Unsolved

This post is more than 5 years old

4 Posts

730

July 5th, 2008 22:00

HijackThis Log HELP!!!

yesterday i received a message when i was going through my music folder in my documents and the it said dr waston something and that i needed to download anti-virus software, then it directed me to the internet where it started downloading this "software" using a fake microsoft page.  I closed out before it finished but now everytime i go into my documents folder this happens as well as shortly after i close all the pop ups my start menu freezes and i need to re-boot.  This is my hijackthis log Please Help!!!!

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:16:45 PM, on 7/5/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Maxtor\Utils\SyncServices.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AVG Safe Search - {1C1B8A44-61FE-411E-8F33-813A4E2E2984} - C:\WINDOWS\system32\ant_ss.dll
O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\WINDOWS\Trntfiltr.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1197171017343
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: MaxSyncService (NTService1) -   - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9954 bytes
 

10.4K Posts

July 7th, 2008 13:00

yezwez2087

1. Please download the Killbox.
  • 1)Save it to the desktop
    2) Rt Click->>Extract all->.Extract it to your Desktop
    3) Double Click Killbox.exe to run it
    4)Select " Delete on Reboot", and then select "All files".
    5) Copy the file names below to the clipboard by highlighting them and pressing Control-C:


    C:\WINDOWS\Trntfiltr.dll

    6) Return to Killbox, go to the File menu, and choose " Paste from Clipboard".
    7) Click the red-and-white " Delete File" button.  Click " Yes" at the Delete on Reboot prompt.










2. Rerun Hijackthis (scan only) and place checks beside the following entries
  • O2 - BHO: AVG Safe Search - {1C1B8A44-61FE-411E-8F33-813A4E2E2984} - C:\WINDOWS\system32\ant_ss.dll
    O2 - BHO: CDNSCacheObj Object - {376892AE-1825-4E5F-9F85-23F9640051CC} - C:\WINDOWS\Trntfiltr.dll
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)



Close all other open windows except Hijackthis and Select " Fix checked"

Close Hijackthis ->> Reboot your PC ->> Rerun Hijackthis and post a fresh Hijackthis log













Microsoft MVP Consumer-Security

 


"The world is what you make of it"




4 Posts

July 7th, 2008 15:00

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:03 PM, on 7/7/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\McAfee\Common Framework\UdaterUI.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
C:\Program Files\Logitech\QuickCam10\QuickCam10.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
C:\Program Files\Common Files\LogiShrd\LComMgr\LVComSX.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
C:\Program Files\Maxtor\Utils\SyncServices.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\Program Files\Maxtor\ManagerApp\Onetouch.exe
O4 - HKLM\..\Run: [mxomssmenu] "C:\Program Files\Maxtor\OneTouch Status\maxmenumgr.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files\Logitech\QuickCam10\QuickCam10.exe" /hide
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1197171017343
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - c:\program files\common files\logishrd\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
O23 - Service: MaxBackServiceInt - Unknown owner - C:\Program Files\Maxtor\Maxtor Backup\MaxBackServiceInt.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exe
O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exe
O23 - Service: MaxSyncService (NTService1) -   - C:\Program Files\Maxtor\Utils\SyncServices.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 8861 bytes

10.4K Posts

July 7th, 2008 20:00

yezwez2087

Looking better. How's your PC running now?

Please perform an Ewido Online Malware Scan


  • When a dialog box appears asking you if you would like to download and install the ewido anti-spyware online scanner please click Yes to allow the download.
  • Click on Start Scan.
  • after the scan completes it will produce a log for you, copy and paste the results of that scan as a reply to this thread
  • If any infections are found, (After you save the logfile), Click on Remove Infections.








Microsoft MVP Consumer-Security

 


"The world is what you make of it"




4 Posts

July 8th, 2008 17:00

Yes, my computer is working much better, no pop up errors in my documents anymore, thank you very much.  Here is the ewido log...

 

__________________________________________________
ewido anti-spyware online scanner
    http://www.ewido.net
__________________________________________________


Name: TrackingCookie.Yieldmanager
Path: :mozilla.24:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: :mozilla.25:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: :mozilla.26:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Yieldmanager
Path: :mozilla.27:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.53:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.54:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.55:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.56:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.57:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.59:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Euroclick
Path: :mozilla.63:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Euroclick
Path: :mozilla.65:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.66:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.67:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.68:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.69:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.70:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Zedo
Path: :mozilla.71:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.72:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.73:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.74:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.75:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.76:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.77:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.78:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.79:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.80:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.81:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.82:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.83:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.84:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.85:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Ru4
Path: :mozilla.90:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.91:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.92:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.93:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.94:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.95:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Revsci
Path: :mozilla.96:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: :mozilla.97:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: :mozilla.98:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tribalfusion
Path: :mozilla.99:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Pointroll
Path: :mozilla.141:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Pointroll
Path: :mozilla.142:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Burstnet
Path: :mozilla.144:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Burstnet
Path: :mozilla.147:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Burstnet
Path: :mozilla.148:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.164:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.165:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.166:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.167:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.168:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.169:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Statcounter
Path: :mozilla.170:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Imrworldwide
Path: :mozilla.188:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Imrworldwide
Path: :mozilla.189:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Esomniture
Path: :mozilla.199:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Liveperson
Path: :mozilla.218:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Liveperson
Path: :mozilla.219:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Addynamix
Path: :mozilla.251:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: :mozilla.256:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: :mozilla.258:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Mediaplex
Path: :mozilla.259:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: :mozilla.269:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: :mozilla.270:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adbrite
Path: :mozilla.271:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Realmedia
Path: :mozilla.273:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Realmedia
Path: :mozilla.274:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Realmedia
Path: :mozilla.275:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Realmedia
Path: :mozilla.276:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Realmedia
Path: :mozilla.277:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Yadro
Path: :mozilla.301:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Serving-sys
Path: :mozilla.319:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.320:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.321:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Hitbox
Path: :mozilla.322:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adjuggler
Path: :mozilla.336:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adjuggler
Path: :mozilla.337:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.338:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Overture
Path: :mozilla.356:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.359:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.360:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Casalemedia
Path: :mozilla.361:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.369:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adrevolver
Path: :mozilla.370:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.247realmedia
Path: :mozilla.415:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.454:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Webtrendslive
Path: :mozilla.457:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Tradedoubler
Path: :mozilla.458:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Trafficmp
Path: :mozilla.460:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.464:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Esomniture
Path: :mozilla.467:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Esomniture
Path: :mozilla.468:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Esomniture
Path: :mozilla.474:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Valuead
Path: :mozilla.475:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Valuead
Path: :mozilla.476:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Valuead
Path: :mozilla.477:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adjuggler
Path: :mozilla.479:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Adjuggler
Path: :mozilla.480:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.2o7
Path: :mozilla.496:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium

Name: TrackingCookie.Burstbeacon
Path: :mozilla.501:C:\Documents and Settings\Wes\Application Data\Mozilla\Firefox\Profiles\1g71yf48.default\cookies.txt
Risk: Medium
 

10.4K Posts

July 9th, 2008 12:00

yezwez2087

Good work

1. Rerun Killbox
  • At the main window Select Tools ->> Delete Temp Files
    At the next window uncheck XP Prefetch
    Leave the other boxes checked
    Select " Delete Selected Temp Files"
    Allow the tool to run. When it is finished (You will know that it is finished because the checks will disappear from the location boxes)
    Select " Exit"
    Then Select " Exit" again to close Killbox






You may now remove/delete/uninstall the tools we used to clean your PC

Now that your log is clean

There are some final notes:
Disable and Enable System Restore
  • Lets create a clean System Restore point
    the instructions are here

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version Java components and update.

Updating Java:
  • Download the latest version of
    Java Runtime Environment (JRE) 6.u6.
    Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
    Click the " Download" button to the right.
    Check the box that says: " Accept License Agreement".
    The page will refresh.
    Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
    Close any programs you may have running - especially your web browser.
    Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
    Check any item with Java Runtime Environment (JRE or J2SE) in the name.
    Click the Remove or Change/Remove button.
    Repeat as many times as necessary to remove each Java versions.
    Reboot your computer once all Java components are removed.
    Then from your desktop double-click on jre-6u6-windowsi586-p.exe to install the newest version.













Update your Anti Virus Software

Use and maintain a Firewall

Visit Microsoft's Windows Update Site Frequently for critical updates

Backup your Important Documents and Files on a regular basis
  • To a disc or a USB key, not your Hardrive

You may want to read this article" So how did I get infected in the first place" by Tony Klein

surf safe































Microsoft MVP Consumer-Security

 


"The world is what you make of it"




4 Posts

July 11th, 2008 20:00

thank you agian very much, my computer runs good as new with no problems... THANKS!!!!
No Events found!

Top