This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Computer very slow

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A couple of weeks ago, my Internet Explorer was running very slow. I installed Mozilla Firefox, and also replaced my Norton SystemWorks with Trend-Micro's PC-cillin. However, this did not solve the problem. The internet connection is fine. I also defragged my computer.

The computer is very slow to boot up, and very slow in opening an internet browser.

Any advice?

Here is my HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 8:00:57 PM, on 11/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.comcast.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5685BC20-FBE6-11D2-885F-00A0243C2C64} (iVantage Remote Data Control) - https://ivantage.thermo.com/ivantagetec/Com…SpectrumRDC.cab
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - https://ivantage.thermo.com/ivantagetec/Common/iemenu.cab
O16 - DPF: {A7A61128-0EAA-11D1-B22F-0000C08C00C4} (SSDBCombo Control 3.1 - A) - https://ivantage.thermo.com/ivantagetec/Common/Ssdw3b32.cab
O16 - DPF: {BEB82CC6-09F3-43EA-BEB1-97188E21035D} (FootPedalCtl Class) - http://sten-tel1.mttest.com/Shared/footpedal.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) - https://ivantage.thermo.com/ivantagetec/Rep…veXViewer80.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Hi phesters and welcome to the forums.

My name is Dave. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can sometimes take a while to research so please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
————————————————————————–

I suspect this may be an AWF infection. AWF replaces .exe files with it's infected files and places the good files into a bak folder. Let's find out…

Download FindAWF:

Save the file to the Desktop
Double-click the FindAWF icon.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 1 then Enter to scan for bak folders
The scan may take a while, please be patient.

When done, a text file, Find AWF report is produced that we need to look at.
Please post it in your reply.
Here is the AWF report: Find AWF report by noahdfear ©2006 Version 1.40 The current date is: Wed 11/07/2007 The current time is: 14:02:00.98 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 07/06/2001 04:56 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 11/12/2003 05:21 PM 77,824 qttask.exe 1 File(s) 77,824 bytes Directory of C:\PROGRA~1\SYMNET~1\BAK 12/26/2005 05:24 PM 100,056 SNDMon.exe 1 File(s) 100,056 bytes Directory of C:\PROGRA~1\WIFD1F~1\BAK 11/03/2006 06:20 PM 866,584 MSASCui.exe 1 File(s) 866,584 bytes Directory of C:\WINDOWS\SMINST\BAK 06/15/2001 05:34 PM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 10/09/2007 08:04 PM 179 hpsysdrv.DAT 05/07/1998 11:04 AM 52,736 hpsysdrv.exe 2 File(s) 52,915 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/04/2004 02:56 AM 15,360 ctfmon.exe 08/07/2001 06:36 PM 90,112 hkcmd.exe 08/07/2001 07:25 PM 143,360 igfxtray.exe 07/03/2001 04:13 PM 81,920 ps2.exe 4 File(s) 330,752 bytes Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK 12/02/2003 04:11 PM 54,296 ccApp.exe 12/02/2003 04:11 PM 58,392 ccRegVfy.exe 2 File(s) 112,688 bytes Directory of C:\PROGRA~1\CREATIVE\SHARED~1\BAK 04/29/2004 09:59 AM 245,760 CAMTRAY.EXE 1 File(s) 245,760 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\BAK 07/17/2007 07:30 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK 05/11/2007 02:06 AM 40,048 Reader_sl.exe 1 File(s) 40,048 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 08/22/2006 05:58 AM 180,269 realsched.exe 1 File(s) 180,269 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 28172 Oct 8 2007 "C:\hp\KBD\KBD.EXE" 61440 Jul 6 2001 "C:\hp\KBD\bak\KBD.EXE" 28172 Oct 8 2007 "C:\Program Files\QuickTime\qttask.exe" 77824 Nov 12 2003 "C:\Program Files\QuickTime\bak\qttask.exe" 28172 Oct 8 2007 "C:\Program Files\SymNetDrv\SNDMon.exe" 100056 Dec 26 2005 "C:\Program Files\SymNetDrv\bak\SNDMon.exe" 28172 Oct 8 2007 "C:\Program Files\Windows Defender\MSASCui.exe" 866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe" 28172 Oct 8 2007 "C:\WINDOWS\SMINST\RECGUARD.EXE" 212992 Jun 15 2001 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 188 Oct 8 2007 "C:\WINDOWS\SYSTEM\hpsysdrv.DAT" 179 Oct 9 2007 "C:\WINDOWS\SYSTEM\bak\hpsysdrv.DAT" 28172 Oct 8 2007 "C:\WINDOWS\SYSTEM\hpsysdrv.exe" 52736 May 7 1998 "C:\WINDOWS\SYSTEM\bak\hpsysdrv.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 28172 Oct 8 2007 "C:\WINDOWS\SYSTEM32\hkcmd.exe" 90112 Aug 7 2001 "C:\hp\drivers\video\HKCMD.EXE" 90112 Aug 7 2001 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 28172 Oct 8 2007 "C:\WINDOWS\SYSTEM32\igfxtray.exe" 143360 Aug 7 2001 "C:\hp\drivers\video\IGFXTRAY.EXE" 143360 Aug 7 2001 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 28172 Oct 8 2007 "C:\WINDOWS\SYSTEM32\ps2.exe" 81920 Jul 3 2001 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 3 2001 "C:\WINDOWS\SYSTEM32\bak\ps2.exe" 54296 Dec 2 2003 "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe" 58392 Dec 2 2003 "C:\Program Files\Common Files\Symantec Shared\bak\ccRegVfy.exe" 28172 Oct 8 2007 "C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" 245760 Apr 29 2004 "C:\Program Files\Creative\Shared Files\bak\CAMTRAY.EXE" 476864 Mar 7 2004 "C:\Program Files\Google\GoogleToolbarInstaller.exe" 28172 Oct 8 2007 "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 559784 Aug 22 2006 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe" 138168 Feb 1 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 17 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 28172 Oct 8 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" 40048 May 11 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe" 28172 Oct 8 2007 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 180269 Aug 22 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" end of report
Well that confirms it is AWF. This will take a few more steps to get cleaned up so please be patient.

Please double-click the FindAWF icon once again.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak folders

A text file opens called: files.txt
Copy and paste the following list of files from in the code box to be restored:

"C:\hp\KBD\bak\KBD.EXE"
"C:\Program Files\QuickTime\bak\qttask.exe"
"C:\Program Files\SymNetDrv\SNDMon.exe""C:\Program Files\SymNetDrv\bak\SNDMon.exe"
"C:\Program Files\Windows Defender\bak\MSASCui.exe"
"C:\WINDOWS\SMINST\bak\RECGUARD.EXE"
"C:\WINDOWS\SYSTEM\bak\hpsysdrv.DAT"
"C:\WINDOWS\SYSTEM\bak\hpsysdrv.exe"
"C:\WINDOWS\SYSTEM32\bak\ctfmon.exe"
"C:\WINDOWS\SYSTEM32\bak\hkcmd.exe"
"C:\WINDOWS\SYSTEM32\bak\igfxtray.exe"
"C:\WINDOWS\SYSTEM32\bak\ps2.exe"
"C:\Program Files\Common Files\Symantec Shared\bak\ccRegVfy.exe"
"C:\Program Files\Creative\Shared Files\bak\CAMTRAY.EXE"
"C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe"
"C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe"
"C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"
Next, close and click Yes to save the changes.

Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folder

When done with the above, it automatically runs a new scan and opens a new log.
Please provide the new FindAWF log in your reply.
Here's the new report. How did this happen? Is there any way I can prevent this? Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Wed 11/07/2007 The current time is: 21:14:40.98 bak folders found ~~~~~~~~~~~ Directory of C:\HP\KBD\BAK 07/06/2001 04:56 PM 61,440 KBD.EXE 1 File(s) 61,440 bytes Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\QUICKT~1\BAK 11/12/2003 05:21 PM 77,824 qttask.exe 1 File(s) 77,824 bytes Directory of C:\PROGRA~1\SYMNET~1\BAK 12/26/2005 05:24 PM 100,056 SNDMon.exe 1 File(s) 100,056 bytes Directory of C:\PROGRA~1\WIFD1F~1\BAK 11/03/2006 06:20 PM 866,584 MSASCui.exe 1 File(s) 866,584 bytes Directory of C:\WINDOWS\SMINST\BAK 06/15/2001 05:34 PM 212,992 RECGUARD.EXE 1 File(s) 212,992 bytes Directory of C:\WINDOWS\SYSTEM\BAK 10/09/2007 08:04 PM 179 hpsysdrv.DAT 05/07/1998 11:04 AM 52,736 hpsysdrv.exe 2 File(s) 52,915 bytes Directory of C:\WINDOWS\SYSTEM32\BAK 08/04/2004 02:56 AM 15,360 ctfmon.exe 08/07/2001 06:36 PM 90,112 hkcmd.exe 08/07/2001 07:25 PM 143,360 igfxtray.exe 07/03/2001 04:13 PM 81,920 ps2.exe 4 File(s) 330,752 bytes Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK 12/02/2003 04:11 PM 54,296 ccApp.exe 12/02/2003 04:11 PM 58,392 ccRegVfy.exe 2 File(s) 112,688 bytes Directory of C:\PROGRA~1\CREATIVE\SHARED~1\BAK 04/29/2004 09:59 AM 245,760 CAMTRAY.EXE 1 File(s) 245,760 bytes Directory of C:\PROGRA~1\GOOGLE\GOOGLE~1\BAK 07/17/2007 07:30 PM 68,856 GoogleToolbarNotifier.exe 1 File(s) 68,856 bytes Directory of C:\PROGRA~1\ADOBE\READER~1.0\READER\BAK 05/11/2007 02:06 AM 40,048 Reader_sl.exe 1 File(s) 40,048 bytes Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK 08/22/2006 05:58 AM 180,269 realsched.exe 1 File(s) 180,269 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 61440 Jul 6 2001 "C:\hp\KBD\KBD.EXE" 61440 Jul 6 2001 "C:\hp\KBD\bak\KBD.EXE" 77824 Nov 12 2003 "C:\Program Files\QuickTime\qttask.exe" 77824 Nov 12 2003 "C:\Program Files\QuickTime\bak\qttask.exe" 28172 Oct 8 2007 "C:\Program Files\SymNetDrv\SNDMon.exe" 100056 Dec 26 2005 "C:\Program Files\SymNetDrv\bak\SNDMon.exe" 866584 Nov 3 2006 "C:\Program Files\Windows Defender\MSASCui.exe" 866584 Nov 3 2006 "C:\Program Files\Windows Defender\bak\MSASCui.exe" 212992 Jun 15 2001 "C:\WINDOWS\SMINST\RECGUARD.EXE" 212992 Jun 15 2001 "C:\WINDOWS\SMINST\bak\RECGUARD.EXE" 179 Oct 9 2007 "C:\WINDOWS\SYSTEM\hpsysdrv.DAT" 179 Oct 9 2007 "C:\WINDOWS\SYSTEM\bak\hpsysdrv.DAT" 52736 May 7 1998 "C:\WINDOWS\SYSTEM\hpsysdrv.exe" 52736 May 7 1998 "C:\WINDOWS\SYSTEM\bak\hpsysdrv.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\ctfmon.exe" 15360 Aug 4 2004 "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" 90112 Aug 7 2001 "C:\WINDOWS\SYSTEM32\hkcmd.exe" 90112 Aug 7 2001 "C:\hp\drivers\video\HKCMD.EXE" 90112 Aug 7 2001 "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" 143360 Aug 7 2001 "C:\WINDOWS\SYSTEM32\igfxtray.exe" 143360 Aug 7 2001 "C:\hp\drivers\video\IGFXTRAY.EXE" 143360 Aug 7 2001 "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" 81920 Jul 3 2001 "C:\WINDOWS\SYSTEM32\ps2.exe" 81920 Jul 3 2001 "C:\hp\drivers\keyboard\PS2.EXE" 81920 Jul 3 2001 "C:\WINDOWS\SYSTEM32\bak\ps2.exe" 54296 Dec 2 2003 "C:\Program Files\Common Files\Symantec Shared\bak\ccApp.exe" 58392 Dec 2 2003 "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe" 58392 Dec 2 2003 "C:\Program Files\Common Files\Symantec Shared\bak\ccRegVfy.exe" 245760 Apr 29 2004 "C:\Program Files\Creative\Shared Files\CAMTRAY.EXE" 245760 Apr 29 2004 "C:\Program Files\Creative\Shared Files\bak\CAMTRAY.EXE" 476864 Mar 7 2004 "C:\Program Files\Google\GoogleToolbarInstaller.exe" 68856 Jul 17 2007 "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" 559784 Aug 22 2006 "C:\Program Files\Common Files\Real\GToolbar\GoogleToolbarInstaller.exe" 138168 Feb 1 2007 "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" 68856 Jul 17 2007 "C:\Program Files\Google\GoogleToolbarNotifier\bak\GoogleToolbarNotifier.exe" 40048 May 11 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" 40048 May 11 2007 "C:\Program Files\Adobe\Reader 8.0\Reader\bak\Reader_sl.exe" 180269 Aug 22 2006 "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" 180269 Aug 22 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe" end of report

How did this happen?

Not sure, there's no real way to know exactly how you were infected. If you can remember exactly what you were doing just before the problems happened that may help you.

Is there any way I can prevent this?

Just make sure you have good protection in place. You have already made some good changes, by going to TrendMicro in place of System Works. System Works is an older program, was it even updated with the latest virus definitions? When we're finished I'll also make some recommendations on additional free protection you can add.

Let's continue the fix:

Please double-click the FindAWF icon once again
This time we are going to remove some folders.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 3 then Enter to remove bak folders

A text file opens called: folders.txt
Click below the line and paste the following list of folders in the code box to be removed:
C:\hp\KBD\bak
C:\Program Files\QuickTime\bak
C:\Program Files\Windows Defender\bak
C:\WINDOWS\SMINST\bak
C:\WINDOWS\SYSTEM\bak
C:\WINDOWS\SYSTEM32\bak
C:\Program Files\Common Files\Symantec Shared\bak
C:\Program Files\Creative\Shared Files\bak
C:\Program Files\Google\GoogleToolbarNotifier\bak
C:\Program Files\Adobe\Reader 8.0\Reader\bak
C:\Program Files\Common Files\Real\Update_OB\bak
Next, close and click Yes to save the changes.

When done with the above, FindAWF automatically runs a new scan and opens a new log that you need to post.
Please provide the new FindAWF log in your reply.
Here's the next AWF log: Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Thu 11/08/2007 The current time is: 16:50:49.70 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\SYMNET~1\BAK 12/26/2005 05:24 PM 100,056 SNDMon.exe 1 File(s) 100,056 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 28172 Oct 8 2007 "C:\Program Files\SymNetDrv\SNDMon.exe" 100056 Dec 26 2005 "C:\Program Files\SymNetDrv\bak\SNDMon.exe" end of report
Ooops :blush:

Fix went fine but my script on step 2 had a small error and left that one file. Just need to re-run step 2 and 3 for it. I'll give you the full instructions but you probably have this down cold by now…..

Please double-click the FindAWF icon once again.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 2 then Enter to restore files from bak folders

A text file opens called: files.txt
Copy and paste the following list of files from in the code box to be restored:
"C:\Program Files\SymNetDrv\bak\SNDMon.exe"
Next, close and click Yes to save the changes.

Once files.txt is saved, FindAWF does the following:
-It attempts to terminate the process represented by each filename on the list, if running
-Deletes the rogue file from the parent folder, if present
-Copies the original file to the parent folder

I think we should be safe to go right to step 3 on it also.

Please double-click the FindAWF icon once again
This time we are going to remove some folders.

If a Security Alert shows, allow the program to run.
As instructed, press any key to continue.
Use the following option: Press 3 then Enter to remove bak folders

A text file opens called: folders.txt
Click below the line and paste the following list of folders in the code box to be removed:
C:\Program Files\SymNetDrv\bak
Next, close and click Yes to save the changes.

When done with the above, FindAWF automatically runs a new scan and opens a new log that you need to post.
Please provide the new FindAWF log in your reply.
Here are step 2 (just in case) and step 3: Find AWF report by noahdfear ©2006 Version 1.40 Option 2 run successfully The current date is: Thu 11/08/2007 The current time is: 21:04:50.56 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Directory of C:\PROGRA~1\SYMNET~1\BAK 12/26/2005 05:24 PM 100,056 SNDMon.exe 1 File(s) 100,056 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ 100056 Dec 26 2005 "C:\Program Files\SymNetDrv\SNDMon.exe" 100056 Dec 26 2005 "C:\Program Files\SymNetDrv\bak\SNDMon.exe" end of report Find AWF report by noahdfear ©2006 Version 1.40 Option 3 run successfully The current date is: Thu 11/08/2007 The current time is: 21:13:18.46 bak folders found ~~~~~~~~~~~ Directory of C:\PROGRA~1\MSNMES~1\BAK 0 File(s) 0 bytes Duplicate files of bak directory contents ~~~~~~~~~~~~~~~~~~~~~~~ end of report
To finish, run Option 4.

Double-click the FindAWF icon once again.
Use the following option: Press 4 then Enter to reset domain zones.

When the program returns to the main menu, use the following option:
Press E then Enter to EXIT

Reboot, and post a fresh HijackThis log, please also let me know how it's running now. I will probably advise some scans but I'd like to see where we're at first.
Here's the HijackThis file. Should I be concerned about the "doginhispen.com" and "whataboutadog.com" entires at O15? I've never heard of these before. I meant to ask that when I first submitted the log.

The computer was very slow this morning, but after rebooting it twice, it was faster, but just as fast as it was when I first told you of the problem.



Logfile of HijackThis v1.99.1
Scan saved at 10:07:40 AM, on 11/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.comcast.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
- C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} -
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -
C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security
2007\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program
Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program
Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -
C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O15 - Trusted Zone: *.doginhispen.com
O15 - Trusted Zone: *.whataboutadog.com
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5685BC20-FBE6-11D2-885F-00A0243C2C64} (iVantage Remote Data Control)
- https://ivantage.thermo.com/ivantagetec/Com…SpectrumRDC.cab
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) -
https://ivantage.thermo.com/ivantagetec/Common/iemenu.cab
O16 - DPF: {A7A61128-0EAA-11D1-B22F-0000C08C00C4} (SSDBCombo Control 3.1 - A) -
https://ivantage.thermo.com/ivantagetec/Common/Ssdw3b32.cab
O16 - DPF: {BEB82CC6-09F3-43EA-BEB1-97188E21035D} (FootPedalCtl Class) -
http://sten-tel1.mttest.com/Shared/footpedal.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer
Control) - https://ivantage.thermo.com/ivantagetec/Rep…veXViewer80.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation
- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro
Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro
Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation
- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Did you run option 4 on the AWF tool? That should have cleared out those 015's. Those are what indicated to me this was AWF. It's part of it and we don't want them. Try using option 4 again. If that doesn't work then use HJT to remove them and post a new log. Just for old times sake…run option 1 on the AWF tool again also and post any log it produces, just in case it's come back.
OK, I ran AWF option 4 again, rebooted, and ran HJT again. As you'll see in the log below, that seemed to get rid of the O15's. I also ran AWF option 1 again and posted the log below..


Logfile of HijackThis v1.99.1
Scan saved at 2:15:11 PM, on 11/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\Program Files\Trend Micro\Internet Security 2007\pccguide.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\HijackThis.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tsc.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
www.comcast.net
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common
Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} -
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} -
c:\program files\google\googletoolbar4.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} -
C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program
files\google\googletoolbar4.dll
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security
2007\pccguide.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program
Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console -
{08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program
Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program
Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} -
C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 -
{e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network
Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program
Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger -
{FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O14 - IERESET.INF: START_PAGE_URL=http://www.comcast.net
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {5685BC20-FBE6-11D2-885F-00A0243C2C64} (iVantage Remote Data Control)
- https://ivantage.thermo.com/ivantagetec/Com…SpectrumRDC.cab
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) -
https://ivantage.thermo.com/ivantagetec/Common/iemenu.cab
O16 - DPF: {A7A61128-0EAA-11D1-B22F-0000C08C00C4} (SSDBCombo Control 3.1 - A) -
https://ivantage.thermo.com/ivantagetec/Common/Ssdw3b32.cab
O16 - DPF: {BEB82CC6-09F3-43EA-BEB1-97188E21035D} (FootPedalCtl Class) -
http://sten-tel1.mttest.com/Shared/footpedal.cab
O16 - DPF: {C4847596-972C-11D0-9567-00A0C9273C2A} (Crystal Report Viewer Control) -
https://ivantage.thermo.com/ivantagetec/Rep…veXViewer80.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} -
C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} -
C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program
Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation
- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -
C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro
Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Protection Against Spyware (PcScnSrv) - Trend Micro
Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcScnSrv.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation
- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. -
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe





Find AWF report by noahdfear ©2006
Version 1.40

The current date is: Fri 11/09/2007
The current time is: 14:17:56.46


bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\MSNMES~1\BAK

0 File(s) 0 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~



end of report
Looks good, AWF got the 015's this time and no more bak folders so that infection is gone. I would advise we do some scans and get some reports to see if anything else is awry.

Download the trial version of AVG Anti-Spyware from here and install it. When the program has been installed, and you click the Finish button, AVG Anti-Spyware will open.

If the program does not automatically update itself during installation, or you are unsure whether it has done so, please do the following:
  • Click the Update icon at the top and under Manual Update click the Start update button.
  • The program will either update or inform you that no update was available.
  • It is essential that you get the update - keep trying until successful. (Note: If you have problems getting the update, you can download an installer for the full database from here (save it on your desktop). Once you have downloaded the installer, make sure that AVG Anti-Spyware is closed and then double-click on avgas-signatures-full-current.exe to install the database).
Please set up the program as follows:
  • Click the Shield icon at the top and under Resident shield is… click active. This should now
    change to inactive.
  • Click the Update icon and untick the automatic update option.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
  • Under How to act? - make sure that Quarantine is selected.
  • Under How to scan? - All checkboxes should be ticked.
  • Under Possibly unwanted software - All checkboxes should be ticked.
  • Under Reports - Select Do not automatically generate reports.
  • Under What to scan? - Select Scan every file.
Close all open windows.



Please download ATF Cleaner here by Atribune. This program is for XP and Windows 2000 only.
It does not require any installation and uses minimal system resources. It is set up to clean IE, FireFox and Opera, and detects the browsers you have and grays out the other(s).
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Recommend UNCHECKING COOKIES if you rely on system remembered passwords.
  • Click the Empty Selected button.

    If you use Firefox browser
  • Click Firefox at the top and choose: Select All EXCEPT FIREFOX SAVED PASSWORDS
  • Click the Empty Selected button.
    NOTE: If you would like to keep your saved passwords, please click No at the prompt.

    If you use Opera browser
  • Click Opera at the top and choose: Select All EXCEPT COOKIES AND SAVED PASSWORDS
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your cookies and saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.


We Now Need To Boot Into Safemode Now

Restart your computer.
When the machine first starts again it will generally list some equipment that is installed in your machine,
amount of memory, hard drives installed etc (BOOT SCREEEN).
At this point you should gently tap the F8 key repeatedly until you are presented with a Options menu.
Select the option for Safe Mode using the arrow keys.
Then press enter on your keyboard to boot into Safe Mode.


Run AVG

  • Click on Scanner on the toolbar.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan your computer.
  • When the scan has finished, follow the instructions below:
    • Make sure that Set all elements to: shows Quarantine
    • Important: Click on the Apply all Actions button This must done before saving the report
    • When the program has finished, it will display the message All actions have been applied.
    • Then click the Save Scan Report button.
    • Click the Save Report as button.
    • Save the report to your Desktop.
      [external image: Posted Image]
  • Right-click the AVG Tray Icon and select Exit.
  • Now copy the report back to this topic.

Restart into normal mode and post the AVG Log.

——————————————————————————————–

Using Internet Explorer, click on Kaspersky Online Scanner * Click 'Accept' in the window that pops up.
* You will be prompted to install an ActiveX component from Kaspersky, Click on the information bar and select Install ActiveX Control if so. This may happen more than once. That is OK. You also may get a warning from your Windows Firewall. You can tell it to unblock.
* The program will launch and then start to download the latest definition files.
* Once the scanner is installed and the definitions downloaded, click 'Next'.
* Now click on 'Scan Settings'
* In the scan settings make sure that the following are selected:
o Scan using the following Anti-Virus database: 'Extended' (If available, otherwise 'Standard')
o Scan Options: 'Scan Archives' and 'Scan Mail Bases'
* Click 'OK'
* Now under 'Select a target to scan' select 'My Computer'
* The scan will take a while, so be patient and let it run. Once the scan is complete, it will display whether your system has been infected.
* Now click on the 'Save Report As…' button:
* Make sure it says Save as a text file - change it if not
* Save the file to your desktop.
Please post the Kaspersky report and a new HijackThis log.

NOTE: You may need to make several posts so the logs don't get cut off it they are long. If they're short you should be able to do it in one shot.
OK, I did everything you recommended. I will post the AVG, Kasperky, and HJT logs in separate posts. As a side note, what settings should have on Trend Micro? Here's the AVG: ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 7:21:49 PM 11/9/2007 + Scan result: :mozilla.100:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.101:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.102:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.103:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.104:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.105:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.106:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.107:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.108:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.158:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.307:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.310:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.347:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.99:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.175:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.176:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.177:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.165:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.42:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.43:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.44:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.370:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.371:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.75:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.77:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.78:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.79:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.59:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned. :mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.181:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.182:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.183:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.144:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.145:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.146:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.147:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.148:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.149:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.84:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Information : Cleaned. :mozilla.119:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.120:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.121:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.372:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.298:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.187:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.188:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.189:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.190:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.192:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.193:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.194:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.195:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.196:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.305:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.306:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.311:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.312:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.73:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.109:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.111:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.112:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.113:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.162:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Revsci : Cleaned. :mozilla.218:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.317:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.318:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.319:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.320:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.163:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.166:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.167:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.170:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.363:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.330:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.331:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.332:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.333:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.334:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.335:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.336:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.337:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.338:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned. :mozilla.340:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.23:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.24:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.25:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.26:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\8w316dsj.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. ::Report end

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI