Unsolved

This post is more than 5 years old

10 Posts

847

May 17th, 2006 16:00

desktop taken over

I have run scans with Ad-aware, Grisoft AVG, CCleaner, MS Windows Malicious Software Removal Tool, and now Hijack This. Here is the log from Hijack This.

Logfile of HijackThis v1.99.1
Scan saved at 11:56:21 AM, on 5/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Iomega HotBurn\Autolaunch.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTP04967 - {2587B037-ABF4-44b9-925D-3D797B26E5AB} - C:\PROGRA~1\GAMEFI~1\Toolbar\tbu02630\GF-TOO~1.DLL
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [GDIPatch] C:\PROGRA~1\WMFPatch\inject.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [e756dbb5.exe] C:\Documents and Settings\me\Local Settings\Application Data\e756dbb5.exe
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxuk10087US
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

I don't know in what ways my computer may still be infected, but I still have a huge, annoying message on the desktop about spyware.

Thank you for helping!

3.3K Posts

May 19th, 2006 17:00

First, uninstall the My Web Search using Add/Remove Programs

1) Click on Start, Settings, Control Panel

2) Double click on Add/Remove Programs

3) Find "My Web Search" in the list of installed programs and click on Change/Remove to uninstall it. You may also want to uninstall any of the following items associated with FunWebProducts.

* My Web Search (Smiley Central or FWP product as applicable)
* My Way Speedbar (Smiley Central or other FWP as applicable)
* My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
* My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
* Search Assistant - My Way

4) Reboot your Computer.

Please download:
SmitfraudFix (by S!Ri)
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press" Enter"; a text file will appear, which lists infected files (if present). Please copy/paste the content of that report into your next reply.

Note :
process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

10 Posts

May 22nd, 2006 13:00

Thank you so much for helping. I ran that, and this is what I got:

SmitFraudFix v2.45

Scan done at 9:11:09.90, Mon 05/22/2006
Run from C:\Documents and Settings\me\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\me\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\me\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="C:\\WINDOWS\\warnhp.html"
"SubscribedURL"=""
"FriendlyName"="Desktop Uninstall"

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End

3.3K Posts

May 22nd, 2006 13:00

You should print out these instructions, or copy them to a NotePad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.

Next, reboot the computer into Safemode.

Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press" Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into your Normal Windows user mode.
A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : running option #2 on a non infected computer will remove your Desktop background.

Also post a fresh hijackthis log

10 Posts

May 22nd, 2006 14:00

Hi,

This is the rapport text file:

SmitFraudFix v2.45

Scan done at 10:04:42.53, Mon 05/22/2006
Run from C:\Documents and Settings\me\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600]

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» End






This is the new hijackthis log:

Logfile of HijackThis v1.99.1
Scan saved at 10:19:09 AM, on 5/22/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Iomega HotBurn\Autolaunch.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\Lexmark 2200 Series\lxbvbmon.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\cidaemon.exe
C:\I386\NOTEPAD.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: XBTP04967 - {2587B037-ABF4-44b9-925D-3D797B26E5AB} - C:\PROGRA~1\GAMEFI~1\Toolbar\tbu02630\GF-TOO~1.DLL
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [GDIPatch] C:\PROGRA~1\WMFPatch\inject.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxuk10087US
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe






This is my desktop properties:






style="BACKGROUND: url(file:///C:/Documents%20and%20Settings/me/Local%20Settings/Application%20Data/Microsoft/Wallpaper1.bmp) no-repeat 50% 50%; LEFT: 0px; WIDTH: 1024px; POSITION: absolute; TOP: 0px; HEIGHT: 768px">

id=0
style="Z-INDEX: 1000; BACKGROUND: none transparent scroll repeat 0% 0%; LEFT: 0px; WIDTH: 1024px; POSITION: absolute; TOP: 0px; HEIGHT: 740px"
name=DeskMovrW marginWidth=0 marginHeight=0 src="file:///C:/WINDOWS/warnhp.html"
frameBorder=0 subscribed_url="" resizeable="ﰟ粶ʠ ಞ">

style="LEFT: 0px; VISIBILITY: hidden; WIDTH: 0px; POSITION: absolute; TOP: 0px; HEIGHT: 0px; container: positioned; zIndex: 5"
classid=clsid:72267F6A-A6F9-11D0-BC94-00C04FB67863>

style="Z-INDEX: 999; LEFT: 0px; VISIBILITY: hidden; WIDTH: 1px; POSITION: absolute; TOP: 0px; HEIGHT: 740px; container: positioned"
classid=clsid:72267F6A-A6F9-11D0-BC94-00C04FB67863>

3.3K Posts

May 23rd, 2006 04:00

Please select and install one of these free Firewall applications:
ZoneAlarm Free Version
Outpost Free
Kerio

When the installation completes successfully, reboot the computer.

Please download Ewido Security suite.

After download, double click on the file to launch the install process.
During installation, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".

Launch ewido by double-clicking the "e" icon on your desktop.
The program will prompt you to update - click the "OK" button.
On the left side of the main screen, click on "Update" and then click "Start Update". The update will start and a progress bar will show the updates being installed.

After the updates are installed, you will see "Update Successful" in the lower left corner.

Once the updates are installed do the following:
Click on "Scanner" and choose "Settings".
Under the bottom section "What to Scan?" make sure "Scan every file" is selected.
Select "OK" and you will return to scanning options.

Boot the computer into safe mode.
Once in safe mode, continue with the instructions below:

On the main screen click on "Complete System Scan" to start the scan.
While the scan is in progress, you will be prompted to clean the first infected file it finds. Put a check next to "Perform action on all infections" in the lower left corner.
Then choose "Clean" and click "OK".

When the scan has completed, Ewido will create a report.txt file.
Click the "Save Report" button on the bottom of the screen and save the log to your desktop.
Exit Ewido when done. Run HijackThis again and put a check in the box next to these entries that may still exist:

R3 - Default URLSearchHook is missing
O2 - BHO: XBTP04967 - {2587B037-ABF4-44b9-925D-3D797B26E5AB} - C:\PROGRA~1\GAMEFI~1\Toolbar\tbu02630\GF-TOO~1.DLL
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: %systemroot%\system32\dumprep 0 -k
The item below is an administrative lock down that may have been set by Spybot Search and Destroy. If you are not using Spybot's option to Lock the control panel, then put a check in the box next to this entry too:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxuk10087US
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -


Using Windows Explorer locate and delete the following folder indicated in Bold text if still present:
C:\Program Files\ MyWebSearch

Reboot the computer into your normal user mode.

Perform an onlinescan here.

- Once you are at the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click "send"
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
- When download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location (Your Desktop is fine).

Reboot the computer and post back a new HijackThis log along with the logs from the Ewido and Panda scans. Thanks!

10 Posts

May 23rd, 2006 17:00

Next part:

:mozilla.103:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.106:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.107:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.109:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.110:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.112:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.113:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.114:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.115:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.130:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.131:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.132:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.133:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.134:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.137:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.148:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.151:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.153:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.154:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.155:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.156:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.157:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.171:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.172:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.174:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.175:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.176:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.177:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.180:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.181:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.182:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.183:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.187:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.188:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.189:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.190:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.191:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.192:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.193:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.210:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.211:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.212:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.213:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.214:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.215:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.216:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.217:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.229:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.230:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.231:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.232:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.233:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.234:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.235:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.241:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.242:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.243:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.244:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.249:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.250:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.251:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.254:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.257:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.266:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.269:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.270:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.276:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.277:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.278:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.279:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.280:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.284:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.285:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.305:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.310:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.324:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.328:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.360:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.361:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.362:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.363:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.364:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.396:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.397:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.398:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.399:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.402:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.409:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.410:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.421:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.422:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.424:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.447:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.457:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.480:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned with backup
:mozilla.481:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Kmpads : Cleaned with backup
:mozilla.524:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.525:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.526:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.527:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.531:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.532:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.548:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.550:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup

10 Posts

May 23rd, 2006 17:00

Hi again; thanks so much for helping me.

Here's the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 1:20:19 PM, on 5/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\PROGRA~1\Iomega\System32\AppServices.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Works\MSWorks.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Drag'n'Drop_Autolaunch] "C:\Program Files\Iomega HotBurn\Autolaunch.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [Ulead AutoDetector] C:\Program Files\Ulead Systems\Ulead Photo Explorer 8.0 SE Basic\Monitor.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [Lexmark 2200 Series] "C:\Program Files\Lexmark 2200 Series\lxbvbmgr.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Lexmark Fax Solutions\fm3032.exe" /s
O4 - HKLM\..\Run: [GDIPatch] C:\PROGRA~1\WMFPatch\inject.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: Yahoo! Widget Engine.lnk = C:\Program Files\Yahoo!\WidgetEngine\YahooWidgetEngine.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Ulead Photo Express 4.0 SE Calendar Checker .lnk = C:\Program Files\Ulead Systems\Ulead Photo Express 4.0 SE\CalCheck.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: Iomega App Services - Iomega Corporation - C:\PROGRA~1\Iomega\System32\AppServices.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe

10 Posts

May 23rd, 2006 17:00

Here's the Panda report


Incident Status Location

Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@apmebf[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@realmedia[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[.atwola.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[.go.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt[hc2.humanclick.com/hc/38933572]
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\me\Application Data\Mozilla\Profiles\default\r36610k3.slt\cookies.txt[.ct.360i.com/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\me\Desktop\SmitfraudFix\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\me\Desktop\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\me\Local Settings\Temp\SmitfraudFix.zip[SmitfraudFix/Process.exe]
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll
Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\WINDOWS\SYSTEM32\f3PSSavr.scr
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\WINDOWS\SYSTEM32\P2P Networking v124.cpl

10 Posts

May 23rd, 2006 17:00

The Ewido log is very long and doesn't fit here. I will try to post it in chunks.

Part 1:

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 11:36:49 AM, 5/23/2006
+ Report-Checksum: F809938B

+ Scan result:

HKLM\SOFTWARE\Classes\AppID\adm.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\Altnet Signing Module.EXE -> Adware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2587B037-ABF4-44b9-925D-3D797B26E5AB} -> Adware.MaxSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{2587B037-ABF4-44b9-925D-3D797B26E5AB} -> Adware.MaxSearch : Cleaned with backup
HKLM\SOFTWARE\PerfectNav -> Adware.KeenValue : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@bfast[1].txt -> TrackingCookie.Bfast : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@ehg-lexmark.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@overture[2].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\me\Application Data\Earthlink\6.0\coleman@rconnect.com\Cookies\me@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup

10 Posts

May 23rd, 2006 17:00

Part 3:

:mozilla.256:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.257:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.264:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.265:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.292:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.299:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.324:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.327:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.356:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.357:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.358:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.359:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.362:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned with backup
:mozilla.366:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.367:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.370:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.377:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.381:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.382:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.383:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.384:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.385:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.386:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.401:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.402:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.411:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.412:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Onestat : Cleaned with backup
:mozilla.432:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.433:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.442:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.443:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.446:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.454:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.485:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.486:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Commission-junction : Cleaned with backup
:mozilla.17:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.20:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.35:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.36:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.37:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.38:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.55:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.71:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.72:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.73:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.78:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.79:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.80:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.81:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.82:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.92:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.97:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.99:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\tbrjjzl9.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup

10 Posts

May 23rd, 2006 17:00

C:\Documents and Settings\me\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\PopupBlocker -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\PopupBlocker\PopupBlockerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SmileyTown\SmileyTownOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\SmileyTown\SmileyTownOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Weather\AlertArchive.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\me\Local Settings\Temp\__unin__.exe -> Adware.Altnet : Cleaned with backup
C:\Program Files\GameFiesta\Toolbar\gf-toolbar.dll -> Adware.Eztracks : Cleaned with backup
C:\Program Files\GameFiesta\Toolbar\tbu02630\gf-toolbar.dll -> Adware.Eztracks : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll -> Adware.PeerNet : Cleaned with backup


::Report End

Message Edited by editorlady on 05-23-200601:41 PM

10 Posts

May 23rd, 2006 17:00

Part 2:

:mozilla.9:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.15:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.16:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.17:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.18:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.19:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.25:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.27:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.28:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.30:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.31:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.32:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.33:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.34:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.35:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.36:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.38:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.39:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.40:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.41:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.42:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.49:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.50:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.51:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.52:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.53:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.54:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.55:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.57:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.64:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.66:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.67:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.70:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.71:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.84:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.90:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.91:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.99:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.100:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.101:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.102:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.107:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.113:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.114:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.115:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.116:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.117:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.118:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.119:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.120:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.121:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.122:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.124:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.128:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.129:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.130:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.131:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.137:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Gator : Cleaned with backup
:mozilla.140:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.143:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.144:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.147:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.155:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.156:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.157:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.158:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.171:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.172:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.191:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.192:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.193:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.194:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.195:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.196:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.197:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.198:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.199:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.201:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.208:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.209:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.214:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Adviva : Cleaned with backup
:mozilla.215:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.221:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.231:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.236:C:\Documents and Settings\me\Application Data\Mozilla\Firefox\Profiles\3ndrno0q.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.240:C:\Documents and Settings\me\Application

3.3K Posts

May 24th, 2006 02:00

Uninstall MyWebSearch using the Add/Remove Programs utility:

1) Click on Start, Settings, Control Panel

2) Double click on Add/Remove Programs

3) Find "MyWebSearch" in the list of installed programs and click on Change/Remove to uninstall it. You may also want to uninstall any of the following items associated with FunWebProducts.

* My Web Search (Smiley Central or FWP product as applicable)
* My Way Speedbar (Smiley Central or other FWP as applicable)
* My Way Speedbar (AOL and Yahoo Messengers) (beta users only)
* My Way Speedbar (Outlook, Outlook Express, and IncrediMail)
* Search Assistant - My Way

4) Reboot your Computer.

Download KILLBOX, extract it to your desktop.

Open killbox.exe.

First click on Tools>Delete Temp Files.
A box will open with a list of all user profiles.

Check the following boxes at a minimum for each profile by clicking on the drop down and checking the boxes that are enabled. Some will not apply and those boxes will not be available to check. Make sure you do this for all the profiles listed.

Temporary Internet Files
Temp Files
XP Prefetch

If you want to clean your cookies, history, and list of recent files run you may check those boxes as well.

Then, click on the Button titled "Delete Selected Temp Files".
Exit by clicking the Button titled "Exit(Save Settings)".

Once back into the main killbox program, check the box:

Delete on Reboot

Highlight all the entries in the quote box below and then Copy them.
Quote:
C:\WINDOWS\SYSTEM32\P2P Networking v124.cpl
C:\WINDOWS\SYSTEM32\f3PSSavr.scr
C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf
C:\Program Files\MSN Messenger\riched20.dll

Then in killbox click File>>Paste from Clipboard

At this point the "All Files" button should be enabled so you can click it.
Click the "All Files" button.

Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes.

A second message will ask to Reboot now? you will need to click No for now.
Note: Killbox will let you know if a file does not exist.

If you have any issues with this method you can copy and paste the lines one at a time into the killbox top box. Then click the "Single File" button. Then click the Red X ...and for the confirmation message that will appear, you will need to click Yes. A second message will ask to Reboot now? you will need to click No until you've completed the instructions below.

Please run HijackThis again and put a check in the box next to these entries:

O4 - HKLM\..\Run: %systemroot%\system32\dumprep 0 -k
***Note***this item below may have been set by your Spybot Search and Destroy. It is an administrative lock down. If you know with certainty that you do not use the Contol panel Lock down feature in Spybot Search and Destroy, then put a check next to this one too:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present


Close all windows except for HijackThis. Now click Fix Checked.

Using Windows Explorer locate and delete the following folders indicated in Bold text:
C:\Program Files\ MyWebSearch
C:\Program Files\ FunWebProducts

Reboot and post back a new HijackThis log. Also, please advise how the computer is now behaving and if you are still having any issues.
Thanks!
No Events found!

Top