Computing.Net > Forums > Security and Virus > System Alert Popup (PLEASE HELP)

System Alert Popup (PLEASE HELP)

Reply to Message Icon

Original Message
Name: Kenson
Date: March 17, 2007 at 14:29:16 Pacific
Subject: System Alert Popup (PLEASE HELP)
OS: Windows XP Pro
CPU/Ram: Dual Processor/ 1Gig Ram
Model/Manufacturer: Dell Precision 360
Comment:

Alas yet another system alert victim :)

This one is trying to promote some rogue "anti" spyware program called "SpyDawn". So far I've used Norton Antivirus, Ad-Aware and Spybot to remove a handful of SpyDawn files yet the little blinking question mark still remains at the bottom right of my system tray..

Any help with this would be much appreciated. Thanks in advance!


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: March 17, 2007 at 14:53:16 Pacific
Reply: (edit)

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified.

Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop.
By default it will install to C:\Program Files\Hijack This.
Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.
Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.
Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

Please copy/paste the content of that report into your next reply.
Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.

Please download SmitFraudFix from this link http://siri.urz.free.fr/Fix/Smitfra... Then extract the contents to your desktop.

!!!! Only run option #1 as runing the other options on an uninfected computer will damage the desktop.!!!!


Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).


Report Offensive Follow Up For Removal

Response Number 2
Name: Kenson
Date: March 17, 2007 at 16:34:08 Pacific
Reply: (edit)

Hi, jabuck

Thank you so much for your help. I appreciate your time on this.

Here is my Hijack Log:


Logfile of HijackThis v1.99.1
Scan saved at 4:07:04 PM, on 3/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\fryhser.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\DOCUME~1\Daniel\LOCALS~1\Temp\winlogon.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/cus...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie...
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {A6ACAE64-F798-4930-AD86-BD3FB32038DB} - C:\Program Files\Video Access ActiveX Object\isadd.dll (file missing)
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [frymxins] frymxins
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINDOWS\System32\win32bootcfg.exe
O4 - HKLM\..\Run: [msconfig38] mssvcc.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [secures23] mssecure.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe
O4 - HKLM\..\RunServices: [secures23] mssecure.exe
O4 - HKLM\..\RunServices: [Compaq32 Service Drivers] msconfig32.exe
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Daniel\LOCALS~1\Temp\winlogon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?lin...
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/download...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{60F16BAA-5FF3-498B-9F38-CD56E189E4B8}: NameServer = 68.94.156.1,68.94.157.1
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: FGLRYUTIL (FGLRYUtil) - ATI Technologies, Inc. - C:\WINDOWS\System32\fryhser.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: mnew4win - Unknown owner - C:\WINDOWS\system32\mnew4win.exe (file missing)
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pdfr10utu - Unknown owner - (no file)
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:\WINDOWS\system32\Tablet.exe
O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - C:\WINDOWS\win32host.exe (file missing)


--SmitfraudFix list coming soon!!


Report Offensive Follow Up For Removal

Response Number 3
Name: jabuck
Date: March 17, 2007 at 17:01:54 Pacific
Reply: (edit)

Nortons scrptblocking must be turned of to run smitfruadfix.

Turn off Norton's ScriptBlocking:

To disable Norton AntiVirus Script Blocking:


Start Norton AntiVirus.
If Norton AntiVirus is installed as part of Norton SystemWorks or Norton Internet Security, then start that program.
Click Options.
If you see a menu, click Norton AntiVirus.
In the left pane, click Script Blocking.
In the right pane, uncheck Enable Script Blocking (recommended).
Click OK.


Report Offensive Follow Up For Removal

Response Number 4
Name: Kenson
Date: March 17, 2007 at 17:12:30 Pacific
Reply: (edit)


Here's the SmitFraudFix list:


SmitFraudFix v2.148

Scan done at 17:06:15.96, Sat 03/17/2007
Run from C:\Documents and Settings\Daniel\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» hosts


»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32

C:\WINDOWS\system32\geplxss.dll FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Daniel


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Daniel\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Daniel\FAVORI~1

C:\DOCUME~1\Daniel\FAVORI~1\Online Security Test.url FOUND !

»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"

»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{aed6f6a3-183c-488d-9f90-23db99f56e7f}"="apathies"

[HKEY_CLASSES_ROOT\CLSID\{aed6f6a3-183c-488d-9f90-23db99f56e7f}\InProcServer32]
@="C:\WINDOWS\system32\geplxss.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{aed6f6a3-183c-488d-9f90-23db99f56e7f}\InProcServer32]
@="C:\WINDOWS\system32\geplxss.dll"

»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32


»»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End


There you have it. Thanks for your patience


Report Offensive Follow Up For Removal

Response Number 5
Name: Kenson
Date: March 17, 2007 at 17:29:50 Pacific
Reply: (edit)

One more thing, is it alright if I turn my Norton AntiVirus scriptblocking and other real time monitoring programs back on now or should I wait until the system alert problem is fixed? Thanks


Report Offensive Follow Up For Removal


Response Number 6
Name: jabuck
Date: March 17, 2007 at 17:49:58 Pacific
Reply: (edit)

You have more problems than just the alert popups so there is a lot to do.

Make sure Norton's script blocking is turned off.

Next, please reboot your computer in Safe Mode by doing the following :

Restart your computer

After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;

Instead of Windows loading as normal, a menu with options should appear;

Select the first option, to run Windows in Safe Mode, then press "Enter".

Choose your usual account.

Once in Safe Mode, open the "SmitfraudFix" folder again and double-click "smitfraudfix.cmd"
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing " Y " and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if "wininet.dll " is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing "Y" and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart it into Normal Windows.

A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Go to start> control panel> administrative tools> services> scroll down to mnew4win and double click it> click stop> click the drop down arrow on the far right of "startup type"> click disable> apply> ok.

Do to same for these:

Pdfr10utu

Win32 Kernel Update

Please download ATF-Cleaner to your desktop from this link
http://www.atribune.org/content/view/19/2/ We will need it later in safe mode

Download and install AVG Anti-Spyware We will need this later in safe mode

Be sure to update AVG Anti- Spyware

Download Killbox to your desktop from this link Killbox by Option^Explicit. If you already have "Killbox" update to this newer version. We will need it later in safe mode

Next reboot into safe mode again.

Run Hijack This from safe mode, close all windows except Hijack This, place a check to the left of the following items and press "fix checked":

O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINDOWS\System32\win32bootcfg.exe

O4 - HKLM\..\Run: [msconfig38] mssvcc.exe

O4 - HKLM\..\Run: [secures23] mssecure.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u

O4 - HKLM\..\RunServices: [msconfig38] mssvcc.exe

O4 - HKLM\..\RunServices: [secures23] mssecure.exe

O4 - HKLM\..\RunServices: [Compaq32 Service Drivers] msconfig32.exe

O4 - HKCU\..\Run: [Firewall auto setup] C:\DOCUME~1\Daniel\LOCALS~1\Temp\winlogon.exe

O23 - Service: mnew4win - Unknown owner - C:\WINDOWS\system32\mnew4win.exe (file missing)

O23 - Service: Pdfr10utu - Unknown owner - (no file)

O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - C:\WINDOWS\win32host.exe (file missing)

Exit Hijack this but remain in safe mode.

Run Killbox from safe mode. Please double-click Killbox.exe to run it.
Select:
Delete on Reboot
then Click on the All Files button.
Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy):

C:\Documents and Settings\Daniel\Local Settings\Temp\winlogon.exe

C:\WINDOWS\System32\win32bootcfg.exe

C:\WINDOWS\System32\mssvcc.exe

C:\WINDOWS\System32\mssecure.exe

C:\WINDOWS\System32\msconfig32.exe

C:\WINDOWS\system32\mnew4win.exe

C:\WINDOWS\win32host.exe

Return to Killbox, go to the File menu, and choose Paste from Clipboard.


Click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click OK at any PendingFileRenameOperations prompt (and please let us know if you receive this message!).

If your computer does not restart automatically, please restart it manually then reboot into safe mode.

Run ATF-Cleaner from safe mode.Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Empty the restore folder. Go to start>control panel>system>system restore tab>check the box beside "turn off system restore>apply (takes a minute)>ok. Go back and uncheck the box to turn system restore back on>apply>ok.

In Safe Mode, run AVG Anti-spyware and click on the Scanner tab at the top. Click the "Settings" tab and then change the recommended action to Quarantine and click Automatically generate report after every scan. Click back to the "Scan" tab and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.

AVG Anti-Spyware will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG Anti-Spyware will display "All actions have been applied" on the right hand side.

Click on "Save Report", then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).

Post the AVG-AntiSpyware report.

Please download Comboscan from this link:

Comboscan


Close all applications and windows.
Double-click on comboscan.exe to run it, and follow the prompts.
When the scan is complete, a text file will open - ComboScan.txt
Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of ComboScan.txt in your next post.
A folder, C:\ComboScan, will also open. In it will be another text file, Supplementary.txt.
Please attach Supplementary.txt to your post.

Note: some firewalls may warn that sigcheck.exe is trying to access the internet - please ensure that you allow sigcheck.exe permission to do so.


Report Offensive Follow Up For Removal

Response Number 7
Name: Kenson
Date: March 17, 2007 at 19:15:17 Pacific
Reply: (edit)

A few things happened when I tried running the smitfraudfix cleanup. They may be insignificant, but I just thought you should know.

When I got the prompt: "Registry cleaning - Do you want to clean the registry?", a grey window popped up for "Disk Cleanup" and it said it was checking to see how much "space" could be gained from the cleanup or something like that. It had a progress bar showing how far along it was. I figured it wasn't related to smitfraudfix so I canceled the Disk Cleanup box, clicked back on the smitfraud window and continued on to say yes to the Registry cleaning. I was in Safe Mode when this happened and I hadn't started any other programs beside SmitFraud.

Secondly it never gave me the prompt to replace the infected "wininet.dll" file though I'm pretty sure I saw that one at the bottom of one of the previous logs I posted.

It didn't prompt me to restart the computer, but it did bring up the log in notepad. I restarted the computer and am now back in Normal Mode. I noticed the desktop background I had is now replaced with solid blue. Is all of this normal?

Anyway here is my latest SmitFraudFix log:

SmitFraudFix v2.148

Scan done at 18:43:20.65, Sat 03/17/2007
Run from C:\Documents and Settings\Daniel\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{aed6f6a3-183c-488d-9f90-23db99f56e7f}"="apathies"

[HKEY_CLASSES_ROOT\CLSID\{aed6f6a3-183c-488d-9f90-23db99f56e7f}\InProcServer32]
@="C:\WINDOWS\system32\geplxss.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{aed6f6a3-183c-488d-9f90-23db99f56e7f}\InProcServer32]
@="C:\WINDOWS\system32\geplxss.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\geplxss.dll Deleted
C:\DOCUME~1\Daniel\FAVORI~1\Online Security Test.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


Thanks again for all your help. Incase something didn't go right with the Registry Cleanup, I'll wait to hear back from you before doing anything further.


Report Offensive Follow Up For Removal

Response Number 8
Name: jabuck
Date: March 17, 2007 at 19:39:27 Pacific
Reply: (edit)

Something went wrong with the disk cleanup. Click start> my computer> right click "local disk c:"> properties> click "disk cleanup" and let it run untill it is finisheed then restart the computer.

Then restart the computer and let me know if you got the desktop back.


Report Offensive Follow Up For Removal

Response Number 9
Name: Kenson
Date: March 17, 2007 at 20:27:09 Pacific
Reply: (edit)

I finished the Disk Cleanup successfully and restarted, but the desktop is still a plain blue. Any ideas??

Would it hurt if I just tried setting the desktop background back to the original image I had in "Appearances and Themes" under the control panel?

Let me know your thoughts.

P.S. I'm sticking close to the computer now so I can give you quicker response ;)


Report Offensive Follow Up For Removal

Response Number 10
Name: jabuck
Date: March 17, 2007 at 20:38:48 Pacific
Reply: (edit)

Set it back then go to start> control panel> display> desktop> customize desktop> web > if there is anythig there other than "my current home page" remove it. If that did not help go to this link http://www.geekstogo.com/forum/page-1-t38725-s0.html scroll down to GerryF's second post and download and run the two .reg files.

You may have to join the forum by registering but it doesn't take but a minute.


Report Offensive Follow Up For Removal

Response Number 11
Name: Kenson
Date: March 17, 2007 at 20:57:07 Pacific
Reply: (edit)

I reapplied my desktop background and that seems to have done the trick. I checked under the Webs tab of Desktop Items and didn't see anything listed there so I'm assuming everything's okay.

Shall I move on to disabling "mnew4win" and the other stuff then post the next log?


Report Offensive Follow Up For Removal

Response Number 12
Name: jabuck
Date: March 17, 2007 at 21:06:34 Pacific
Reply: (edit)

Yes continue with the virus removal.


Report Offensive Follow Up For Removal

Response Number 13
Name: Kenson
Date: March 17, 2007 at 22:46:35 Pacific
Reply: (edit)

Okay here's the scoop:


I went into the services section of Administrative Tools and took a look at all the files you mentioned to stop. Each one of them were marked as already stopped and only gave me the option to "Start" them. So I bypassed that step. However I did notice that many of them were set to Manual or Automatic in the drop down list so I made sure to set each of those to "Disabled".

Next when I ran the Hijack scan it only came up with the "04" HKLMs and none of the "023" Services. I figured it might have something to do with those being ones related to the files that were already stopped in Administrative Tools. I checked the ones that were there and had them fixed.

I'm now trying to add the path files you recommended to Killbox from the clipboard, but everytime I use the "paste from clipboard" function it appears to do nothing. If I directly paste into the path dropdown list it will paste the first of the paths copied, but that's it. I have the "All Files" button selected but it appears it will only let me do one path at a time.

I'm not really sure what to do. What's the best course of action? Should I just delete each path one by one? And if so should I still have "Delete on Reboot" checked?

P.S. Thanks for sticking with me on this jabuck. I do notice a significant improvement on my PC's performance and stability.


Report Offensive Follow Up For Removal

Response Number 14
Name: jabuck
Date: March 18, 2007 at 07:00:57 Pacific
Reply: (edit)

I don't know what the problem with Killbox is but lets try a different tool.

Please download “Avenger” by swandog46 to your desktop from this link http://swandog46.geekstogo.com/avenger.zip

1. Click on Avenger.zip to open the file
Extract avenger.exe to your desktop

2. Copy all the text contained in the area between the X"s below to your Clipboard by highlighting it and pressing (Ctrl+C):
XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Files to delete:
C:\Documents and Settings\Daniel\Local Settings\Temp\winlogon.exe

C:\WINDOWS\System32\win32bootcfg.exe

C:\WINDOWS\System32\mssvcc.exe

C:\WINDOWS\System32\mssecure.exe

C:\WINDOWS\System32\msconfig32.exe

C:\WINDOWS\system32\mnew4win.exe

C:\WINDOWS\win32host.exe


XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
3. Now, start The Avenger program by clicking on its icon on your desktop.
Under "Script file to execute" choose "Input Script Manually".
Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
Paste the text copied to clipboard into this window by pressing (Ctrl+V).
Click Done
Now click on the Green Light to begin execution of the script
Answer "Yes" twice when prompted.
4. The Avenger will automatically do the following:
It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
On reboot, it will briefly open a black command window on your desktop, this is normal.
After the restart, it creates a log file that should open with the results of Avenger's actions. This log file will be located at C:\avenger.txt
The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
5. Please copy/paste the content of c:\avenger.txt into your reply and the other logs please.


Report Offensive Follow Up For Removal

Response Number 15
Name: Kenson
Date: March 18, 2007 at 10:23:32 Pacific
Reply: (edit)

Hi


Here are my results from running Avenger:


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\hdrfkuiv

*******************

Script file located at: \??\C:\xcltkqqq.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

File C:\Documents and Settings\Daniel\Local Settings\Temp\winlogon.exe not found!
Deletion of file C:\Documents and Settings\Daniel\Local Settings\Temp\winlogon.exe failed!

Could not process line:
C:\Documents and Settings\Daniel\Local Settings\Temp\winlogon.exe
Status: 0xc0000034

File C:\WINDOWS\System32\win32bootcfg.exe not found!
Deletion of file C:\WINDOWS\System32\win32bootcfg.exe failed!

Could not process line:
C:\WINDOWS\System32\win32bootcfg.exe
Status: 0xc0000034

File C:\WINDOWS\System32\mssvcc.exe not found!
Deletion of file C:\WINDOWS\System32\mssvcc.exe failed!

Could not process line:
C:\WINDOWS\System32\mssvcc.exe
Status: 0xc0000034

File C:\WINDOWS\System32\mssecure.exe not found!
Deletion of file C:\WINDOWS\System32\mssecure.exe failed!

Could not process line:
C:\WINDOWS\System32\mssecure.exe
Status: 0xc0000034

File C:\WINDOWS\System32\msconfig32.exe not found!
Deletion of file C:\WINDOWS\System32\msconfig32.exe failed!

Could not process line:
C:\WINDOWS\System32\msconfig32.exe
Status: 0xc0000034

File C:\WINDOWS\system32\mnew4win.exe not found!
Deletion of file C:\WINDOWS\system32\mnew4win.exe failed!

Could not process line:
C:\WINDOWS\system32\mnew4win.exe
Status: 0xc0000034

File C:\WINDOWS\win32host.exe not found!
Deletion of file C:\WINDOWS\win32host.exe failed!

Could not process line:
C:\WINDOWS\win32host.exe
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.

It seems as if they are no longer on the computer. Unfortunately, that's all I can post for now, I've got to go to work. I'll be back at 8 tonight so don't worry about checking this thread for posts until then. I'll post the other logs when I get back. Talk to you then. Thanks.


Report Offensive Follow Up For Removal

Response Number 16
Name: Kenson
Date: March 19, 2007 at 00:47:38 Pacific
Reply: (edit)

Okay, here's my AVG report:


AVG Anti-Spyware - Scan Report


+ Created at: 12:04:58 AM 3/19/2007

+ Scan result:

C:\WINDOWS\system32\c.bat -> Backdoor.BotGet.FtpA : Cleaned.
C:\WINDOWS\browser.exe -> Hijacker.Small : Cleaned.
:mozilla.125:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.126:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.127:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.128:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.129:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.130:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.131:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.132:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.133:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.134:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.135:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.136:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.139:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.140:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.141:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.321:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.341:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.372:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.457:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.520:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.567:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F.tmp -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.13:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.16:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.17:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.30:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.31:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.32:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.33:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.34:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.274:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.275:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.277:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.278:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.279:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.163:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.164:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23.tmp -> TrackingCookie.Adtech : Cleaned.
:mozilla.143:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.144:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.145:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.146:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.147:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq24.tmp -> TrackingCookie.Advertising : Cleaned.
:mozilla.11:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.40:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq25.tmp -> TrackingCookie.Atdmt : Cleaned.
:mozilla.37:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Bfast : Cleaned.
:mozilla.40:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.84:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq28.tmp -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.784:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.368:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.785:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp -> TrackingCookie.Burstnet : Cleaned.
:mozilla.224:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.227:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.228:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.229:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2B.tmp -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2C.tmp -> TrackingCookie.Clickbank : Cleaned.
:mozilla.383:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2D.tmp -> TrackingCookie.Com : Cleaned.
:mozilla.14:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.14:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.15:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.15:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.16:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.17:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.18:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.19:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.20:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.21:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.36:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.37:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.8:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2F.tmp -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.443:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.444:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.422:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.423:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.424:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.425:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.426:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.427:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.428:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.429:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.430:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.431:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.432:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.433:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.322:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.323:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.324:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.13:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.19:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.20:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.154:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.155:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.156:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.157:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.158:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.159:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.32:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.33:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Enigma Software Group\SpyHunter\Backup\daniel@fastclick[2].txt.bak -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Enigma Software Group\SpyHunter\Backup\daniel@media.fastclick[2].txt.bak -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq31.tmp -> TrackingCookie.Fastclick : Cleaned.
:mozilla.216:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.217:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.240:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq35.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq38.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq39.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3A.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3B.tmp -> TrackingCookie.Hitslink : Cleaned.
:mozilla.465:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.737:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.729:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.730:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.731:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.740:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.741:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.742:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.743:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.744:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.745:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.746:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.10:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.10:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.11:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.9:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3C.tmp -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.38:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.39:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.750:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.751:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq44.tmp -> TrackingCookie.Onestat : Cleaned.
:mozilla.247:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.248:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.249:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.250:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.251:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.566:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
:mozilla.101:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.328:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.329:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.330:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.331:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3D.tmp -> TrackingCookie.Pointroll : Cleaned.
:mozilla.570:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.571:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.236:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.237:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.191:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.192:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.193:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3E.tmp -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.583:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.584:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.585:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.586:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.587:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3F.tmp -> TrackingCookie.Realmedia : Cleaned.
:mozilla.763:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned.
:mozilla.589:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq40.tmp -> TrackingCookie.Revenue : Cleaned.
:mozilla.176:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.177:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.178:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.179:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.184:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.185:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.692:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.273:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.276:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.280:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.281:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.282:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.283:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.284:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq30.tmp -> TrackingCookie.Ru4 : Cleaned.
:mozilla.262:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.263:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.264:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.265:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.266:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.267:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq41.tmp -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.88:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.89:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.90:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.91:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.92:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.93:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq42.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq43.tmp -> TrackingCookie.Sextracker : Cleaned.
:mozilla.219:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.220:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.325:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.326:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.327:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.206:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.207:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.208:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq45.tmp -> TrackingCookie.Statcounter : Cleaned.
:mozilla.214:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.65:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.66:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.67:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.68:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.694:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.69:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.70:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq46.tmp -> TrackingCookie.Tacoda : Cleaned.
:mozilla.199:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.200:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq47.tmp -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.624:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.625:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.626:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.627:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.628:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.629:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.630:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.631:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.632:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq48.tmp -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.6:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.6:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.7:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.7:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq49.tmp -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4A.tmp -> TrackingCookie.Valueclick : Cleaned.
:mozilla.119:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Weborama : Cleaned.
:mozilla.47:C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cs5p2sf0.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.718:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4B.tmp -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.681:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.170:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.171:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.172:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.173:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.174:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.175:C:\Documents and Settings\Daniel\Application Data\Mozilla\Firefox\Profiles\y7rudoee.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq20.tmp -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4D.tmp -> TrackingCookie.Zedo : Cleaned.


::Report end

You weren't kidding when you said it might take a while, but man was I surprised. It found all kinds of wierd stuff. And I had JUST used my Spybot and Ad-Aware.

Some of the finds were quite alarming. Especially that "Hijacker.Small" file. I've been using this computer for 4 years now. Who knows how long that thing's been hiding!

I'd like to continue using this program in the future in conjunction with my other spyware and anti-virus programs. Does anyone out there know if there is a problem with having multiple anti spyware programs running their real-time protection simultaneously? Or is it better to choose one for real-time monitoring and keep the others around for manual scanning only? If anyone knowledgeable about the subject knows about conflict between multiple spyware programs, I'd love to hear your suggestions.
Thanks.


Report Offensive Follow Up For Removal

Response Number 17
Name: Kenson
Date: March 19, 2007 at 01:20:04 Pacific
Reply: (edit)

Here is my "ComboScan.txt" file and "Supplementary.txt" file:

ComboScan v20070306.20 run by Daniel on 2007-03-19 at 00:50:35
Computer is in Normal Mode.
----------------------

-- System Res---------

Successfully created ComboScan Restore Point.


-- Last 2 Restore Point(s) --
2: 2007-03-19 07:50:40 UTC - RP2 - ComboScan Restore Point
1: 2007-03-19 04:22:29 UTC - RP1 - System Checkpoint


Performed disk cleanup.


-- HijackThis (run as Daniel.----------------------

Logfile of HijackThis v1.99.1
Scan saved at 12:50:46 AM, on 3/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\System32\fryhser.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Tablet.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\WTablet\TabUserW.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Documents and Settings\Daniel\Desktop\comboscan.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\HIJACK~1\Daniel.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O4 - HKLM\..\Run: [frymxins] frymxins
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [YBrowser] C:\PROGRA~1\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Registry Cleaner Scheduler] "C:\Program Files\CleanMyPC\Registry Cleaner\RCScheduler.exe" /startup
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\WTablet\TabUserW.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AT&T Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?lin...
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microso...
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/download...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{60F16BAA-5FF3-498B-9F38-CD56E189E4B8}: NameServer = 68.94.156.1,68.94.157.1
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: FGLRYUTIL (FGLRYUtil) - ATI Technologies, Inc. - C:\WINDOWS\System32\fryhser.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O2