This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Think I have a trojan...

32 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:36 PM, on 10/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AOL 9.0\waol.exe
C:\Program Files\AOL 9.0\shellmon.exe
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\pchealth\helpctr\binaries\HelpCtr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: VPN Client.lnk = ?
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\DOCUME~1\TRACYB~1\LOCALS~1\Temp\WZSE0.TMP\INSTAL~1.EXE (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 9892 bytes
Hello tracy419 and welcome to the What the Tech Forums

My name is Trevuren and I will be helping you with your problem.


Your computer appears to have been infected by a backdoor trojan. These programs have the ability to steal passwords and other information from your system. If you use your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:

* Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
* Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
* Consider what other private information could possibly have been taken from your computer and take appropriate steps

This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.

If you wish to reformat then please let me know in your next response, I'll now continue with instructions for cleaning.

==================================================================

Download SDFix and save it to your Desktop.

Double click SDFix.exe and it will extract the files to %systemdrive%
(Drive that contains the Windows Directory, typically C:\SDFix)

Please then reboot your computer in Safe Mode by doing the following :
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
  • Open the extracted SDFix folder and double click RunThis.bat to start the script.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
  • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
  • Finally paste the contents of the Report.txt back on the forum with a new HijackThis log

Regards,

Trevuren
Oh god, worse than I thought. If there is not a 100% way to know it is completely gone, I definitely am interested in reformatting my computer. Will the files I back up before reformatting re-infect the system if I load them onto the newly reformatted computer? If so, is there any way to save these files and not have them infected? Thanks so much for your help.
Here is some info that may be of use:


How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
http://www.dslreports.com/faq/10451

When should I re-format? How should I reinstall?
http://www.dslreports.com/faq/10063

If you choose to format and reinstall see this link for instructions:
http://www.cyberwalker.net/faqs/how-tos/reinstall-faq.html


In this particular case, I would only backup your essential data and pictures. To tell you the truth, I would still go through the process of cleaning up your PC first so that you eliminate the active infection and maximize your chances of not contaminating your backups.

Your choice. If you decide to follow my advice, please continue with the fix as posted in my first reply.

Good Luck,

Trevuren
Thanks, attaching the sdfix log.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:07 PM, on 10/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - AppInit_DLLs: C:\WINDOWS\system32\sulimo.dat
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\DOCUME~1\TRACYB~1\LOCALS~1\Temp\WZSE0.TMP\INSTAL~1.EXE (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 9992 bytes

Attachments:

Please download SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Double-click smitfraudfix.exe
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm


Regards,

Trevuren
SmitFraudFix v2.242 Scan done at 23:02:20.28, Thu 10/25/2007 Run from C:\Documents and Settings\Tracy Berkman\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\igfxsrvc.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\sulimo.dat FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\WINDOWS\\system32\\sulimo.dat" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Please print out or copy these instructions/tutorial to Notepad as the internet will not be available to you at certain points of the removal process (while in Safe Mode). Make sure to work through all the Steps in the exact order in which they are listed below. If there's anything that you don't understand, ask your question(s) before moving on with the fixes.


1. Download and update AVG AntiSpyware 7.5.

First download AVG AntiSpyware from HERE and save that file to your desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG AntiSpyware, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete, run AVG AntiSpyware and update the definition files.
  • On the main screen select the icon "Update" then select the "Update now" link.
    • Next select the "Start Update" button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then select "Quarantine".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG AntiSpyware, Do Not run a scan just yet


2. Reboot your computer into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3. Once in Safe Mode, double-click Smitfraudfix.exe
Select option #2 - Clean by typing 2 and press Enter to delete the infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?" answer Yes by typing Y and hit Enter.
The tool will now check if wininet.dll is infected. If a clean version is found, you will be prompted to replace wininet.dll. Answer Yes to the question "Replace infected file ?" by typing Y and hit Enter.

A reboot may be needed to finish the cleaning process, if you computer does not restart automatically please do it yourself manually. Reboot in Safe Mode.

The tool will create a log named rapport.txt in the root of your drive, eg: Local Disk C: or partition where your operating system is installed. Please post that log along with all others requested in your next reply.


4. Clean out your Temporary Internet files. Proceed as follows:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.

5. Next Click Start, click Control Panel and then double-click Display. Click on the Desktop tab, then click the Customize Desktop button. Click on the Web tab. Under Web Pages you should see a checked entry called Security info or something similar. If it is there, select that entry and click the Delete button. Click Ok then Apply and Ok.

6. Empty the Recycle Bin by right-clicking the Recycle Bin icon on your Desktop, and then clicking Empty Recycle Bin.

7. Launch AVG AntiSpyware by double-clicking the icon on your desktop.
  • Note: IMPORTANT: Do not open any other windows or programs while AVG AntiSpyware is scanning, it may interfere with the scanning proccess
  • Select the "Scanner" icon at the top and then the "Scan" tab then click on "Complete System Scan".
  • AVG AntiSpyware will now begin the scanning process, be patient this may take a little time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all actions"
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the screen and save it to a text file on your DESKTOP (This is important).
8. Close AVG AntiSpyware and Reboot back into Normal Windows Mode

9. Run SmitfraudFix. Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #3 - Delete Trusted zone by typing 3 and press Enter
Answer YES to the question "Restore Trusted Zone?" by Typing Y and hit Enter.

Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.

10. Please Post the following logs:
  • c:\rapport.txt
  • AVG AntiSpyware log (if made available)
  • A new HijackThis log
Your may need several replies to post the requested logs, otherwise they might get cut off.

Regards,

Trevuren
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:56:47 AM, on 10/26/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\scriptcl.dll
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1184392617\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [PMCRemote] C:\Program Files\Pinnacle\Shared Files\\Programs\Remote\Remoterm.exe
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\AOL 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [DW4] "C:\Program Files\The Weather Channel FW\Desktop Weather\DesktopWeather.exe"
O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {238F6F83-B8B4-11CF-8771-00A024541EE3} (Citrix ICA Client) - http://a516.g.akamai.net/f/516/25175/7d/ru…cat-no-eula.cab
O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (Automatic Driver Installation Control) - http://inst.c-wss.com/n035p/EN/install/gtdownlr.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase2895.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/…loadcontrol.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\480\G2AWinLogon.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. Installer service (CiscoVpnInstallService) - Unknown owner - C:\DOCUME~1\TRACYB~1\LOCALS~1\Temp\WZSE0.TMP\INSTAL~1.EXE (file missing)
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\480\g2aservice.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
O23 - Service: Intel® PROSet/Wireless SSO Service (WLANKEEPER) - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe

–
End of file - 9525 bytes
(The Rapport.txt made after I pressed 2 and then re-ran it like it told me to.) SmitFraudFix v2.242 Scan done at 0:36:15.23, Fri 10/26/2007 Run from C:\Documents and Settings\Tracy Berkman\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in safe mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost »»»»»»»»»»»»»»»»»»»»»»»» Winsock2 Fix S!Ri's WS2Fix: LSP not Found. »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\system32\Delete_Me_Dummy_sulimo.dat Deleted »»»»»»»»»»»»»»»»»»»»»»»» DNS HKLM\SYSTEM\CCS\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\..\{57C6AED3-5E78-4610-8AFC-F13E57F354EB}: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» End
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 9:01:32 AM 10/26/2007 + Scan result: C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP106\A0024749.exe -> Downloader.Agent.ekd : No action taken. :mozilla.451:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.247realmedia : No action taken. :mozilla.149:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.316:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.676:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.684:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.70:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.719:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.71:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.72:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.73:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.74:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.76:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.77:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.78:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.79:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.80:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.81:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.83:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.84:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.85:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.86:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.87:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.88:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.898:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.89:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.90:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.91:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.92:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.93:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.94:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.95:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. :mozilla.96:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@2o7[2].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@brightcove.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@charmingshoppes.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@marketlive.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@mcclatchy.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@msnservices.112.2o7[2].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@taymark.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@ulta.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@viamtvcom.112.2o7[2].txt -> TrackingCookie.2o7 : No action taken. :mozilla.461:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.462:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.463:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. :mozilla.468:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@adbrite[3].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : No action taken. :mozilla.151:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.152:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.153:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.154:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.155:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.156:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.157:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.158:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][3].txt -> TrackingCookie.Adrevolver : No action taken. :mozilla.615:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adtech : No action taken. :mozilla.616:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Adtech : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@adtech[1].txt -> TrackingCookie.Adtech : No action taken. :mozilla.12:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.13:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.14:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.15:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Advertising : No action taken. :mozilla.16:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Advertising : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@advertising[2].txt -> TrackingCookie.Advertising : No action taken. :mozilla.17:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. :mozilla.440:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Bluestreak : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Bridgetrack : No action taken. :mozilla.378:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Burstbeacon : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][3].txt -> TrackingCookie.Burstbeacon : No action taken. :mozilla.376:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. :mozilla.377:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : No action taken. :mozilla.265:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.266:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.267:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.268:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken. :mozilla.648:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Cnn : No action taken. :mozilla.649:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Cnn : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Cnn : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@com[1].txt -> TrackingCookie.Com : No action taken. :mozilla.438:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken. :mozilla.501:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Coremetrics : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : No action taken. :mozilla.9:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : No action taken. :mozilla.260:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.261:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. :mozilla.262:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Euroclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken. :mozilla.211:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.212:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.213:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.214:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.215:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.216:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. :mozilla.217:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Fastclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@fortunecity[2].txt -> TrackingCookie.Fortunecity : No action taken. :mozilla.329:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Googleadservices : No action taken. :mozilla.304:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.341:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.347:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.348:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.576:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.577:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.786:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.831:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.832:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.833:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.834:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.871:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.872:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.873:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.874:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.875:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. :mozilla.906:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken. :mozilla.339:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken. :mozilla.340:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Imrworldwide : No action taken. :mozilla.827:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Information : No action taken. :mozilla.512:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Live : No action taken. :mozilla.513:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Live : No action taken. :mozilla.514:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Live : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Live : No action taken. :mozilla.412:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.413:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.414:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.415:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.605:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. :mozilla.606:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Liveperson : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : No action taken. :mozilla.387:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Masterstats : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : No action taken. :mozilla.57:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken. :mozilla.485:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Msn : No action taken. :mozilla.486:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Msn : No action taken. :mozilla.487:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Msn : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Msn : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][3].txt -> TrackingCookie.Msn : No action taken. :mozilla.396:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Netflame : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Netflame : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@overture[2].txt -> TrackingCookie.Overture : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken. :mozilla.317:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Paypal : No action taken. :mozilla.368:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.369:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.370:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.371:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.372:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.373:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.374:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. :mozilla.375:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pointroll : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken. :mozilla.697:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pro-market : No action taken. :mozilla.698:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pro-market : No action taken. :mozilla.699:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Pro-market : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@qksrv[2].txt -> TrackingCookie.Qksrv : No action taken. :mozilla.10:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.11:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Questionmarket : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken. :mozilla.275:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. :mozilla.276:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. :mozilla.277:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. :mozilla.278:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Realmedia : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@realmedia[2].txt -> TrackingCookie.Realmedia : No action taken. :mozilla.894:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revenue : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@revenue[2].txt -> TrackingCookie.Revenue : No action taken. :mozilla.101:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.102:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.103:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.104:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.106:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.107:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.108:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. :mozilla.177:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Revsci : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@revsci[2].txt -> TrackingCookie.Revsci : No action taken. :mozilla.400:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. :mozilla.402:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Ru4 : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken. :mozilla.441:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.442:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.443:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.444:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.445:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. :mozilla.446:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed]-sys[3].txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@sexlist[2].txt -> TrackingCookie.Sexlist : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Sextracker : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Sextracker : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@sextracker[1].txt -> TrackingCookie.Sextracker : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@smartadserver[1].txt -> TrackingCookie.Smartadserver : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken. :mozilla.384:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.385:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. :mozilla.386:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken. :mozilla.283:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.284:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.285:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.286:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.287:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.288:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.289:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken. :mozilla.150:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Valuead : No action taken. :mozilla.474:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Webtrends : No action taken. :mozilla.476:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Webtrends : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : No action taken. :mozilla.650:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@xxxcounter[1].txt -> TrackingCookie.Xxxcounter : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@xxxcounter[2].txt -> TrackingCookie.Xxxcounter : No action taken. :mozilla.178:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.179:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.180:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.181:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.182:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.183:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.184:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.185:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken. :mozilla.186:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Zedo : No action taken. :mozilla.187:C:\Documents and Settings\Tracy Berkman\Application Data\Mozilla\Firefox\Profiles\ygejed9j.default\cookies.txt -> TrackingCookie.Zedo : No action taken. C:\Documents and Settings\Tracy Berkman\Cookies\tracy_berkman@zedo[2].txt -> TrackingCookie.Zedo : No action taken. ::Report end
A. Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 3 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u3…allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u3-windows-i586-p.exe to install the newest version.
Now to Clean out the Java cache:

Go into the Control Panel and double-click the Java Icon.
  • Under Temporary Internet Files, click the Delete Files button.
  • There are three options in the window to clear the cache - Leave ALL 3 Checked
    • Downloaded Applets
      Downloaded Applications
      Other Files
  • Click OK on Delete Temporary Files Window
    Note: This deletes ALL the Downloaded Applications and Applets from the CACHE.
  • Click OK to leave the Java Control Panel.

B. Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.


C. Now, please tell me how your system is running. If all is well, we can procede with the final cleanup procedures
Sorry, I got lost at: Go to Start > Settings > Control Panel, double-click on and remove all older versions of Java. Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name. Click the Remove or Change/Remove button. Repeat as many times as necessary to remove each Java versions. I didn't see anything in the Control Panel about Java, except "Java Plug-In" which cannot be deleted. I am on XP, is this the right way to do it?
OK, please do the following:

Please provide a list of uninstallable programs.

To Provide a List of Installed Programs
  • Run HijackThis.
  • Click Config>>Miscellaneous Tools>>Open Uninstall Manager>>Save List
  • Save list to Desktop
  • Copy the Notepad list and Paste it into this thread.
Ok, here is the log. Do you want me to forget about installing the java exe I downloaded and ATF? Ad-Aware 2007 Adobe Acrobat - Reader 6.0.2 Update Adobe Bridge 1.0 Adobe Common File Installer Adobe Flash Player ActiveX Adobe Flash Player Plugin Adobe Help Center 1.0 Adobe Photoshop CS2 Adobe Reader 6.0.1 Adobe Stock Photos 1.0 AIM 6 AOL Coach Version 1.0(Build:20040229.1 en) AOL Uninstaller (Choose which Products to Remove) AOLIcon Apple Mobile Device Support Apple Software Update AVG Anti-Spyware 7.5 BitTorrent 5.0.9 Broadcom Management Programs Canon MP150 Cisco Systems VPN Client 5.0.00.0340 Conexant HDA D110 MDC V.92 Modem Dell Digital Jukebox Driver Dell Game Console DellSupport Digital Content Portal Digital Line Detect DivX Codec DivX Converter DivX Player DivX Web Player Documentation & Support Launcher EarthLink setup files EducateU ELIcon Games, Music, & Photos Launcher GemMaster Mystic GoToAssist 8.0.0.480 High Definition Audio Driver Package - KB835221 HijackThis 2.0.2 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 10 (KB903157) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB888795) Hotfix for Windows XP (KB891593) Hotfix for Windows XP (KB895961) Hotfix for Windows XP (KB899337) Hotfix for Windows XP (KB899510) Hotfix for Windows XP (KB902841) Hotfix for Windows XP (KB915865) Hotfix for Windows XP (KB926239) Intel® Graphics Media Accelerator Driver Intel® PROSet/Wireless Software iTunes Jasc Animation Shop 3 Java 2 Runtime Environment, SE v1.4.2_03 Kaspersky Online Scanner Learn2 Player (Uninstall Only) McAfee VirusScan Enterprise mCore mDrWiFi MetaFrame Presentation Server Web Client for Win32 mHlpDell Microsoft .NET Framework 1.0 Hotfix (KB887998) Microsoft .NET Framework 1.0 Hotfix (KB930494) Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Enterprise 2007 Microsoft Office Enterprise 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office Groove MUI (English) 2007 Microsoft Office Groove Setup Metadata MUI (English) 2007 Microsoft Office Home and Student 2007 Microsoft Office Home and Student 2007 Trial Microsoft Office InfoPath MUI (English) 2007 Microsoft Office OneNote MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft Plus! Digital Media Edition Installer Microsoft Plus! Photo Story 2 LE Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable mIWA mLogView mMHouse Modem Helper Mozilla Firefox (2.0.0.8) mPfMgr mPfWiz mProSafe mSSO MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 Parser and SDK Musicmatch® Jukebox mWlsSafe mWMI mXML mZConfig NetWaiting NetZeroInstallers Otto Pinnacle TVCenter Pro PowerDVD 5.7 QuickSet QuickTime RealPlayer Basic Security Update for Excel 2007 (KB936509) Security Update for Microsoft .NET Framework 2.0 (KB928365) Security Update for Office 2007 (KB934062) Security Update for Office 2007 (KB936514) Security Update for the 2007 Microsoft Office System (KB936960) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB941202) Sonic DLA Sonic Encoders Sonic MyDVD LE Sonic RecordNow Audio Sonic RecordNow Copy Sonic RecordNow Data Sonic Update Manager Synaptics Pointing Device Driver The Weather Channel Desktop Ultra QuickTime Converter 2.3.0916 Update for Windows Media Player 10 (KB913800) Update for Windows Media Player 10 (KB926251) Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) Update Rollup 2 for Windows XP Media Center Edition 2005 VeohTV BETA Viewpoint Media Player Weather Services WebCyberCoach 3.2 Dell WildTangent Web Driver Windows Internet Explorer 7 Windows Live OneCare safety scanner Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 10 Windows Media Player 10 Hotfix [See EmeraldQFE2 for more information] Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890927 Windows XP Media Center Edition 2005 KB908246 Windows XP Media Center Edition 2005 KB925766 WinRAR archiver

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI