PDA

View Full Version : I have the problem too...



triplenine
2007-05-24, 07:55
Dealing with smitfraud-c toolbar.888 mainly but getting win32.agent.AT showing up in Spybot. Trend Micro notifications popup warning of different Trojans as well. Ran Vundofix, SDfix, and Combofix and still getting instances. The system is running well but still got the TM Notifiers. Here is the Hijack this log for my system:

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 11:39:17 PM, on 5/23/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Altdesk\AltDesk.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\lab\CLEANUP\HiJackThis_v2.exe

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0060921
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=ZLr2sEKrAdA7GyLYEidhK5jJmps
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.4.29.dll
O2 - BHO: (no name) - {3C805603-134A-42BF-B370-A7736A145967} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {489263D0-1E71-4B29-B4D1-46DAA5856DF7} - c:\windows\security\database\libanti.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - C:\WINDOWS\system32\gebawwv.dll (file missing)
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\Altdesk\AltDesk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O20 - Winlogon Notify: winzlo32 - winzlo32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9939 bytes


Let me know what you think.
-999

pskelley
2007-05-25, 15:01
Welcome to Safer Networking, I wish to be sure you have viewed and understand this information.
"BEFORE you POST" (READ this Procedure before Requesting Assistance)
http://forums.spybot.info/showthread.php?t=288
All advice given is taken at your own risk.

Since I see no required scan results, I think you should read the above instructions so we are on the same bage. You had a Vundo infection and without seeing the Vundofix results, since much of the infection is hidden, I can't comment on if you removed it or not. I can show you this:
http://forums.spybot.info/showthread.php?t=8668 If Spybot is up to date and totally immunized, you can ignore that false positive.

Please see this: http://forums.spybot.info/showpost.php?p=12880&postcount=2
C:\Program Files\Java\jre1.5.0_06\ <<< Java is out of date, download the newest version and uninstall ALL old versions in Add Remove programs.

Do you know what this is?
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=...yLYEidhK5jJmps

Let's do some cleanup and see what happens:

1) Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

2) AVG Anti-Spyware: Deactivate the Resident Shield
- Before proceeding, deactivate the "Resident Shield" as this may prevent changes to the registry.
- To do this, click "Change State" to the right of the Resident Shield option in the main window.
- You will clearly see the status change to Inactive if you have done this correctly.

3) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

(first R0 you can leave if you set your startpage to "blank"

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: (no name) - {3C805603-134A-42BF-B370-A7736A145967} - C:\WINDOWS\system32\geedc.dll (file missing)
O2 - BHO: PsapiAnalyzer Object - {489263D0-1E71-4B29-B4D1-46DAA5856DF7} - c:\windows\security\database\libanti.dll (file missing)
O2 - BHO: (no name) - {9A853E36-4A35-4DBF-9C03-AD9423798E35} - C:\WINDOWS\system32\gebawwv.dll (file missing)
O20 - Winlogon Notify: winzlo32 - winzlo32.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

4) Use the instructions in the following link to run AVG Anti-Spyware, delete or quarantine anything it finds and post the scan report.
http://forums.security-central.us/showthread.php?t=3165


5) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart the computer and post that scan report, a new HJT log, any information I requested, and any comments you think will help.

Thanks

triplenine
2007-05-25, 18:54
Thanks for the response. I did most of that after I posted originally. I will run ATF cleaner and see what happens. I will post again this evening after work, but I think that I am close to the point where I am getting the Spybot hits are false. Great forum by the way. I got most of this taken care of by reading the other posts.
-999

triplenine
2007-05-25, 20:23
OK here we go...

I deleted the "missing files"

I also deleted: R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://127.0.0.1:4664/first_usage&s=...yLYEidhK5jJmps - the computer didn't explode so - cool.

OK here is the most recent AVG report:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:53:21 AM 5/25/2007

+ Scan result:



:mozilla.206:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.207:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.208:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.209:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.210:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.211:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.212:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.213:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.214:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.215:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.216:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.217:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.218:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.219:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.220:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.221:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.222:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.223:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.224:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.225:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.226:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.227:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.228:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.229:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.230:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.231:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.232:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.233:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.234:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.235:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.236:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.237:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.238:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.239:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.240:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.241:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.242:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.294:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.373:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.404:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.440:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.443:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.475:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.594:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.385:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.386:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.387:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.93:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.95:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.96:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.97:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.172:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.

triplenine
2007-05-25, 20:24
:mozilla.173:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.47:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.48:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.49:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.50:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.52:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.425:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.119:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.120:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.121:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.122:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.123:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.124:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.125:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.777:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.454:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.455:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.456:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.457:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.51:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.467:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.468:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.391:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.392:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.393:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.394:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.144:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.145:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.204:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.150:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.56:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.57:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.58:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.79:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.80:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.829:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.152:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Intelli-direct : Cleaned.
:mozilla.823:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.824:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.64:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.28:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.29:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.31:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.32:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.186:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.262:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.263:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.264:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.265:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.266:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.658:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.659:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.660:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.275:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.277:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.278:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.279:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.675:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.676:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.677:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.678:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.679:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.680:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.354:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.359:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.360:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.361:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.362:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.130:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.131:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.132:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.133:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.134:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.135:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.136:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.137:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.138:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.139:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.140:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.141:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.142:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.82:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.83:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.84:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.85:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.86:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.87:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.88:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.365:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Safer-networking : Cleaned.
:mozilla.302:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.303:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.304:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.305:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.306:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.307:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.254:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.255:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.256:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.257:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.258:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.259:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.260:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.261:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.267:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.268:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.243:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.244:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.245:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.246:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.247:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.252:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.253:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.102:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.103:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.104:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.105:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.106:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.107:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.108:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.109:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.110:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.73:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.74:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.807:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.286:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.773:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.

triplenine
2007-05-25, 20:24
:mozilla.71:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.72:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.75:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.76:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.115:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.116:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.117:C:\Documents and Settings\Chris\Application Data\Mozilla\Firefox\Profiles\tnbhsu3k.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\winzlo32.dll.vir -> Trojan.Dialer.qn : Cleaned.


::Report end

triplenine
2007-05-25, 20:25
And the most recent HJT:
C:\PROGRA~1\TRENDM~1\INTERN~1\PccVScan.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\lab\CLEANUP\VundoFix.exe
C:\lab\CLEANUP\triplenine.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0060921
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.4.29.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\Altdesk\AltDesk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O20 - Winlogon Notify: winzlo32 - winzlo32.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9616 bytes

I highlighted the entries in bold that I am concerned about. Let me know what you think. I might run Vundofix again for laughs to see what happens.

triplenine
2007-05-25, 20:31
OK, the HJT entries that I was concerned about were nothing...just system files.
I cleared the winligin entry that I missed.

If you see anything glaring let me know, I really appreciate the help.
-999

pskelley
2007-05-25, 20:41
No need to store all of those junk cookies like that:
http://mozilla.gunnars.net/firefox_help_firefox_cookie_tutorial.html
http://privacy.getnetwise.org/browsing/tools/firefox1/ffdisablecookies
http://www.mozilla.org/projects/security/pki/psm/help_21/using_priv_help.html

Post a complete HJT log, you cut that one off.

Thanks

triplenine
2007-05-29, 20:08
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 12:07:22 PM, on 5/29/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PccGuide.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Creative\Mixer\CTSVolFE.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Winamp\winampa.exe
C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Altdesk\AltDesk.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.exe
C:\Program Files\OpenOffice.org 2.1\program\soffice.BIN
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Thunderbird\thunderbird.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\lab\CLEANUP\triplenine.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0060921
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.4.29.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [CTSVolFE.exe] "C:\Program Files\Creative\Mixer\CTSVolFE.exe" /r
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AltDesk] C:\Program Files\Altdesk\AltDesk.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - Startup: OpenOffice.org 2.1.lnk = C:\Program Files\OpenOffice.org 2.1\program\quickstart.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SsBeSvc.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9598 bytes

pskelley
2007-05-29, 20:22
Thanks for the complete HJT log, I would use HJT to remove this item:
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
http://www.trendmicro.com/vinfo/grayware/ve_graywareDetails.asp?GNAME=ADW%5FPOP%2EA
Trend Micro says it is adware.

I suggest you clean your System Restore files to be sure:
System Restore does not know the good files from the bad. In case bad stuff has gotten into your System Restore files, follow the instructions in this link to get clean System Restore files. Turn it off, reboot then turn it back on:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?Open&src=sec_doc_nam

AVG Anti-Spyware is a good program but it does use some resources. Once the trial is over you can update and use the scanner for as long as you wish, but unless you purchase it you should turn it off completely so it does not run unless you start it manually.

Some good information for you:
http://users.telenet.be/bluepatchy/miekiemoes/slowcomputer.html
http://users.telenet.be/bluepatchy/miekiemoes/prevention.html

If you have questions about Spybot, you may post them here:
http://forums.spybot.info/forumdisplay.php?f=4 where Spybot
experts will be glad to advise you.

Here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.spybot.info/showthread.php?t=279
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html
http://cybercoyote.org/security/not-admin.shtml

Thanks...pskelley
Safer Networking Forums
http://www.spybot.info/en/donate/index.html
If you are reading this information...thank a teacher,
If you are reading it in English...thank a soldier.

tashi
2007-06-05, 01:56
Glad we could help, as the problem appears to be resolved this topic has been archived.

If you need it re-opened, please send me a private message (pm) and provide a link to the thread. Applies only to the original poster, anyone else with similar problems please start a new topic.