Help - Search - Members
Full Version: comp eggs - type mp3.exe in my startup
Piriform Community Forums > Computer Help and Discussion > Spyware Hell
Agnes
Hi,


I would like to ask you if you can helf me to do something with my computer. I have the ``comp eggs`` problem in my startup.
I tried to delete it several times. But it always comes back.

here is my hjt analisys





Logfile of HijackThis v1.99.1
Scan saved at 12:03:59 PM, on 4/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
c:\progra~1\intern~1\iexplore.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [comp eggs] "C:\DOCUME~1\Owner\APPLIC~1\BALLAB~1\type mp3.exe"
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


Please help me.

Thank you

Agi
rridgely
Welcome to the forum. smile.gif
I removed your other post just to keep instructions simple.

Run BitDefender Online Scanner
  • Using internet Explorer please go HERE to run BitDefender's Online scan.
  • Read the terms and then click I Agree
  • You may receive a Security Warning about the BitDefender ActiveX control, If you do, please allow it to install.
  • On the scanning Options screen, Press Click Here To Scan and then follow the on screen prompts.
  • Once bit defender is finished scanning your computer it will automatically remove the infections. Once the removal process is finished press the close button and a dialog box will appear asking if you want to send your scan log back to the makers of bitdefender. You do not have to do this but what you do want to do is press the button that says "view log" and then copy and paste that log into notepad and save it to your desktop as bitdefender.txt.
  • Reboot your computer
Post the bit defender scan log along with a new hijackthis log.
Agnes
QUOTE(rridgely @ Apr 19 2007, 10:53 PM) [snapback]69008[/snapback]
Welcome to the forum. smile.gif
I removed your other post just to keep instructions simple.

Run BitDefender Online Scanner
  • Using internet Explorer please go HERE to run BitDefender's Online scan.
  • Read the terms and then click I Agree
  • You may receive a Security Warning about the BitDefender ActiveX control, If you do, please allow it to install.
  • On the scanning Options screen, Press Click Here To Scan and then follow the on screen prompts.
  • Once bit defender is finished scanning your computer it will automatically remove the infections. Once the removal process is finished press the close button and a dialog box will appear asking if you want to send your scan log back to the makers of bitdefender. You do not have to do this but what you do want to do is press the button that says "view log" and then copy and paste that log into notepad and save it to your desktop as bitdefender.txt.
  • Reboot your computer
Post the bit defender scan log along with a new hijackthis log.


hi! thank you for your welcome.
I tried to do this online scanning, but I cannot do it, because I couldnt click on the I Agree thing. What should I do now?
Agnes
huhhhhh. I found the mp3.exe in my application data. In the ballabout folder. I am going to delete, and see what`s going to happen... huh.gif unsure.gif
rridgely
You can delete that file if you want, but there is a chance it may not work.

Try this scan:

Run Panda Activescan from Here.

Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.


Post the panda log and a new hijackthis log.
Agnes
QUOTE(rridgely @ Apr 20 2007, 12:03 PM) [snapback]69051[/snapback]
You can delete that file if you want, but there is a chance it may not work.

Try this scan:

Run Panda Activescan from Here.

Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.
Post the panda log and a new hijackthis log.



Hi,
I dont know what the hell`s going on sad.gif
I tried this scan. It works only with IE. But I cannot click on the button. I click on it, and nothing happen. Before I had deleted the whole folder which included the mp3.exe file.
So, now I am in Safe Mode , but the IE doesnt work. I can use only the Mozilla browser.
What should I do? Maybe I should the IE7 again? Whats wrong here?

Here is my HJT:

Logfile of HijackThis v1.99.1
Scan saved at 3:36:24 AM, on 4/20/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [CCleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] "C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /startupscan
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\PROGRA~1\Skype\Phone\IEPlugin\SKYPEI~1.DLL
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe



Thank you





rridgely
Open Hijackthis, and click the Misc Tools button.
Then click the Open Uninstall Manager... button.
The Add/Remove Programs Manager panel should appear.
In this panel click the Save list button.
Save the uninstall_list.txt file to your desktop and copy and paste the contents back in your next reply.
Agnes
QUOTE(rridgely @ Apr 20 2007, 08:23 PM) [snapback]69095[/snapback]
Open Hijackthis, and click the Misc Tools button.
Then click the Open Uninstall Manager... button.
The Add/Remove Programs Manager panel should appear.
In this panel click the Save list button.
Save the uninstall_list.txt file to your desktop and copy and paste the contents back in your next reply.



1Click DVD Copy Pro 2.3.1.1
Ad-Aware SE Personal
Adobe Acrobat 5.0
Adobe Flash Player 9 ActiveX
Adobe Photoshop 7.0
Agnitum Outpost Firewall Pro
ALPS Touch Pad Driver
America Online (Choose which version to remove)
Apple Software Update
Ashampoo AntiSpyWare 1.60
BitComet 0.85
CCleaner (remove only)
CD/DVD Drive Acoustic Silencer
Cda Product Service - shared component
Desktop Architect
DivX Codec
DivX Content Uploader
DivX Converter
DivX Player
DivX Web Player
DVD43 v3.9.0
DVD-RAM Driver
EVEREST Home Edition v2.20
Express Burn
FastStone Photo Resizer 2.1
Form Fill (Windows Live Toolbar)
GdiplusUpgrade
GIB 3.0
Google Gmail Notifier
Google Toolbar for Firefox
HijackThis 1.99.1
HP Document Viewer 5.3
HP Image Zone 5.3
HP Imaging Device Functions 5.3
HP PSC & OfficeJet 5.3.A
HP Software Update
HP Solution Center & Imaging Support Tools 5.3
Ice Cream Tycoon
Intel® Graphics Media Accelerator Driver for Mobile
Intel® PROSet/Wireless Software
InterVideo WinDVD Creator 2
InterVideo WinDVD for TOSHIBA
iTunes
J2SE Runtime Environment 5.0 Update 1
Jasc Animation Shop 3
Jasc Paint Shop Pro 9
Mahjong Tales Ancient Wisdom
mDrWiFi
MetaFrame Presentation Server Web Client for Win32
mHelp
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB886903)
Microsoft .NET Framework 2.0
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft National Language Support Downlevel APIs
Microsoft Office FrontPage 2003
Microsoft Office OneNote 2003
Microsoft Office Standard Edition 2003
Microsoft Windows Media Video 9 VCM
mIWA
mIWCA
mLogView
mMHouse
Mozilla Firefox (1.5.0.10)
mPfMgr
mPfWiz
mProSafe
MSN
mWlsSafe
mXML
mZConfig
NCH Toolbox Uninstall
Nero 7 Premium
NOD32 antivirus system
Notebook Maximizer
Opera 9.10
PhotoFiltre
QuickTime
RealPlayer
Realtek AC'97 Audio
SAMSUNG Mobile USB Modem 1.0 Software
SD Secure Module
Skype 3.0
Skype Plugin Manager
Sonic DLA
Sonic RecordNow!
Spy Sweeper
Tabbed Browsing (Windows Live Toolbar)
Texas Instruments PCIxx21/x515 drivers.
TOSHIBA Accessibility
TOSHIBA Assist
TOSHIBA ConfigFree
TOSHIBA Controls
TOSHIBA Fn-esse
TOSHIBA Hardware Setup
TOSHIBA Hotkey Utility
TOSHIBA PC Diagnostic Tool
TOSHIBA Power Saver
Toshiba Registration and Metamail Trust Architecture
TOSHIBA SD Memory Card Format
TOSHIBA Software Modem
TOSHIBA Software Upgrades
TOSHIBA Speech System Applications
TOSHIBA Speech System SR Engine(U.S.) Version1.0
TOSHIBA Speech System TTS Engine(U.S.) Version1.0
TOSHIBA Supervisor Password
Toshiba Tbiosdrv Driver
TOSHIBA Virtual Sound
TOSHIBA Zooming Utility
Total Commander (Remove or Repair)
Touch and Launch
TouchPad On/Off Utility
TypingMaster 2002
Ulead COOL 360
Ulead Photo Explorer 8.6
Ulead PhotoImpact 12
Unlocker 1.8.5
Winamp (remove only)
Windows Defender Signatures
Windows Internet Explorer 7
Windows Live Messenger
Windows Live Sign-in Assistant
Windows Live Toolbar
Windows Live Toolbar
Windows Media Format Runtime
Windows Media Player 10
WinRAR archiváló
WinZip
Xara Xtreme Pro
Xara3D6

rridgely
Download Deljob.exe and save it on your desktop.
Doubleclick Deljob.exe.
If the PC is infected, you'll get a message that "Suspicious files" are found and the suspicious files look similar to: B2DRF32OI6483931.job (random numbers and letters),
then select option 2 by typing 2 and hit enter.

A log, (logit.txt) should open afterwards. This log will be present on your desktop. Post the contents of the logfile in your next reply together with a new Hijackthislog.
Agnes
QUOTE(rridgely @ Apr 21 2007, 10:21 AM) [snapback]69148[/snapback]
Download Deljob.exe and save it on your desktop.
Doubleclick Deljob.exe.
If the PC is infected, you'll get a message that "Suspicious files" are found and the suspicious files look similar to: B2DRF32OI6483931.job (random numbers and letters),
then select option 2 by typing 2 and hit enter.

A log, (logit.txt) should open afterwards. This log will be present on your desktop. Post the contents of the logfile in your next reply together with a new Hijackthislog.




hi! there it is, the deljob log. I didnt see a suspicious fie.

but here, I see the TEST SEND 4 ACTIVE thing that I mentioned before. Do you think it s harmful?

--------------------------------------------------------
BACKUPS CREATED in C:\DELJOB


AC1A3D6495ADB134.job
--------------------------------------------------------
FILES IN TASKS FOLDER

AppleSoftwareUpdate.job
Check Updates for Windows Live Toolbar.job
--------------------------------------------------------
EXPORT APP DATA FOLDERS

Volume in drive C is SQ003928
Volume Serial Number is B4BD-A73C

Directory of C:\Documents and Settings\Owner\Application Data

04/19/2007 09:53 PM <DIR> .
04/19/2007 09:53 PM <DIR> ..
04/18/2007 07:08 AM <DIR> 1CLICK~1 1clickPro
03/26/2007 03:49 PM <DIR> Adobe
01/02/2007 03:07 PM <DIR> AdobeAUM
01/02/2007 03:07 PM <DIR> AdobeUM
04/02/2007 10:29 PM <DIR> Ahead
02/22/2007 06:05 PM <DIR> APPLEC~1 Apple Computer
02/06/2007 12:14 AM <DIR> DivX
12/30/2006 09:38 PM <DIR> Google
12/25/2006 02:37 PM <DIR> HP
04/12/2006 02:04 PM <DIR> ICACLI~1 ICAClient
09/11/2006 05:44 PM <DIR> IDENTI~1 Identities
04/10/2006 07:17 PM <DIR> INTERV~1 InterVideo
05/23/2005 05:29 PM <DIR> Intuit
04/12/2007 02:17 AM <DIR> Jasc
03/28/2007 11:30 PM <DIR> JASCSO~1 Jasc Software Inc
12/27/2006 12:17 PM <DIR> Lavasoft
01/02/2007 11:52 PM <DIR> LEADER~1 Leadertech
04/09/2006 09:25 PM <DIR> MACROM~1 Macromedia
03/30/2007 11:53 PM <DIR> MICROS~1 Microsoft
02/13/2007 05:07 PM <DIR> MICROS~2 Microsoft Games
01/03/2007 05:00 PM <DIR> Mozilla
01/07/2007 12:12 AM <DIR> NCHSWI~1 NCH Swift Sound
02/19/2007 11:05 AM <DIR> Opera
09/08/2006 01:03 PM <DIR> PCTOOL~1 PC Tools
04/03/2007 09:43 PM <DIR> Real
03/17/2007 02:53 PM <DIR> Sereniti
04/21/2007 02:49 PM <DIR> Skype
04/10/2007 02:06 AM <DIR> Snapfish
04/10/2006 07:16 PM <DIR> Sonic
05/14/2006 01:02 PM <DIR> Sun
04/11/2006 08:09 PM <DIR> Symantec
01/29/2007 12:44 AM <DIR> toshiba
03/21/2007 12:44 AM <DIR> ULEADS~1 Ulead Systems
03/16/2007 01:35 AM <DIR> Uniblue
01/05/2007 02:20 PM <DIR> uTorrent
04/06/2007 01:35 AM <DIR> Vso
04/11/2007 01:17 AM <DIR> Webroot
12/23/2006 05:34 PM <DIR> WHOLES~1 WholeSecurity
0 File(s) 0 bytes
40 Dir(s) 35,095,244,800 bytes free
Volume in drive C is SQ003928
Volume Serial Number is B4BD-A73C

Directory of C:\Documents and Settings\All Users\Application Data

04/11/2007 01:19 AM <DIR> .
04/11/2007 01:19 AM <DIR> ..
01/02/2007 03:05 PM <DIR> Adobe
04/02/2007 12:22 AM <DIR> Ahead
02/15/2007 11:47 PM <DIR> AOL
02/22/2007 12:04 AM <DIR> APPLEC~1 Apple Computer
04/18/2007 03:32 AM <DIR> Google
08/20/2006 05:38 PM <DIR> HP
03/28/2007 11:31 PM <DIR> INSTAL~1 InstallShield
05/23/2005 05:30 PM <DIR> Intuit
05/23/2005 05:25 PM <DIR> McAfee.com
03/01/2007 03:32 PM <DIR> MICROS~1 Microsoft
02/13/2007 05:07 PM <DIR> MICROS~2 Microsoft Games
01/03/2007 12:16 AM <DIR> NCHSWI~1 NCH Swift Sound
12/26/2006 03:29 PM <DIR> PURENE~1 Pure Networks
12/27/2006 02:51 PM <DIR> QUICKT~1 QuickTime
03/26/2007 02:57 PM <DIR> SECTAS~1 SecTaskMan
12/30/2006 04:07 PM <DIR> Skype
08/20/2006 05:33 PM <DIR> Sonic
03/27/2007 01:22 AM <DIR> Symantec
03/18/2007 10:39 PM <DIR> TEMP
04/03/2007 02:31 AM <DIR> TESTSE~1 TEST SEND 4 ACTIVE
03/19/2007 02:51 PM <DIR> ULEADS~1 Ulead Systems
04/11/2007 01:19 AM <DIR> Webroot
08/20/2006 04:26 PM <DIR> WINDOW~1 Windows Genuine Advantage
12/23/2006 01:56 PM <DIR> WINDOW~2 Windows Live Toolbar
11/02/2006 11:29 PM <DIR> Yahoo
09/14/2006 09:08 PM <DIR> Yahoo!
0 File(s) 0 bytes
28 Dir(s) 35,095,240,704 bytes free
--------------------------------------------------------



Logfile of HijackThis v1.99.1
Scan saved at 2:53:03 PM, on 4/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Opera\Opera.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] "C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /startupscan
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe


rridgely
Download AVG Anti-Spyware
  1. Load AVG antispyware and then click the Update tab at the top. Under Manual Update click Start update.
  2. After the update finishes (the status bar at the bottom will display "Update successful")
  3. Click on the Scanner tab at the top and then click on Complete System Scan
  4. Ewido will list any infections found on the left, when the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG antispyware will then display "All actions have been applied" on the right.
  5. Click on "Save Report", then "Save Report As". This will create a text file which you can then save to the Desktop and post back
Note that this is not AVG antivirus but the program formally known as Ewido.
Agnes
QUOTE(rridgely @ Apr 21 2007, 01:00 PM) [snapback]69165[/snapback]
Download AVG Anti-Spyware
  1. Load AVG antispyware and then click the Update tab at the top. Under Manual Update click Start update.
  2. After the update finishes (the status bar at the bottom will display "Update successful")
  3. Click on the Scanner tab at the top and then click on Complete System Scan
  4. Ewido will list any infections found on the left, when the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. AVG antispyware will then display "All actions have been applied" on the right.
  5. Click on "Save Report", then "Save Report As". This will create a text file which you can then save to the Desktop and post back
Note that this is not AVG antivirus but the program formally known as Ewido.


hi,
there is the report:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:49:47 PM 4/21/2007

+ Scan result:



HKU\S-1-5-21-519459852-3855340036-3308542633-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored.
C:\Downloads\software\1 click COPY Pro 2.3.1+ crack\New Folder (2).rar/1Click.DVD.COPY.PRO.2.3.1.1 Patch.exe -> Downloader.Delf.aup : Ignored.
C:\Program Files\LG Software Innovations\1Click DVD Copy Pro\1Click.DVD.COPY.PRO.2.3.1.1 Patch.exe -> Downloader.Delf.aup : Ignored.
:mozilla.126:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.127:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.128:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.129:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.133:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.134:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.135:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.136:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.137:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.138:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.139:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.140:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.337:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.496:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.585:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.620:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.645:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.661:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.682:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@aavalue[1].txt -> TrackingCookie.Aavalue : Ignored.
C:\Documents and Settings\Owner\Cookies\owner@grouplotto.aavalue[2].txt -> TrackingCookie.Aavalue : Ignored.
:mozilla.322:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.455:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.458:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.468:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.201:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adocean : Ignored.
:mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adocean : Ignored.
:mozilla.303:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.304:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.305:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.306:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.307:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.308:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.309:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.310:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.285:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.286:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.287:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.288:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.289:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.19:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.642:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
:mozilla.482:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Bluestreak : Ignored.
:mozilla.336:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignored.
:mozilla.335:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.348:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.350:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.351:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.352:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.353:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.785:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Clickbank : Ignored.
:mozilla.300:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.10:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.11:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.7:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.76:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
:mozilla.485:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.486:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.487:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.489:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.742:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.757:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.367:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Directnetadvertising : Ignored.
:mozilla.57:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.450:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Euroclick : Ignored.
:mozilla.318:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.319:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.320:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.321:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.514:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.515:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.516:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.517:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.518:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.519:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.520:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.589:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.590:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.654:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.706:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.735:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.736:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.825:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.950:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.405:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ivwbox : Ignored.
:mozilla.208:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Linksynergy : Ignored.
:mozilla.210:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Linksynergy : Ignored.
:mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.243:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.244:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.245:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.246:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.277:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.278:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.279:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.284:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.110:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.111:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.451:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.459:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.460:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.461:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.462:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.463:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.187:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.188:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.189:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.190:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.385:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.341:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.342:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.344:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.345:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.346:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.347:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.349:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.354:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.555:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.556:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.557:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.558:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.559:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.445:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.446:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.447:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.448:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.537:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.294:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.295:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.296:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.297:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.298:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.299:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.343:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.506:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Weborama : Ignored.
:mozilla.394:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.313:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.314:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.315:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.316:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.317:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.311:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.312:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Zedo : Ignored.


::Report end

rridgely
Delete these 2 files:

C:\Downloads\software\1 click COPY Pro 2.3.1+ crack\New Folder (2).rar
C:\Program Files\LG Software Innovations\1Click DVD Copy Pro\1Click.DVD.COPY.PRO.2.3.1.1 Patch.exe

Software cracks almost always contain some sort of virus/spyware.

-----------
Download Superantispyware
  1. Load Superantispyware and click the check for updates button.
  2. Once the update is finished click the scan your computer button.
  3. Check Perform Complete Scan and then next.
  4. Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
  5. Make sure that they all have a check next to them and press next.
  6. Click finish and you will be taken back to the main interface.
  7. Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  8. Copy and paste the log onto the forum.

Post the superantispyware log along with a new hijackthis log.
Agnes
QUOTE(rridgely @ Apr 21 2007, 08:56 PM) [snapback]69216[/snapback]
Delete these 2 files:

C:\Downloads\software\1 click COPY Pro 2.3.1+ crack\New Folder (2).rar
C:\Program Files\LG Software Innovations\1Click DVD Copy Pro\1Click.DVD.COPY.PRO.2.3.1.1 Patch.exe

Software cracks almost always contain some sort of virus/spyware.

-----------
Download Superantispyware
  1. Load Superantispyware and click the check for updates button.
  2. Once the update is finished click the scan your computer button.
  3. Check Perform Complete Scan and then next.
  4. Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
  5. Make sure that they all have a check next to them and press next.
  6. Click finish and you will be taken back to the main interface.
  7. Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  8. Copy and paste the log onto the forum.
Post the superantispyware log along with a new hijackthis log.

SUPERAntiSpyware Scan Log
Generated 04/22/2007 at 03:56 PM

Application Version : 3.6.1000

Core Rules Database Version : 3222
Trace Rules Database Version: 1233

Scan type : Complete Scan
Total Scan Time : 00:44:28

Memory items scanned : 535
Memory threats detected : 0
Registry items scanned : 6991
Registry threats detected : 0
File items scanned : 37092
File threats detected : 17

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@ads.mininova[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.levelclick[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ad.magyaronline[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.mobiledia[2].txt
C:\Documents and Settings\Owner\Cookies\owner@clickaudit[2].txt
C:\Documents and Settings\Owner\Cookies\owner@easywarez[1].txt
C:\Documents and Settings\Owner\Cookies\owner@usenext[2].txt
C:\Documents and Settings\Owner\Cookies\owner@vhost.oddcast[2].txt
C:\Documents and Settings\Owner\Cookies\owner@www.easywarez[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.googleadservices[1].txt
C:\Documents and Settings\Owner\Cookies\owner@www.ultrabanner[1].txt

Adware.Lop-Gen
C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\TEST SEND 4 ACTIVE\POP DOES.EXE
C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\TEMP\BIS201.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP13\A0002498.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP13\A0002580.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP13\A0002589.EXE
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP13\A0002590.EXE
Agnes
QUOTE(rridgely @ Apr 21 2007, 08:56 PM) [snapback]69216[/snapback]
Delete these 2 files:

C:\Downloads\software\1 click COPY Pro 2.3.1+ crack\New Folder (2).rar
C:\Program Files\LG Software Innovations\1Click DVD Copy Pro\1Click.DVD.COPY.PRO.2.3.1.1 Patch.exe

Software cracks almost always contain some sort of virus/spyware.

-----------
Download Superantispyware
  1. Load Superantispyware and click the check for updates button.
  2. Once the update is finished click the scan your computer button.
  3. Check Perform Complete Scan and then next.
  4. Superantispyware will now scan your computer and when its finished it will list all the infections it has found.
  5. Make sure that they all have a check next to them and press next.
  6. Click finish and you will be taken back to the main interface.
  7. Click Preferences and then click the statistics/logs tab. Click the dated log and press view log and a text file will appear.
  8. Copy and paste the log onto the forum.
Post the superantispyware log along with a new hijackthis log.

Logfile of HijackThis v1.99.1
Scan saved at 5:55:55 PM, on 4/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\BitComet\BitComet.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Skype\Plugin Manager\SkypePM.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] "C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /startupscan
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
Agnes
hi!

I did today another AVG scanning.
There is the log


---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 9:55:46 AM 4/23/2007

+ Scan result:



HKU\S-1-5-21-519459852-3855340036-3308542633-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Ignored.
:mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.192:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.193:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.194:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.195:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.196:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.197:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.198:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.199:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.200:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.201:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.202:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.203:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.204:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.205:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.369:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.516:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.604:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.639:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.664:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.680:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.701:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.25:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.26:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.481:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.484:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.494:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.257:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adocean : Ignored.
:mozilla.258:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adocean : Ignored.
:mozilla.85:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.86:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.90:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.92:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.331:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.332:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.333:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.334:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.335:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.661:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
:mozilla.502:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Bluestreak : Ignored.
:mozilla.368:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Burstbeacon : Ignored.
:mozilla.367:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.380:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.382:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.383:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.384:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.385:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.804:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Clickbank : Ignored.
:mozilla.15:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.131:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.653:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Connextra : Ignored.
:mozilla.654:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Connextra : Ignored.
:mozilla.655:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Connextra : Ignored.
:mozilla.161:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Coremetrics : Ignored.
:mozilla.505:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.506:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.507:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.509:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cpvfeed : Ignored.
:mozilla.761:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.776:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.831:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Dealtime : Ignored.
:mozilla.399:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Directnetadvertising : Ignored.
:mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
:mozilla.476:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Euroclick : Ignored.
:mozilla.45:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.46:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.47:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.353:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.354:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.355:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.356:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.117:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Gemius : Ignored.
:mozilla.118:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Gemius : Ignored.
:mozilla.119:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Gemius : Ignored.
:mozilla.267:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.534:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.535:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.536:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.537:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.538:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.539:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.540:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.608:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.609:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.673:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.725:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.754:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.755:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.844:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.969:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Hitbox : Ignored.
:mozilla.436:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ivwbox : Ignored.
:mozilla.264:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Linksynergy : Ignored.
:mozilla.266:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Linksynergy : Ignored.
:mozilla.154:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.155:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.156:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Liveperson : Ignored.
:mozilla.168:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.169:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.101:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Netflame : Ignored.
:mozilla.102:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Netflame : Ignored.
:mozilla.103:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Netflame : Ignored.
:mozilla.290:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.291:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.292:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.293:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Overture : Ignored.
:mozilla.658:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Paypal : Ignored.
:mozilla.323:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.324:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.325:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.330:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Pointroll : Ignored.
:mozilla.177:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.178:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.590:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Real : Ignored.
:mozilla.591:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Real : Ignored.
:mozilla.592:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Real : Ignored.
:mozilla.548:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.549:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.550:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Realmedia : Ignored.
:mozilla.100:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.93:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.94:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.95:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.97:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.98:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.99:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Revsci : Ignored.
:mozilla.477:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.485:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.486:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.487:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.488:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.489:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.247:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.248:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.249:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.250:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.251:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.417:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Serving-sys : Ignored.
:mozilla.373:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.374:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.376:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.377:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.378:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.379:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.381:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.386:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Specificclick : Ignored.
:mozilla.574:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.575:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.576:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.577:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.578:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.472:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.473:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.474:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.556:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.772:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Toplist : Ignored.
:mozilla.340:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.341:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.342:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.343:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.344:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.345:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Trafficmp : Ignored.
:mozilla.375:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.526:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Weborama : Ignored.
:mozilla.133:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Webtrends : Ignored.
:mozilla.426:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.348:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.349:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.350:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.351:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.352:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.346:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
:mozilla.347:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\tb65zuzy.default\cookies.txt -> TrackingCookie.Zedo : Ignored.
C:\System Volume Information\_restore{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP15\A0002982.exe -> Trojan.Obfuscated.en : Ignored.


::Report end

Agnes
today another with superantispyware


SUPERAntiSpyware Scan Log
Generated 04/23/2007 at 11:04 AM

Application Version : 3.6.1000

Core Rules Database Version : 3222
Trace Rules Database Version: 1233

Scan type : Complete Scan
Total Scan Time : 00:52:35

Memory items scanned : 415
Memory threats detected : 0
Registry items scanned : 7017
Registry threats detected : 0
File items scanned : 36388
File threats detected : 1

Adware.Lop-Gen
C:\SYSTEM VOLUME INFORMATION\_RESTORE{1D1D6F93-1B0C-4060-8D79-09274A81BD2A}\RP15\A0002982.EXE
Agnes
HJT


Logfile of HijackThis v1.99.1
Scan saved at 12:03:42 PM, on 4/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Documents and Settings\Owner\Desktop\HijackThis.exe /startupscan
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe

rridgely
You don't have to keep running the scans. tongue.gif
I've just been busy, I wasn't ignoring you. Just give me a day or so to respond.(I can only spend so much time doing this.)

Do things seem better?

Run Kaspersky WebScanner
  • Please go HERE and click Kaspersky Online Scanner
  • Read and Accept the Agreement
  • You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • If you see a Windows dialog asking if you want to install this software, click the Install button.
  • The program will launch and then begin downloading the latest definition files,
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button becomes available, please click on it.
  • Click on the Scan Settings button, and in the next window select the Extended database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
  • When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window.
  • Paste kaspersky log onto forum.
Agnes
QUOTE(rridgely @ Apr 23 2007, 03:32 PM) [snapback]69366[/snapback]
You don't have to keep running the scans. tongue.gif
I've just been busy, I wasn't ignoring you. Just give me a day or so to respond.(I can only spend so much time doing this.)

Do things seem better?



Hi!
It`s okay, write me when you are not so busy.
This whole computer is so complicated now sad.gif
I am very grateful to you for you helps. Thank you.
So. I do all the time this scannings, hoping to be the computer better.
And I dont know what is the problem. Because I deleted the comp eggs - type mp3.exe at least, and it is not as it was before. I wish I made a backup sad.gif
Yesterday, I got a blue `welcome screen` , because some ` kbdclass.sys ` . I guess this is because I bought a new mouse for the notebook. And somehow I got it. But I don`t know how to repair this.
Finally at the bottom of my screen you know, these is a blue stripe. So this stripe became thicker now (it happened 3-4 days before).
Have a good day,
rridgely
Your computer probably isn't clean yet. I can help you fix it but you need to run that scan I posted.
I need to see a screenshot of your monitor problem though because if its hardware related I obviously can't do anything.

Press the button on your keboard that says PrtScr. Then open ms paint and press ctrl+v. Save the picture as a .jpg and then go to this site and upload it:
http://imageshack.us/

Once you upload it you will get links to the picture. Copy and paste the second link onto the forum for me to see. biggrin.gif
Agnes
QUOTE(rridgely @ Apr 23 2007, 03:32 PM) [snapback]69366[/snapback]
Run Kaspersky WebScanner
  • Please go HERE and click Kaspersky Online Scanner
  • Read and Accept the Agreement
  • You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • If you see a Windows dialog asking if you want to install this software, click the Install button.
  • The program will launch and then begin downloading the latest definition files,
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button becomes available, please click on it.
  • Click on the Scan Settings button, and in the next window select the Extended database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
  • When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window.
  • Paste kaspersky log onto forum.


I`m sorry, I cannot run this Kaspersky. It works only with IE, but does nothing for me.
Agnes
QUOTE(rridgely @ Apr 23 2007, 08:42 PM) [snapback]69406[/snapback]
Your computer probably isn't clean yet. I can help you fix it but you need to run that scan I posted.
I need to see a screenshot of your monitor problem though because if its hardware related I obviously can't do anything.

Press the button on your keboard that says PrtScr. Then open ms paint and press ctrl+v. Save the picture as a .jpg and then go to this site and upload it:
http://imageshack.us/

Once you upload it you will get links to the picture. Copy and paste the second link onto the forum for me to see. biggrin.gif



there it is:



rridgely
Are you talking about your start bar? To fix that rightclick it and then choose "lock taskbar".
If thats not what you mean then it didn't show in your screenshot.(which means its your monitor)

You have to use IE to run that scan. Try it with IE if you haven't yet.
If you tried internet explorer already and it still didn't work yet then try this:

Run Panda Activescan from Here.

Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.



Agnes
QUOTE(rridgely @ Apr 24 2007, 07:52 AM) [snapback]69450[/snapback]
Are you talking about your start bar? To fix that rightclick it and then choose "lock taskbar".
If thats not what you mean then it didn't show in your screenshot.(which means its your monitor)

You have to use IE to run that scan. Try it with IE if you haven't yet.
If you tried internet explorer already and it still didn't work yet then try this:

Run Panda Activescan from Here.

Once you are on the Panda site click the Scan your PC button
- A new window will open...click the Check Now button
- Enter your Country
- Enter your State/Province
- Enter your e-mail address and click send
- Select either Home User or Company
- Click the big Scan Now button
- If it wants to install an ActiveX component allow it
- It will start downloading the files it requires for the scan
(Note: It may take a couple of minutes)
- When the download is complete, click on Local Disks to start the scan
- When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location so you can post it back.




hi!
IE doesn`t want to do this things for me. Not the Kaspersky, not the panda.
I use Mozilla.
So, I try to uninstall IE7 and then install again.
Thanks for helping
Agnes
I did an `Advanced Registry Fix` scan.

Here is the log.

Scan Time: Tuesday, April 24, 2007 at 1:22 PM

ActiveX / OLE / COM Sections:
_____________________________

HKEY_CLASSES_ROOT\TypeLib\{A4CA8810-6E46-36FF-A048-B7FD564742F8}\2.0\win32 --> PATH (Fixed Successfully)
HKEY_CLASSES_ROOT\AtWorkRendering\shell\PrintTo\command --> 0 (Fixed Successfully)

Registry Integrity:
__________________


User Software Settings:
_______________________

HKEY_CURRENT_USER\Software\Digital River\SoftwarePassport\Download Manager\4BD4B7197FAB248685137DBA8698CAFB --> LMxmlfilename --> C:\PROGRAM FILES\COMMON FILES\DOWNLOAD MANAGER\WINXMEDIA CD MP3/WAV/WMA CONVERTER\LMDOWNLOADINFO.XML(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main --> Local Page --> C:\WINDOWS\SYSTEM32\BLANK.HTM(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\&eBay Search --> --> C:\DOWNLOADS\EBAYTB.DLL/RCSEARCH.HTML(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all links using BitComet --> --> C:\PROGRAM FILES\BITCOMET\BITCOMET.EXE/ADDALLLINK.HTM(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download all videos using BitComet --> --> C:\PROGRAM FILES\BITCOMET\BITCOMET.EXE/ADDVIDEO.HTM(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Download link using &BitComet --> --> C:\PROGRAM FILES\BITCOMET\BITCOMET.EXE/ADDLINK.HTM(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Open in new background tab --> --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-US\MSNTABRES.DLL(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Open in new foreground tab --> --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-US\MSNTABRES.DLL(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ba0855ad-c80a-11da-8a66-806d6172696f}\_Autorun\DefaultIcon --> --> D:\LOGILOGO.ICO(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace --> LocalDelta --> C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS MEDIA\10.0\WMSDKNSD.XML(Fixed Successfully)
HKEY_CURRENT_USER\Software\Microsoft\Windows Media\WMSDK\Namespace --> RemoteDelta --> C:\DOCUMENTS AND SETTINGS\OWNER\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS MEDIA\10.0\WMSDKNSR.XML(Fixed Successfully)

System Software Settings:
_________________________

HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail\AOL --> LocalizedString --> C:\PROGRAM FILES\AMERICA ONLINE 9.0\RESOURCE.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\aol.exe --> LocalizedString --> C:\PROGRA~1\AMERIC~1.0\RESOURCE.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\DigitalImaging\HP Photosmart 3200 series\DeviceInstances\1156109921\Functions\Print --> DatFile --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\DATA\DEVICEDISCOVERY\HPODD09_NPI.INI (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\DigitalImaging\HP Photosmart 3200 series\DeviceInstances\1161261181\Functions\Print --> DatFile --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\DATA\DEVICEDISCOVERY\HPODD09_NPI.INI (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 2570 series --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 2570 series BT --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3100 series --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3100 series BT --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3100 series fax --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3200 series --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3200 series BT --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3300 series --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3300 series BT --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Hewlett-Packard\HPZ\Glue\HP Photosmart 3300 series fax --> ghoulpathname --> C:\PROGRAM FILES\HP\DIGITAL IMAGING\{3E386744-10FA-44B2-98C9-DF7A270DECB3}\UTIL\COMMON\HPZGHL12.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE UserData NT --> BackupFileName --> C:\PROGRAM FILES\UNINSTALL INFORMATION\IE USERDATA NT\IE USERDATA NT.DAT (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE.HKCUZoneInfo --> BackupFileName --> C:\PROGRAM FILES\UNINSTALL INFORMATION\IE.HKCUZONEINFO\IE.HKCUZONEINFO.DAT (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE.HKCUZoneInfo --> InstallINFFile --> C:\DOCUME~1\OWNER\LOCALS~1\TEMP\RGI2.TMP (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE40.Controls --> BackupFileName --> C:\PROGRAM FILES\UNINSTALL INFORMATION\IE40.CONTROLS\IE40.CONTROLS.DAT (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE40.Controls --> InstallINFFile --> C:\DOCUME~1\OWNER\LOCALS~1\TEMP\RGI204.TMP (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE40.UserAgent --> BackupFileName --> C:\PROGRAM FILES\UNINSTALL INFORMATION\IE40.USERAGENT\IE40.USERAGENT.DAT (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IE40.UserAgent --> InstallINFFile --> C:\DOCUME~1\OWNER\LOCALS~1\TEMP\RGI1.TMP (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Advanced INF Setup\IEHomePageInfo --> BackupFileName --> C:\PROGRAM FILES\UNINSTALL INFORMATION\IEHOMEPAGEINFO\IEHOMEPAGEINFO.DAT (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions --> Remote Exchange Extensions --> C:\WINDOWS\SYSTEM32\EMSUI32.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Exchange\Client\Extensions --> Kaspersky Mail Checker --> C:\PROGRAM FILES\KASPERSKY LAB\KASPERSKY ANTI-VIRUS 6.0\MCOU.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main --> Local Page --> C:\WINDOWS\SYSTEM32\BLANK.HTM (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components195B24E3691A214794109FEE73AC67E --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-AU\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components52026FFCD9EC4548B6165DC93008A04 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-CA\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\ComponentsE2F65CF27AFB9D4A978CF888DA69CA7 --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-CA\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F58A70DBADD45F4F864B41C7A89C85C --> 90A2CC5A3D9ECE9429D33078B4DBC4C2 --> C:\WINDOWS\TEMP\MPENGINE.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\1F5A5C27363E975428FAA006DE3CECFD --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-US\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29BB37897B982B84291B5259FED5F3F4 --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-PH\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\2E53A294F83182D45A3785356A851754 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCINST.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\31C0682E3111780479067E7CB3B8DBB4 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCCHARCV.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3DEE68F0FC3313E4CAD8E4C3EBCBEC40 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2TEXT.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3E81A4DC21026924FB5FAF933085D236 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCVRTRST.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\3FFC6CF7AA55B79458B6A9D3D36C6B95 --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-SG\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\4B103AA2ABAB321409E368DFD33A1EEA --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-IE\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50BBD0A1CB1FD3648A16157120DF2829 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2TNEF.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50C154874C6F14B48AE0F5068BC7E626 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DEFUTDCD.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\50E357748DE0DD840851872431DDB49B --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2RTF.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\56BAFEB49925C9F4892AFBA609E9CA3A --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\MSNTB.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D5B4CF03265F214ABE5FA89A270B47C --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-IN\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\624ADBC9C5580A64F811F5F25C0E9AFD --> A20E0CC2FC208E34E8FDB6B76BBB8E92 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-US\MSNFFRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6925106EE9D0AF740BCCD43F8907862F --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2TAR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6B8760239075CDA43837B6E980B8E590 --> 2CE27694B1714B74C87E057D0836067D --> C:\PROGRAM FILES\COMMON FILES\MICROSOFT SHARED\WINDOWS LIVE\WINDOWSLIVELOGIN.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6EEA3CF07EBD65C48A3FE380BC2FF61E --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2LZ.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\705BB738044DAE244B1B0019626BA989 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-SG\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\71767C89877A8C54292E76050A81603F --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-GB\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7D6437C5C6894A94F8CBB03BDF0023CE --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCL30.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7E15C61DF087B524BA7E9D78687034C8 --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-ZA\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\7F1D30D7D91CB71468487E54D083F466 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-US\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\91F31ECC41B96D243A45422551C96C23 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2ZIP.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\956B95676BE85A84DA3C38A66DE87EF4 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2RAR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A3F62FB51162E9444A6023B92E588C76 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-MY\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A485391124AB7B648B78A3FE779DF71C --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-IE\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A5F25478387645C4BA73C9515115754B --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-ID\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\A8DC89FAF3F52B3448C6E06B118C405E --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2AMG.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE832776AAB8D864DA9ADA65C87AD802 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-AU\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AE842139D531885469A1CDC35A26B1F4 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DECSDK.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AF92A9A71C3316044B7D1756CC86608A --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-NZ\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\B788EE3AF96C9D24EB1DC5ABABFCD3DD --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-IN\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BAEB54D195A6E4D42A9BCE5F94DCC60F --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-WW\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BB26CE3D008E2FA499FDEE6A7A5B9335 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2CAB.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\BE6AEA47C44CE854791235345CE87CE6 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2LHA.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1AC78A74A3296B4BA739BA5E5766344 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2SS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C1D015D543A678D4088D751CA77430A5 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2ARJ.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\D2EEB513BDC48C443B0FFC4606A08DFF --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2ID.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DB86CBDC6F0593649A6EAD6F6C9ECF66 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-ID\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DE6692E1170B7234EB5CFD71486A1C3F --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2GZIP.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\DF4FA19F558483F4F8E462F084BE6C6A --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-MY\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F258F648EAD8F594EBDCA471EBF04B29 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-GB\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F42B98E5315CA254F98CB0E739C7CEA1 --> 00000000000000000000000000000000 --> C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\DECOMPOSERS\DEC2.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F449218B608352B4D91EF2747ABC8609 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-ZA\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7785DDBB03FCAF49ADA245416F38EF9 --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-PH\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA554C3CF8B06F94E9E4AB88BC75D4DB --> A0C5E5D363B589F4997A82F7D7DBEC30 --> C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SKYPE\PLUGINS\IPXML.XML (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FA554C3CF8B06F94E9E4AB88BC75D4DB --> 00000000000000000000000000000000 --> C:\DOCUMENTS AND SETTINGS\ALL USERS\APPLICATION DATA\SKYPE\PLUGINS\IPXML.XML (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FB70A7D216B42EC49BD012B9D2E54534 --> 320C1B37094475A47A1E2F2086CEEB25 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\EN-NZ\MSN_SLRS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FC8D7A450BEF6664098C13458DBF4E5C --> 5365DED7C74BF0B4A90D78561DF59DF4 --> C:\PROGRAM FILES\WINDOWS LIVE TOOLBAR\COMPONENTS\EN-WW\MSNTABRES.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\DD14EBD2921256C43A3D657432A6063F\InstallProperties --> DisplayIcon --> C:\PROGRAM FILES\QUICKEN\QUICKEN.ICO (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components3706BE699FFAC54E8D7DDEF21B60CDE --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CAPOLMGR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components6974588BF55B71469B8A3AC82302BAB --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\SSLEAY32.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\1D74CE3AEFF56AE4B8A3B7BB325A5400 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CADAL.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\20ADCF8A960F7A048AE188EC7BDF775A --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CANET.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\29CEA8A7F9927324B936C770A0FCCE88 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CAUNINSTALL.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\331752FA4CA84194BA9F88C11567EE78 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CAWINSYS.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\3653017FA5F4248408D76923E34F521A --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CADNLMGR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\3AED3044E3C8E75419492A88AC51DE9A --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CASOAPV.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\4119CCBCE57E9CE4C9B82684FBCC68D7 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\VONGOSERVICE.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\54D4D48FE7FAD714DA6BB718451BD467 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\VONGOPORTABLE.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\5E38D2370CCA3D9458F3F6E404B5950D --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\VONGODIALOGBANNER.BMP (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\5E6A695AB93D68843B3A7F07CFCF3F48 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CASYSMGR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\637B701D8BF6BF747B4796A1B9A16AA5 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\TRAY.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\66D289AA5C497E543AF531C4E22A9F46 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CACMN.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\6B4687B1CA9D63545824D2C6FA41DDB6 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\VONGOPLAYER.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\785E9640D08874041A5002701193326A --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\QT-MT335.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\829A20E0C9F0B6E419B00C3A8A62CEF8 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\MSVCP71.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\883A7D602339AF34580C2CD8DAF6E4D5 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\LIBEAY32.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\99E170480F9DFCD48ABBCDD4786F875A --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CALIBMGR.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\B4A2F24EE75042B459D6553E134101C2 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\CALAUNCHER.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\CC4D3433E02B28842B321F9AE2974A97 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\VONGO.EXE (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\F1EF5086ACDC2B74AA041E1902611623 --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\SQLDRIVERS\QSQLITE.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-21-519459852-3855340036-3308542633-1003\Components\F68706DAED654BB4D86E03641CE4937B --> 9C00E7BDFED6A98418218D8F61414FA5 --> C:\PROGRAM FILES\VONGO\MSVCR71.DLL (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MetaFrame Presentation Server Web Client for Win32 --> UninstallString --> C:\PROGRA~1\CITRIX\ICAWEB32\UNINST.INF (Fixed Successfully)

Shared DLLs / Folders:
______________________

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\lanmanserver\Shares --> HPPhotosmart (Fixed Successfully)

Windows Fonts:
______________

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Amaze Bold (TrueType) --> C:\WINDOWS\FONTS\AMAZB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Amaze Italic (TrueType) --> C:\WINDOWS\FONTS\AMAZI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Amaze Normal (TrueType) --> C:\WINDOWS\FONTS\AMAZR___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bangle Bold (TrueType) --> C:\WINDOWS\FONTS\BANGB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bangle Italic (TrueType) --> C:\WINDOWS\FONTS\BANGI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bangle Normal (TrueType) --> C:\WINDOWS\FONTS\BANGN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bart Bold (TrueType) --> C:\WINDOWS\FONTS\BARTB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bart Italic (TrueType) --> C:\WINDOWS\FONTS\BARTI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bart Normal (TrueType) --> C:\WINDOWS\FONTS\BARTN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bimini Bold (TrueType) --> C:\WINDOWS\FONTS\BIMINB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bimini Italic (TrueType) --> C:\WINDOWS\FONTS\BIMINI__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Bimini Normal (TrueType) --> C:\WINDOWS\FONTS\BIMINR__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Chasm Bold (TrueType) --> C:\WINDOWS\FONTS\CHASB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Chasm Italic (TrueType) --> C:\WINDOWS\FONTS\CHASI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Chasm Normal (TrueType) --> C:\WINDOWS\FONTS\CHASN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Dolphin Bold (TrueType) --> C:\WINDOWS\FONTS\DOLPHB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Dolphin Italic (TrueType) --> C:\WINDOWS\FONTS\DOLPHI__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Dolphin Normal (TrueType) --> C:\WINDOWS\FONTS\DOLPHR__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Eurasia Bold (TrueType) --> C:\WINDOWS\FONTS\EURAB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Eurasia Italic (TrueType) --> C:\WINDOWS\FONTS\EURAI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Eurasia Normal (TrueType) --> C:\WINDOWS\FONTS\EURAN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Flat Brush Bold (TrueType) --> C:\WINDOWS\FONTS\FLATBB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Flat Brush Italic (TrueType) --> C:\WINDOWS\FONTS\FLATBI__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Flat Brush Normal (TrueType) --> C:\WINDOWS\FONTS\FLATBN__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Galant Bold (TrueType) --> C:\WINDOWS\FONTS\GALAB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Galant Italic (TrueType) --> C:\WINDOWS\FONTS\GALAI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Galant Normal (TrueType) --> C:\WINDOWS\FONTS\GALAN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Gaze Bold (TrueType) --> C:\WINDOWS\FONTS\GAZEB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Gaze Italic (TrueType) --> C:\WINDOWS\FONTS\GAZEI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Gaze Normal (TrueType) --> C:\WINDOWS\FONTS\GAZEN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Kelt Bold (TrueType) --> C:\WINDOWS\FONTS\KELTB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Kelt Italic (TrueType) --> C:\WINDOWS\FONTS\KELTI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Kelt Normal (TrueType) --> C:\WINDOWS\FONTS\KELTN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Liberate Bold (TrueType) --> C:\WINDOWS\FONTS\LIBEB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Liberate Normal (TrueType) --> C:\WINDOWS\FONTS\LIBEN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Lynda Cursive Bold (TrueType) --> C:\WINDOWS\FONTS\LYNDCB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Lynda Cursive Normal (TrueType) --> C:\WINDOWS\FONTS\LYNDCN__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Mirror Bold (TrueType) --> C:\WINDOWS\FONTS\MIRRB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Mirror Italic (TrueType) --> C:\WINDOWS\FONTS\MIRRI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Mirror Normal (TrueType) --> C:\WINDOWS\FONTS\MIRRN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Notes Normal (TrueType) --> C:\WINDOWS\FONTS\NOTESR__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Paris Bold (TrueType) --> C:\WINDOWS\FONTS\PARISB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Paris Italic (TrueType) --> C:\WINDOWS\FONTS\PARISI__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Paris Normal (TrueType) --> C:\WINDOWS\FONTS\PARISR__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Short Hand Bold (TrueType) --> C:\WINDOWS\FONTS\SHORHB__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Short Hand Italic (TrueType) --> C:\WINDOWS\FONTS\SHORHI__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Short Hand Normal (TrueType) --> C:\WINDOWS\FONTS\SHORHN__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Signs Normal (TrueType) --> C:\WINDOWS\FONTS\SIGNSR__.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Simpson Bold (TrueType) --> C:\WINDOWS\FONTS\SIMPB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Simpson Italic (TrueType) --> C:\WINDOWS\FONTS\SIMPI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Simpson Normal (TrueType) --> C:\WINDOWS\FONTS\SIMPN___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Surfer Bold (TrueType) --> C:\WINDOWS\FONTS\SURFB___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Surfer Italic (TrueType) --> C:\WINDOWS\FONTS\SURFI___.TTF (Fixed Successfully)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts --> Surfer Normal (TrueType) --> C:\WINDOWS\FONTS\SURFN___.TTF (Fixed Successfully)

Invalid File Associations:
__________________________

HKEY_CLASSES_ROOT\.java --> HKEY_CLASSES_ROOT\javafile (Fixed Successfully)
HKEY_CLASSES_ROOT\.obd --> HKEY_CLASSES_ROOT\Office.Binder.9\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.obt --> HKEY_CLASSES_ROOT\Office.Binder.Template.9\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.obz --> HKEY_CLASSES_ROOT\Office.Binder.Wizard.9\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.php3 --> HKEY_CLASSES_ROOT\php3file (Fixed Successfully)
HKEY_CLASSES_ROOT\.pl --> HKEY_CLASSES_ROOT\plfile (Fixed Successfully)
HKEY_CLASSES_ROOT\.sc2 --> HKEY_CLASSES_ROOT\SchedulePlus.Application.7\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.scd --> HKEY_CLASSES_ROOT\SchedulePlus.Application.7\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.sch --> HKEY_CLASSES_ROOT\SchedulePlus.Application.7\Shell\Open\Command --> Default --> Value Not Set (Fixed Successfully)
HKEY_CLASSES_ROOT\.sql --> HKEY_CLASSES_ROOT\sqlfile (Fixed Successfully)

Startup Programs:
_________________


Sound and AppEvents:
____________________


Add / RemovePrograms:
_____________________


Help Files:
___________


Application Paths / Temp Files / Shortcuts:
___________________________________________




File / Shell Extensions:
________________________

(Fixed Successfully)
(Fixed Successfully)
(Fixed Successfully)
(Fixed Successfully)

Full System Scan:
_________________
rridgely
I don't know what that program is as I've never used it but registry cleaners for the most part cause more problems then they fix.
CCleaner's issues scanner is the only registry cleaner I can say that I've found to be 99% safe or maybe even 100.

Try this scan which can be run on firefox:

Run TrendMicro™ HouseCall Java Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read the terms and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
  • Reboot the PC

Make sure you save the log of things found and post it with a new hijackthis log.
Agnes
QUOTE(rridgely @ Apr 24 2007, 11:31 AM) [snapback]69473[/snapback]
I don't know what that program is as I've never used it but registry cleaners for the most part cause more problems then they fix.
CCleaner's issues scanner is the only registry cleaner I can say that I've found to be 99% safe or maybe even 100.

Try this scan which can be run on firefox:

Run TrendMicro™ HouseCall Java Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read the terms and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
  • Reboot the PC
Make sure you save the log of things found and post it with a new hijackthis log.



here are the TREND MICRO detected vulnerabilities. I copied what was there.


Detected vulnerabilities

(MS07-017) Vulnerabilities in GDI Could Allow Remote Code Execution (925902)

Transfering more information about this vulnerability...
An error occured while trying to retrieve more information about this vulnerability. There is currently no more information available.
This release replaces the following security updates:

* MS05-002
* MS05-053
* MS06-001

It also addresses the Windows Animated Cursor Remote Code Execution vu...
More information about this vulnerability and its elimination.
Affected programs and services: Microsoft Windows 2000 Service Pack 2
Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Windows Vista
Microsoft Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Windows Vista x64 Edition
Malware exploiting this vulnerability: TROJ_ANICMOO.AX, EXPL_ANICMOO.GEN

This release replaces the following security updates:

* MS05-002
* MS05-053
* MS06-001

It also addresses the Windows Animated Cursor Remote Code Execution vulnerability (CVE-2007-0038), which is currently being exploited in the wild and discussed in the following advisory:

Microsoft Security Advisory 935423

The following malware exploit the Windows Animated Cursor Remote Code Execution vulnerability:

* EXPL_ANICMOO.GEN
* TROJ_ANICMOO.AX

More information about this vulnerability and its elimination.

(MS07-019) Vulnerability in Universal Plug and Play Could Allow Remote Code Execution (931261)

Transfering more information about this vulnerability...
An error occured while trying to retrieve more information about this vulnerability. There is currently no more information available.
This security bulletin resolves the following newly discovered vulnerability: UPnP Memory Corruption Vulnerability. A remote code execution vulnerability exists in the Universal Plug and Play ...
More information about this vulnerability and its elimination.
Affected programs and services: Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional x64 Edition Service Pack 2
Malware exploiting this vulnerability: unknown
This security bulletin resolves the following newly discovered vulnerability: UPnP Memory Corruption Vulnerability. A remote code execution vulnerability exists in the Universal Plug and Play (UPnP) service in the way that it handles specially crafted HTTP requests. These HTTP requests could only be sent directly to a target computer by a remote malicious user on the same subnet. The Windows XP firewall and the protocol enforce this subnet restriction.

A remote malicious user who successfully exploited this vulnerability could run arbitrary code in the context of the Local Service account and could not run code under the Local SYSTEM account.

More information about this vulnerability and its elimination.

(MS07-020) Vulnerability in Microsoft Agent Could Allow Remote Code Execution (932168)

Transfering more information about this vulnerability...
An error occured while trying to retrieve more information about this vulnerability. There is currently no more information available.
This release addresses the remote code execution vulnerability in the way specially-crafted URLs are handled by Microsoft Agent, a software technology used in Microsoft applic...
More information about this vulnerability and its elimination.
Affected programs and services: Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003
Microsoft Windows XP Service Pack 2
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Microsoft Windows Server 2003 x64 Edition Service Pack 1
Malware exploiting this vulnerability: unknown
This release addresses the remote code execution vulnerability in the way specially-crafted URLs are handled by Microsoft Agent, a software technology used in Microsoft applications that enables the use of animated characters in making computer education easier and more interactive.

Successful exploitation of this vulnerability allows a remote malicious user to take control of an affected system. However, a user would still have to click a link for an attack to become successful.

Running Windows Internet Explorer 7 mitigates this vulnerability. Windows Vista is likewise unaffected.
More information about this vulnerability and its elimination.

(MS07-021) Vulnerabilities in CSRSS Could Allow Remote Code Execution (930178)

Transfering more information about this vulnerability...
An error occured while trying to retrieve more information about this vulnerability. There is currently no more information available.
This security bulletin resolves the following newly discovered vulnerabilities affecting Windows Client/Server Run-time Subsystem (CSRSS):

* ...

More information about this vulnerability and its elimination.
Affected programs and services: Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003
Microsoft Windows XP Service Pack 2
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Windows Vista
Microsoft Windows XP Professional x64 Edition Service Pack 2
Microsoft Windows Server 2003 Service Pack 2
Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition Service Pack 2
Windows Vista x64 Edition
Malware exploiting this vulnerability: unknown
This security bulletin resolves the following newly discovered vulnerabilities affecting Windows Client/Server Run-time Subsystem (CSRSS):

* MsgBox (CSRSS) Remote Code Execution Vulnerability (CVE-2006-6696) - A remote code execution vulnerability exists in the Windows Client/Server Run-time Subsystem (CSRSS) process because of the way that it handles error messages. A remote malicious user could exploit the vulnerability by constructing a specially crafted application that could potentially allow remote code execution.

Additionally, if a user viewed a specially crafted Web site, a remote malicious user who successfully exploited this vulnerability could take complete control of an affected system.

In a local attack scenario, a remote malicious user must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.

In a Web-based attack scenario, a remote malicious user would have to host a Web site that contains a Web page that is used to exploit this vulnerability. A remote malicious user would have no way to force users to visit a specially crafted Web site. Instead, a remote malicious user would have to convince them to visit the Web site, typically by getting them to click a link that takes them to the attacker's Web site. After they click the link, they would be prompted to perform several actions. An attack could only occur after they performed these actions.

* CSRSS Local Elevation of Privilege Vulnerability (CVE-2007-1209) - A privilege elevation vulnerability exists in the way that the Windows 32 Client/Server Run-time Subsystem (CSRSS) handles its connections during the startup and stopping of processes.

A remote malicious user must have valid logon credentials and be able to log on locally to exploit this vulnerability. The vulnerability could not be exploited remotely or by anonymous users.

A remote malicious user who successfully exploited this vulnerability could take complete control of an affected system. A remote malicious user could then install programs; view, change, or delete data; or create new accounts with full user rights.

* CSRSS DoS Vulnerability (CVE-2006-6797) - A denial of service vulnerability exists in the Client/Server Run-time Subsystem (CSRSS) service because of the way it handles error messages. A remote malicious user who exploited this vulnerability could cause the affected system to stop responding and automatically restart. Note that the denial of service vulnerability would not allow a remote malicious user to run code or to elevate their user rights, but it could cause the affected system to stop accepting requests.

More information about this vulnerability and its elimination.

(MS07-022) Vulnerability in Windows Kernel Could Allow Elevation of Privilege (931784)

Transfering more information about this vulnerability...
An error occured while trying to retrieve more information about this vulnerability. There is currently no more information available.
This release replaces the security update MS06-049 which affects Microsoft Windows 2000 Service Pack 4. A vulnerability in Windows Kernel due to incorrect permissions on a mapped memory segment may allow a malic...
More information about this vulnerability and its elimination.
Affected programs and services: Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003
Microsoft Windows XP Service Pack 2
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 Service Pack 2
Malware exploiting this vulnerability: unknown
This release replaces the security update MS06-049 which affects Microsoft Windows 2000 Service Pack 4.

A vulnerability in Windows Kernel due to incorrect permissions on a mapped memory segment may allow a malicious user to take control of an affected system. However, this vulnerability cannot be exploited remotely via the Internet or by users with invalid logon credentials. A malicious user must first log on to the system and then run a program to successfully exploit the said vulnerability.
More information about this vulnerability and its elimination.
Agnes
QUOTE(rridgely @ Apr 24 2007, 11:31 AM) [snapback]69473[/snapback]
I don't know what that program is as I've never used it but registry cleaners for the most part cause more problems then they fix.
CCleaner's issues scanner is the only registry cleaner I can say that I've found to be 99% safe or maybe even 100.

Try this scan which can be run on firefox:

Run TrendMicro™ HouseCall Java Scan
  • Please go HERE to run the Trend Micro™ HouseCall Scan.
  • Click Scan now. It's free!
  • Read the terms and put a Check next to Yes I accept the terms of use.
  • Click the Launching HouseCall>> button.
  • If confirmed that HouseCall can run on your system, under Using Java-based HouseCall kernel click the Starting HouseCall>> button.
  • You may receive a Security Warning about the TrendMicro Java applet, click YES.
  • Under Scan complete computer for malware, grayware, and vulnerabilities click the Next>> button.
  • Please be patient while it installs, updates, and scans your system.
  • Once the scan is complete, it will take you to the summary page.
  • Under Cleanup options, choose clean all detected infections automatically.
  • Click the Clean now>> button.
  • If anything was found you may be prompted to run the scan again, you can just close the browser window.
  • Reboot the PC
Make sure you save the log of things found and post it with a new hijackthis log.



HJT

Logfile of HijackThis v1.99.1
Scan saved at 6:42:49 PM, on 4/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Eset\nod32kui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\WINDOWS\system32\DVDRAMSV.exe
C:\Program Files\Eset\nod32krn.exe
C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Documents and Settings\Owner\Desktop\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://gportal.hu/portal/floridawithus/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.3.19.dll
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKLM\..\Run: [Outpost Firewall] "C:\Program Files\Agnitum\Outpost Firewall\outpost.exe" /waitservice
O4 - HKLM\..\Run: [OutpostFeedBack] C:\Program Files\Agnitum\Outpost Firewall\feedback.exe /dump:os_startup
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [HijackThis startup scan] "C:\Documents and Settings\Owner\Desktop\HijackThis.exe" /startupscan
O8 - Extra context menu item: &eBay Search - res://C:\Downloads\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Download all links using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: Download all videos using BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: Download link using &BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?fa67b106f7c9401faa0c7b1e01ffa992
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?fa67b106f7c9401faa0c7b1e01ffa992
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Web Anti-Virus - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\WINDOWS\system32\shdocvw.dll
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\Program Files\Agnitum\Outpost Firewall\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} - http://csmagi.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} - http://security.symantec.com/sscv6/SharedC...n/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1156106971828
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} - http://messenger.zone.msn.com/binary/Messe...nt.cab31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} - http://a248.e.akamai.net/f/248/5462/2h/www...ol/SymDlBrg.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} - http://messenger.zone.msn.com/binary/Solit...wn.cab31267.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: DVD-RAM_Service - Matsushita Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Outpost Firewall Service (OutpostFirewall) - Agnitum Ltd. - C:\Program Files\Agnitum\Outpost Firewall\outpost.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
rridgely
How does your computer seem?
Please try surfing around google for a few minutes with internet explorer and see if it works.
Agnes
QUOTE(rridgely @ Apr 24 2007, 06:46 PM) [snapback]69497[/snapback]
How does your computer seem?
Please try surfing around google for a few minutes with internet explorer and see if it works.



Hi!
At this time I dont have Internet Explorer. But the other things works good. The blue screen disppeared after the last scanning and correcting. Thank you.
I`m going to download the IE, because some programs working just with that.
So, now my (I hope) only problem is my thicker start - bar. And when I open the start menu, the buttons are bigger then they was. Look:

rridgely
What do you mean you don't have internet explorer? Did you use some sort of tool to uninstall it?
You cannot completely uninstall Internet explorer.(plus I see it in your start menu..)

Your start bar is bigger because its not locked and your icons just look bigger. Have you been messing with your display settings?

Agnes
QUOTE(rridgely @ Apr 24 2007, 09:32 PM) [snapback]69515[/snapback]
What do you mean you don't have internet explorer? Did you use some sort of tool to uninstall it?
You cannot completely uninstall Internet explorer.(plus I see it in your start menu..)

Your start bar is bigger because its not locked and your icons just look bigger. Have you been messing with your display settings?



Huhhhh. I thought I didn`t have. Yes I uninstalled, I dont know how..
But now I have. It works, when I am surfing, great, but I still cannot do a scan with Panda, or Kaspersky. Why don`t they start?

I tried to lock the taskbar, but they are the same size.

Display settings? The blue screen? I mentioned, it disappeared smile.gif
Agnes
QUOTE(rridgely @ Apr 24 2007, 09:32 PM) [snapback]69515[/snapback]
What do you mean you don't have internet explorer? Did you use some sort of tool to uninstall it?
You cannot completely uninstall Internet explorer.(plus I see it in your start menu..)

Your start bar is bigger because its not locked and your icons just look bigger. Have you been messing with your display settings?



So.....
I found an example

it was like this :

and if you see the 2 pictures in their original size. Now it is bigger than it was sad.gif

rridgely
Oh ok so you just needed to drag it down. Glad its fixed.
Your sure that you weren't messing with font sizes or screen resolution or anything like that while trying to fix your start menu?

So your not getting any pop ups or anything like that right?
Lets run this and see if anything turns up:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.
Agnes
QUOTE(rridgely @ Apr 24 2007, 10:08 PM) [snapback]69518[/snapback]
Oh ok so you just needed to drag it down. Glad its fixed.
Your sure that you weren't messing with font sizes or screen resolution or anything like that while trying to fix your start menu?

So your not getting any pop ups or anything like that right?
Lets run this and see if anything turns up:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.



FND24.NFI;C:\Program Files\ESET\cache;Trojan.DownLoader.20865;Deleted.;
FND25.NFI\data002;C:\Program Files\ESET\cache\FND25.NFI;Probably WIN.IRC.WORM.Virus;;
FND25.NFI;C:\Program Files\ESET\cache;Archive contains infected objects;Moved.;
R1AJ0BCA.NQF\data002;C:\Program Files\ESET\infected\R1AJ0BCA.NQF;Probably WIN.IRC.WORM.Virus;;
R1AJ0BCA.NQF;C:\Program Files\ESET\infected;Archive contains infected objects;Moved.;

Agnes
QUOTE(rridgely @ Apr 24 2007, 10:08 PM) [snapback]69518[/snapback]
Oh ok so you just needed to drag it down. Glad its fixed.
Your sure that you weren't messing with font sizes or screen resolution or anything like that while trying to fix your start menu?

So your not getting any pop ups or anything like that right?
Lets run this and see if anything turns up:

* Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
  • Doubleclick the drweb-cureit.exe file and Allow to run the express scan
  • This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
  • Once the short scan has finished, mark the drives that you want to scan.
  • Select all drives. A red dot shows which drives have been chosen.
  • Click the green arrow at the right, and the scan will start.
  • Click 'Yes to all' if it asks if you want to cure/move the file.
  • When the scan has finished, in the menu, click file and choose save report list
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Close Dr.Web Cureit.
  • Reboot your computer!! Because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web you saved previously in your next reply.


What do you think I have to do now? Should I uninstall the NOD32? I got this virus (?) from the nod 32`s folder sad.gif . somehow.
Should I use Avast again?
rridgely
No those files were found in Nods quarantine. Don't worry about.(nod is better than avast anyway)
I think your computer should be pretty clean now.

What kind of problems are you still having?
Agnes
QUOTE(rridgely @ Apr 25 2007, 07:14 PM) [snapback]69614[/snapback]
No those files were found in Nods quarantine. Don't worry about.(nod is better than avast anyway)
I think your computer should be pretty clean now.

What kind of problems are you still having?


you think that ? smile.gif that would be great.
Problems? IE doesn`t work in some situations , like you know panda scanning. And the start bar is still thicker. that`s it. For surfing, it`s great now.
thank you so much for your helping. I couldn`t have done it without you...
rridgely
Its probably something to do with your active x settings. If everything seems to be working fine then you should be ok.
Nod is a good program so you should be pretty clean. smile.gif
Agnes
QUOTE(rridgely @ Apr 26 2007, 07:25 PM) [snapback]69660[/snapback]
Its probably something to do with your active x settings. If everything seems to be working fine then you should be ok.
Nod is a good program so you should be pretty clean. smile.gif


I did it! It was in the Display Properties/Appearence/Advance. Just change the active bar settings. I should have done this before rolleyes.gif

Thank you again! smile.gif
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.