83:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.84:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.85:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.86:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.87:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.88:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.89:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.90:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.91:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.92:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.93:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.94:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.95:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.96:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.97:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.98:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.99:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.305:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.306:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.307:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.308:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.309:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.310:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.176:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.493:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.494:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.495:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.496:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.497:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.498:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.499:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.501:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.326:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.327:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.328:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.329:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.330:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.174:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.500:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.766:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.767:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.335:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.336:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.362:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.363:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.364:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.365:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.366:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.367:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.368:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.369:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.763:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned.
:mozilla.346:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.581:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.582:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.583:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.584:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.61:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.58:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.59:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.62:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.63:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.64:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.65:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.375:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.376:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.377:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.378:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.379:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.380:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.381:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.389:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.390:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.615:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.563:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.162:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.502:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.503:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.504:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.505:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.506:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.507:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.508:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.509:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.510:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.238:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.239:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.382:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.383:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.384:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.385:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.386:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.240:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.241:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.242:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.243:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.244:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.245:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.246:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.247:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.248:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.249:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.250:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.251:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.252:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.253:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.254:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.255:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.256:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.257:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.469:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.470:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.471:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.472:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.473:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.474:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.315:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.316:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.184:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.186:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.188:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.198:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.201:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.202:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.337:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.772:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.189:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.190:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.191:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.192:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.193:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.194:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.195:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.199:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.200:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.60:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.154:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.156:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.157:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.158:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.159:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.160:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.161:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.359:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.360:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.361:C:\Documents and Settings\JR\Application Data\Mozilla\Firefox\Profiles\bw6lr630.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Seems to be running better, but again I can't know for sure if the popups are gone.

Also, I do remember downloading the program winzix to uncompress a video file I downloaded. It does seem that the popups started occuring shortly after. Hope this helps.

Jordan

Also, I do remember downloading the program winzix to uncompress a video file I downloaded. It does seem that the popups started occuring shortly after.


Bingo! :wacko: I just went to their "website" and downloaded their "software" onto my clean VM. I promptly had a wonderful LOP infection. This "software" is nothing but garbage…they should be shutdown. The program doesn't even DO anything from what I can tell. And even after attempting to remove the software through Add or Remove Programs LOP was still hanging around.

Let's get a Kaspersky scan too.

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.

Also, were you able to delete that file Delete Trust Pop.exe?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI