Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
My system apparently has been attacked by the "iworm_attck_v122.02a" virus. At first, I only had problems starting Internet Explorer (a problem I continue to have). Next, I developed problems with Windows Installer. Every time I reboot the system it tries to install Norton Antivirus 2005, but fails (Antivirus is already installed on the system and appears to be running correctly). I then developed problems with spyware programs. At first, it was a program called SpyFalcon. I thought I managed to remove the program, but now I'm bombarded with pop-up messages that state "Your computer is infected with last version of internet trojan 'iworm_attck_v122.02a'. It is highly recommended that you install antivirus software. Click the icon for more information." I know that if I click onto the icon, additional spyware will be loaded so I haven't taken the bait. However, my Norton Antivirus has not been able to remove the virus and I don't know what steps to take next. Any help would be appreciated.
Help with "iworm_attck_v122.02a"

Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. You can download Hijack This at this link http://www.tomcoyote.org/hjt/ then place it into a folder of it's on, such as C:\HJT, so that back up copies can be made and not clutter your desktop or other folders and the backup copies of deleted items can be easily located if needed.
Once saved double click HijackThis.exe, and press "Scan". When the scan is finished, the "Scan" button will change into a "Save Log" button.
Press that, save the log, Ctrl-A to Select All, and copy its contents into the text editor at this forum.Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

jabuck,
Thanks for the help.
Gary
Here is the log:
Logfile of HijackThis v1.99.1
Scan saved at 8:56:44 PM, on 3/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\LMSXXD.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HJT\hijackthis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp3162.tmp
O2 - BHO: Norton Personal Firewall 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Personal Firewall 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: SecurityToolbar - {736b5468-bdad-41be-92d0-22ae2ddf7bcb} - C:\Program Files\Security Toolbar\Security Toolbar.dll
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [LMSXXD] LMSXXD.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123098797941
O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} (InstallShield Update Service Setup Player) - http://updates.installshield.com/CAB/dwusplay.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?326
O18 - Protocol: bw+0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {9FEFEE98-76AF-45D3-8645-5AE31204E719} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exeHelp with "iworm_attck_v122.02a"

Please download smitRem.zip and save it to your desktop from this link http://noahdfear.geekstogo.com/smitRem.exe
Open the file and it will extract itself to a new folder called SmitRem.
Reboot into safe mode by following the directions Here.
Open the smitRem folder, then double click the RunThis.bat file to start the tool. Follow the prompts on screen. Your desktop and icons will disappear and then reappear again, this is normal.
Wait for the tool to complete and Disk Cleanup to finish, this may take a while; please be patient.Next go to Start > Control Panel > click Display > Desktop > Customize Desktop > Web > Uncheck "Security Info" if present.
While still in safe mode run Hijack This again, close all windows and browsers except HT, place a check to the left of the following items and press "fix checked":
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
O2 - BHO: HomepageBHO - {4da4616d-7e6e-4fd9-a2d5-b6c535733e22} - C:\WINDOWS\system32\hp3162.tmp
O3 - Toolbar: Viewpoint Toolbar - {F8AD5AA5-D966-4667-9DAF-2561D68B2012} - C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll
O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file)
O8 - Extra context menu item: &Viewpoint Search - res://C:\Program Files\Viewpoint\Viewpoint Toolbar V35\ViewBar.dll/CXTSEARCH.HTML
All of the 018"s
Set up the computer to view hidden files by going to start>control panel>folder options>view tab>tick the circle beside "show hidden files and folders" and untick the box beside "hide extensions of known file types" and "hide protected system operating files">apply>ok.
Navigate to and delte these files/folders if found:
C:\WINDOWS\system32\mssearchnet.exe
C:\WINDOWS\system32\nvctrl.exe
Run this free online scan from Panda
When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to the desktop, then copy/paste into the text editor and post it.
Please download this cleaner and run it in safe mode
http://www.atribune.org/content/view/19/2/ by Atribune.
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select AllDownload Ewido Security Suite then set it up this way Ewido Setup Instructions reboot into safe mode run Ewido
When the scan has completed, Ewido will create a report.txt file. Click the "Save Report" button on the bottom of the screen and save the log to your desktop.
Please reboot into normal mode and post the ewido log.
Click the Empty Selected button.

jback,
I've followed the steps you've detailed. Attached is the Panda Report (there seems to be multiple problems) and I'm now going to run ATF-Cleaner and Ewido.
Thanks again for your help.
Gary
Panda Log
Incident Status LocationAdware:adware/exact.bargainbuddy Not disinfected C:\WINDOWS\SYSTEM32\exclean.exe
Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\SYSTEM32\paytime.exe
Adware:adware/powerscan Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.exe
Adware:adware/secure32 Not disinfected C:\WINDOWS\secure.html
Adware:adware/pesttrap Not disinfected C:\WINDOWS\soft.exe
Adware:adware/wupd Not disinfected C:\PROGRAM FILES\Media Access
Adware:adware/ist.istbar Not disinfected C:\PROGRAM FILES\COMMON FILES\Totem Shared
Adware:adware/cws Not disinfected C:\Documents and Settings\Gary\Favorites\Insurance
Adware:adware/dyfuca Not disinfected Windows Registry
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CLASSES_ROOT\Interface\{c380566d-f343-42ab-987b-6b38a1a35747}
Adware:adware/ncase Not disinfected Windows Registry
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Microsofte Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.microsofteup.112.2o7.net/]
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.2o7.net/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Yadro Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.yadro.ru/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Seeq Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.www48.seeq.com/]
Spyware:Cookie/HotLog Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hotlog.ru/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/Bilbo.counted Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bilbo.counted.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.hc2.humanclick.com/hc/7065837]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/go Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.go.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.centrport.net/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.com.com/]
Spyware:Cookie/Bs.serving-sys Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/LPneimanmarcus]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/8495858]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/79635536]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/71075664]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/46950671]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.server.iad.liveperson.net/hc/24631554]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.did-it.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.belnk.com/]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip[Doome.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-47f46a86-7e161ca1.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-5caac6df-4d54680d.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\count3.jar-3d85b97e-271361a5.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\loaderadv441.jar-18af2898-49cd06f3.zip[Matrix.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\loaderadv441.jar-18af2898-49cd06f3.zip[Dummy.class]
Virus:Exploit/ByteVerify Not disinfected C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\menu.jr-c78a21d-45472b9f.zip[Dummy.class]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[7065837]
Spyware:Cookie/24/7 Realmedia Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[LPneimanmarcus]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[8495858]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[79635536]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[71075664]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[46950671]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[24631554]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\smitRem.exe[Process.exe]
Help with "iworm_attck_v122.02a"

jback,
Below is the Ewido Log. In your previous response, the last instruction said to "click the Empty Selected button" after rebooting in normal mode and posting the Ewido log. What did you mean by the "Empty Selected button"?
Thanks again.
Gary
Ewido Log
ewido anti-malware - Scan report
+ Created on: 2:32:47 PM, 3/14/2006
+ Report-Checksum: CC73B205+ Scan result:
HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Adware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Media Access -> Adware.WinAD : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Adware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue -> Adware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-241690110-3660279054-1395811753-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4DA4616D-7E6E-4FD9-A2D5-B6C535733E22} -> Adware.Generic : Cleaned with backup
HKU\S-1-5-21-241690110-3660279054-1395811753-1005\Software\Microsoft\Windows\CurrentVersion\Policies\AMeOpt -> Adware.InternetOptimizer : Cleaned with backup
C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip/Gagaga.class -> Dropper.Beyond.g : Cleaned with backup
C:\Documents and Settings\Gary\.jpi_cache\jar\1.0\archive.jar-13e1f81d-2d757f29.zip/Vbagx.class -> Not-A-Virus.Exploit.Java.Bytverify : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.76:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.195:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.196:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.254:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.255:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.315:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.318:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.319:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.324:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.334:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.349:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.356:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.385:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Counted : Cleaned with backup
:mozilla.404:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.405:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.406:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.420:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.421:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.447:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.528:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.529:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.530:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.532:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.533:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.593:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.607:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.608:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.628:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.639:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.640:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.651:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.661:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.689:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.692:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.701:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.705:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.726:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.727:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.728:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.729:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.744:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.745:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.746:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.747:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.748:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.749:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.750:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.751:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.752:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.753:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.754:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.756:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.769:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.770:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.771:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.772:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.773:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.774:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.775:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.776:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.777:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned with backup
:mozilla.787:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.811:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.812:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.813:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.814:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.815:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.816:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.817:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.818:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.819:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.820:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.821:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.822:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.823:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.833:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.834:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.835:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.836:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.837:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.838:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.839:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.840:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.841:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.842:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.904:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.913:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.923:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.924:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.925:C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Gary\Gary Non LLC Folders\TXT Files\gary richman@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Gary\Gary Non LLC Folders\TXT Files\gary richman@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Guest\Cookies\guest@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Karina\Cookies\karina@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\LLC Guest\Cookies\llc guest@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@estat[1].txt -> TrackingCookie.Estat : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@weborama[1].txt -> TrackingCookie.Weborama : Cleaned with backup
C:\Documents and Settings\Rose\Cookies\rose@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.127:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.140:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.147:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.152:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.153:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.168:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.178:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.179:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.180:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.181:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.197:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.256:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.268:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.277:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned with backup
:mozilla.284:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.286:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup
:mozilla.288:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.299:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.301:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.304:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.305:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.310:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.313:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.317:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.327:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.328:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.335:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup
:mozilla.338:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.340:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Linksynergy : Cleaned with backup
:mozilla.357:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.358:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.359:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.365:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.366:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.380:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.387:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.402:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.408:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.409:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.416:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.433:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.434:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.439:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.468:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.469:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.470:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.471:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.473:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.474:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.478:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.479:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.480:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.481:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.482:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.483:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.484:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.485:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.486:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.487:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.488:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.496:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.502:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.509:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Bfast : Cleaned with backup
:mozilla.530:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.531:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.535:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.536:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Clickagents : Cleaned with backup
:mozilla.537:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.538:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.539:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.540:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.541:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.544:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned with backup
:mozilla.551:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.554:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.557:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.561:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.562:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.563:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned with backup
:mozilla.574:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned with backup
:mozilla.578:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.583:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.585:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificpop : Cleaned with backup
:mozilla.586:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.587:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.606:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.607:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.610:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.613:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.614:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.615:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.617:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.618:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.619:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.620:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.621:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.622:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.623:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.625:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.626:C:\Documents and Settings\Sasha\Application Data\Mozilla\Firefox\Profiles\e5jvbzpt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ads.specificpop[1].txt -> TrackingCookie.Specificpop : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@centrport[2].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@clickagents[1].txt -> TrackingCookie.Clickagents : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@com[2].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@e-2dj6wfkowhc5kap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-adidasus.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-officeworld.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-researchinmotion.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@ehg-spafinder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@linksynergy[2].txt -> TrackingCookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@marthastewart.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@phg.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@revenue[1].txt -> TrackingCookie.Revenue : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@test.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@valuead[1].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@valueclick[2].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@y-1shz2prbmdj6wvny-1sez2pra2dj6wjloapdpolqq6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Sasha\Cookies\sasha@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Program Files\Media Access -> Adware.MediaAccess : Cleaned with backup
:mozilla.25:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.30:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.33:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.34:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.35:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.36:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.37:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.38:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.39:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.40:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.41:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.42:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.43:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.44:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.51:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.56:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.57:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.84:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.147:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Yadro : Cleaned with backup
:mozilla.163:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.164:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.169:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.192:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.222:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.223:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.246:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.266:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.267:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.286:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.288:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.289:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.290:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.295:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Casinotropez : Cleaned with backup
:mozilla.305:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.320:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Hotlog : Cleaned with backup
:mozilla.327:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.328:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.356:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Counted : Cleaned with backup
:mozilla.375:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.376:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.377:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.378:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.247realmedia : Cleaned with backup
:mozilla.391:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Pro-market : Cleaned with backup
:mozilla.392:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.393:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.394:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.395:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.396:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.418:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.447:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.448:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.449:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.450:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.451:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.479:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.480:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.501:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.502:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.503:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.504:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.505:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.506:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.566:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Centrport : Cleaned with backup
:mozilla.579:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Com : Cleaned with backup
:mozilla.580:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Com : Cleaned with backup
:mozilla.581:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Com : Cleaned with backup
:mozilla.589:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.601:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.612:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.613:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Aavalue : Cleaned with backup
:mozilla.624:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.634:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.662:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Bridgetrack : Cleaned with backup
:mozilla.665:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Valueclick : Cleaned with backup
:mozilla.674:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Bluestreak : Cleaned with backup
:mozilla.678:C:\RECYCLER\NPROTECT\00818336.MOZ -> TrackingCookie.Euroclick : Clean

jabuck,
I just realized that in my previous two posts, I accidentally misspelled your user name. Please accept my apologies. I appreciate all your assistance.
grichman
Help with "iworm_attck_v122.02a"

Reboot into safe mode and navigate to these files and delete them:
C:\WINDOWS\SYSTEM32\exclean.exe
C:\WINDOWS\SYSTEM32\paytime.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.exe
C:\WINDOWS\secure.html
C:\WINDOWS\soft.exe
C:\PROGRAM FILES\Media Access (delete folder)
C:\PROGRAM FILES\COMMON FILES\Totem Shared (delete the contents of this folder)
Post the ewido scan after you run ATF-Cleaner.
Clear the jave cache, directions at this link http://www.java.com/en/download/help/cache_virus.xml
Run Panda and post log
You will need to updtae your java if you have not done so.If you do not have a high speed connction wait until you get ready for bed tonight, it takes a while.You can download v1.5.0 from this link http://java.com/en/download/download_the_latest.jsp

The "empty" was an error in my coping from MY "my documents".
Looks like one of my post have be lost
Reboot into safe mode then navigate to and delete these files/folders:
C:\WINDOWS\SYSTEM32\exclean.exe
C:\WINDOWS\SYSTEM32\paytime.exe
C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.exe
C:\WINDOWS\secure.html
C:\WINDOWS\soft.exe
C:\PROGRAM FILES\Media Access (folder)
C:\PROGRAM FILES\COMMON FILES\Totem Shared (delete the contents of this folder)
Delete the java cache by following these directions http://www.java.com/en/download/help/cache_virus.xml
Then post a new Panda scan along with a new HT log
If you are not running java version 1.5.0 or higher you need top update. You can download v1.5.0 from this link http://java.com/en/download/index.jsp Unless you have a high speed connection you may want to wait until you are ready to retire for the evening before downloading, it takes a while.

jaback,
Here are the most recent logs. It appears that several problems remain. Also, I could not locate some of the files that appear on the Panda log. Can you explain this?
Thanks for your help.
grichman
Panda Log #2Incident Status Location
Adware:adware/exact.bargainbuddy Not disinfected C:\WINDOWS\SYSTEM32\vx0.nls
Adware:adware/powerscan Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.exe
Adware:adware/ist.istbar Not disinfected C:\PROGRAM FILES\COMMON FILES\Totem Shared
Adware:adware/cws Not disinfected C:\Documents and Settings\Gary\Favorites\Insurance
Adware:adware/wupd Not disinfected Windows Registry
Adware:adware/secure32 Not disinfected C:\WINDOWS\system32\drivers\etc\hosts
Potentially unwanted tool:application/mywebsearch Not disinfected HKEY_CLASSES_ROOT\Interface\{c380566d-f343-42ab-987b-6b38a1a35747}
Adware:adware/ncase Not disinfected Windows Registry
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Gary\Cookies\gary@2o7[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Gary\Application Data\Mozilla\Firefox\Profiles\lydlrcmh.default\cookies.txt[]
Spyware:Cookie/2o7.net Not disinfected C:\Documents and Settings\Gary\Cookies\gary@2o7[1].txt
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Gary\Desktop\XP Downloads\smitRem.exe[Process.exe]HiJackThis Log #2
Logfile of HijackThis v1.99.1
Scan saved at 10:42:30 PM, on 3/14/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\LMSXXD.exe
C:\WINDOWS\System32\DSentry.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HJT\hijackthis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://finance.yahoo.com/p?v&k=pf_1
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O2 - BHO: Norton Personal Firewall 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Norton Personal Firewall 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.exe
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [LMSXXD] LMSXXD.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 3.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 3.0\aoltb.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} - http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {0C568603-D79D-11D2-87A7-00C04FF158BB} (BrowseFolderPopup Class) - http://download.mcafee.com/molbin/Shared/MGBrwFld.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123098797941
O16 - DPF: {885BB46A-3F1E-44C3-A01B-A7D9260CC98B} (InstallShield Update Service Setup Player) - http://updates.installshield.com/CAB/dwusplay.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://www.ritzpix.com/upload/FujifilmUploadClient.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?326
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.exe
O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe
O23 - Service: PACSPTISVR - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe
O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Help with "iworm_attck_v122.02a"

Ru HT again and remove these items:
O16 - DPF: {02BED220-FBC7-4392-93A2-3A50B056F78E} -http://down.plaxo.com/down/release/instub.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1123098797941
O16 - DPF: {A7EA8AD2-287F-11D3-B120-006008C39542} (CBSTIEPrint Class) - http://offers.e-centives.com/cif/download/bin/actxcab.cab
Download killbox from this link Download killbox from this link Killbox to your desktop.
Reboot into safe mode.
Double-click on Killbox.exe to run it.
Put a tick by Standard File Kill.
In the "Full Path of File to Delete" box, copy and paste each of the following lines one at a time.C:\WINDOWS\SYSTEM32\vx0.nls
C:\WINDOWS\DOWNLOADED PROGRAM FILES\pcpowerscan.EXE
Click on the button that has the red circle with the X in the middle after you enter each file.
It will ask for confimation to delete the file.
Click Yes.
Continue with that procedure until you have pasted all of these in the "Paste Full Path of File to Delete" box.Next,while still in safe mode and you computer set to view hidden files, navigate to the following folder and delete it:
C:\PROGRAM FILES\COMMON FILES\Totem Shared
The folder we deleted (Totem Shared) is associated with lop.com.
To search for lop we do to do get a "startup list log" from Hijack This. To do so run HT in normal mode>click the "open the misc. tool section " button>check the two boxes to the right of "generate startup lit log>then click "startup list log">yes>poost the results.

jaback,
Here is the "Startup List" log from HijackThis.
Thanks.
StartupList report, 3/15/2006, 4:47:03 PM
StartupList version: 1.52.2
Started from : C:\Program Files\HJT\hijackthis\HijackThis.exe
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
* Including empty and uninteresting sections
* Showing rarely important sections
==================================================Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\WDBtnMgr.exe
C:\WINDOWS\system32\LMSXXD.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\CTHELPER.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\WINDOWS\System32\drivers\CDAC11BA.exe
C:\WINDOWS\System32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\HJT\hijackthis\HijackThis.exe---------------------
Listing of startup folders:
Shell folders Startup:
[C:\Documents and Settings\Gary\Start Menu\Programs\Startup]
*No files*Shell folders AltStartup:
*Folder not found*User shell folders Startup:
*Folder not found*User shell folders AltStartup:
*Folder not found*Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
*No files*Shell folders Common AltStartup:
*Folder not found*User shell folders Common Startup:
*Folder not found*User shell folders Alternate Common Startup:
*Folder not found*---------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,[HKLM\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*[HKCU\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
*Registry value not found*[HKCU\Software\Microsoft\Windows\CurrentVersion\Winlogon]
*Registry key not found*---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunccApp = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
WD Button Manager = WDBtnMgr.exe
UpdReg = C:\WINDOWS\UpdReg.exe
MsmqIntCert = regsvr32 /s mqrt.dll
LMSXXD = LMSXXD.exe
DVDSentry = C:\WINDOWS\System32\DSentry.exe
CTSysVol = C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
CTHelper = CTHELPER.exe
CTDVDDet = C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.exe
ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
SunJavaUpdateSched = C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce*No values found*
---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx*No values found*
---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices*No values found*
---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce*Registry key not found*
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunLDM = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
Aim6 =---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce*No values found*
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx*Registry key not found*
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices*Registry key not found*
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce*Registry key not found*
---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run*Registry key not found*
---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run*Registry key not found*
---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run[OptionalComponents]
*No values found*---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*No subkeys found*---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
*No subkeys found*---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
*No subkeys found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
*No subkeys found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
*Registry key not found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
*Registry key not found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
*Registry key not found*---------------------
Autorun entries in Registry subkeys of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*---------------------
Autorun entries in Registry subkeys of:
HKCU\Software\Microsoft\Windows NT\CurrentVersion\Run
*Registry key not found*---------------------
File association entry for .EXE:
HKEY_CLASSES_ROOT\exefile\shell\open\command(Default) = "%1" %*
---------------------
File association entry for .COM:
HKEY_CLASSES_ROOT\comfile\shell\open\command(Default) = "%1" %*
---------------------
File association entry for .BAT:
HKEY_CLASSES_ROOT\batfile\shell\open\command(Default) = "%1" %*
---------------------
File association entry for .PIF:
HKEY_CLASSES_ROOT\piffile\shell\open\command(Default) = "%1" %*
---------------------
File association entry for .SCR:
HKEY_CLASSES_ROOT\scrfile\shell\open\command(Default) = "%1" /S
---------------------
File association entry for .HTA:
HKEY_CLASSES_ROOT\htafile\shell\open\command(Default) = C:\WINDOWS\system32\mshta.exe "%1" %*
---------------------
File association entry for .TXT:
HKEY_CLASSES_ROOT\txtfile\shell\open\command(Default) = %SystemRoot%\system32\NOTEPAD.exe %1
---------------------
Enumerating Active Setup stub paths:
HKLM\Software\Microsoft\Active Setup\Installed Components
(* = disabled by HKCU twin)[>{22d6f312-b0f6-11d0-94ab-0080c74c7e95}]
StubPath = C:\WINDOWS\inf\unregmp2.exe /ShowWMP[>{26923b43-4d38-484f-9b9e-de460746276c}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigIE[>{60B49E34-C7CC-11D0-8953-00A0C90347FF}MICROS] *
StubPath = RunDLL32 IEDKCS32.DLL,BrandIE4 SIGNUP[>{881dd1c5-3dcf-431b-b061-f3f88e8be88a}] *
StubPath = %systemroot%\system32\shmgrate.exe OCInstallUserConfigOE[{2C7339CF-2B09-4501-B3F3-F3508C9228ED}] *
StubPath = %SystemRoot%\system32\regsvr32.exe /s /n /i:/UserInstall %SystemRoot%\system32\themeui.dll[{44BBA840-CC51-11CF-AAFA-00AA00B6015C}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:OE /CALLER:WINNT /user /install[{44BBA842-CC51-11CF-AAFA-00AA00B6015B}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msnetmtg.inf,NetMtg.Install.PerUser.NT[{4b218e3e-bc98-4770-93d3-2731b9329278}] *
StubPath = %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection MarketplaceLinkInstall 896 %systemroot%\inf\ie.inf[{5945c046-1e7d-11d1-bc44-00c04fd912be}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\msmsgs.inf,BLC.QuietInstall.PerUser[{6BF52A52-394A-11d3-B153-00C04F79FAA6}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\wmp10.inf,PerUserStub[{7790769C-0471-11d2-AF11-00C04FA35D02}] *
StubPath = "%ProgramFiles%\Outlook Express\setup50.exe" /APP:WAB /CALLER:WINNT /user /install[{89820200-ECBD-11cf-8B85-00AA005B4340}] *
StubPath = regsvr32.exe /s /n /i:U shell32.dll[{89820200-ECBD-11cf-8B85-00AA005B4383}]
StubPath = %SystemRoot%\system32\ie4uinit.exe[{89B4C1CD-B018-4511-B0A1-5476DBF70820}] *
StubPath = C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\mscories.dll,Install[{8b15971b-5355-4c82-8c07-7e181ea07608}] *
StubPath = rundll32.exe advpack.dll,LaunchINFSection C:\WINDOWS\INF\fxsocm.inf,Fax.Install.PerUser---------------------
Enumerating ICQ Agent Autostart apps:
HKCU\Software\Mirabilis\ICQ\Agent\Apps*Registry key not found*
---------------------
Load/Run keys from C:\WINDOWS\WIN.INI:
load=*INI section not found*
run=*INI section not found*Load/Run keys from Registry:
HKLM\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKLM\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKLM\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: load=*Registry value not found*
HKCU\..\Windows NT\CurrentVersion\WinLogon: run=*Registry value not found*
HKCU\..\Windows\CurrentVersion\WinLogon: load=*Registry key not found*
HKCU\..\Windows\CurrentVersion\WinLogon: run=*Registry key not found*
HKCU\..\Windows NT\CurrentVersion\Windows: load=
HKCU\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: load=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: run=*Registry value not found*
HKLM\..\Windows NT\CurrentVersion\Windows: AppInit_DLLs=---------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\System32\ssmypics.scr
drivers=*Registry value not found*Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*---------------------
Checking for EXPLORER.exe instances:
C:\WINDOWS\Explorer.exe: PRESENT!
C:\Explorer.exe: not present
C:\WINDOWS\Explorer\Explorer.exe: not present
C:\WINDOWS\System\Explorer.exe: not present
C:\WINDOWS\System32\Explorer.exe: not present
C:\WINDOWS\Command\Explorer.exe: not present
C:\WINDOWS\Fonts\Explorer.exe: not present---------------------
Checking for superhidden extensions:
.lnk: HIDDEN! (arrow overlay: yes)
.pif: HIDDEN! (arrow overlay: yes)
.exe: not hidden
.com: not hidden
.bat: not hidden
.hta: not hidden
.scr: not hidden
.shs: HIDDEN!
.shb: HIDDEN!
.vbs: not hidden
.vbe: not hidden
.wsh: not hidden
.scf: HIDDEN! (arrow overlay: NO!)
.url: HIDDEN! (arrow overlay: yes)
.js: not hidden
.jse: not hidden---------------------
Verifying REGEDIT.exe integrity:
- Regedit.exe found in C:\WINDOWS
- .reg open command is normal (regedit.exe %1)
- Company name OK: 'Microsoft Corporation'
- Original filename OK: 'REGEDIT.EXE'
- File description: 'Registry Editor'Registry check passed
---------------------
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
Norton Personal Firewall 2006 - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll - {9ECB9560-04F9-4bbc-943D-298DDF1699E1}---------------------
Enumerating Task Scheduler jobs:
Norton AntiVirus - Scan my computer - Gary.job
Norton SystemWorks One Button Checkup.job
Symantec Drmc.job
WinSxS.job---------------------
Enumerating Download Program Files:
[DirectAnimation Java Classes]
CODEBASE = file://C:\WINDOWS\Java\classes\dajava.cab
OSD = C:\WINDOWS\Downloaded Program Files\DirectAnimation Java Classes.osd[Microsoft XML Parser for Java]
CODEBASE = file://C:\WINDOWS\Java\classes\xmldso.cab
OSD = C:\WINDOWS\Downloaded Program Files\Microsoft XML Parser for Java.osd[{00000075-9980-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/voxacm.CAB[{00000161-0000-0010-8000-00AA00389B71}]
CODEBASE = http://codecs.microsoft.com/codecs/i386/msaudio.cab[SupportSoft SmartIssue]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsi.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab[SupportSoft Script Runner Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\tgctlsr.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab[Microsoft Office Template and Media Control]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\IEAWSDC.DLL
CODEBASE = http://office.microsoft.com/templates/ieawsdc.cab[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab[BrowseFolderPopup Class]
InProcServer32 = C:\WINDOWS\MCBin\Shared\MGBrwFld.dll
CODEBASE = http://download.mcafee.com/molbin/Shared/MGBrwFld.cab[Shockwave ActiveX Control]
InProcServer32 = C:\WINDOWS\system32\macromed\director\SwDir.dll
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab[MSSecurityAdvisor Class]
InProcServer32 = C:\WINDOWS\System32\mssecadv.dll
CODEBASE = http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1094192249796[LSSupCtl Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\CONFLICT.2\LSSupCtl.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab[Symantec AntiVirus scanner]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\avsniff.dll
CODEBASE = http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc2.cab[InstallShield Update Service Setup Player]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\dwusplay.exe
CODEBASE = http://updates.installshield.com/CAB/dwusplay.cab[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[ActiveScan Installer Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll
CODEBASE = http://acs.pandasoftware.com/activescan/as5free/asinst.cab[HPObjectInstaller Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\HPCommunication.dll
CODEBASE = http://h30155.www3.hp.com/ediags/gs/install/guidedsolutions.cab[{9F1C11AA-197B-4942-BA54-47A8489BB47F}]
CODEBASE = http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37662.6806944444[FujifilmUploader Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\FujifilmUploadClient.dll
CODEBASE = http://www.ritzpix.com/upload/FujifilmUploadClient.cab[Get_ActiveX Control]
InProcServer32 = C:\WINDOWS\DOWNLO~1\HPGETD~1.OCX
CODEBASE = https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx[Symantec RuFSI Registry Information Class]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\rufsi.dll
CODEBASE = http://security.symantec.com/SSC/SharedContent/common/bin/cabsa.cab[Java Plug-in 1.4.1_02]
InProcServer32 = C:\Program Files\Java\j2re1.4.1_02\bin\npjpi141_02.dll
CODEBASE = http://java.sun.com/products/plugin/1.4/jinstall-14_02-windows-i586.cab[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[Java Plug-in 1.5.0_06]
InProcServer32 = C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll
CODEBASE = http://java.sun.com/update/1.5.0/jinstall-1_5_0_06-windows-i586.cab[ActiveDataInfo Class]
InProcServer32 = C:\PROGRA~1\COMMON~1\SYMANT~1\SymAData.dll
CODEBASE = http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash8.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[QDiagHUpdateObj Class]
InProcServer32 = C:\WINDOWS\system32\qdiagh.ocx
CODEBASE = http://h30043.www3.hp.com/aio/eng/check/qdiagh.cab?326---------------------
Enumerating Winsock LSP files:
NameSpace #1: C:\WINDOWS\System32\mswsock.dll
NameSpace #2: C:\WINDOWS\System32\winrnr.dll
NameSpace #3: C:\WINDOWS\System32\mswsock.dll
NameSpace #4: C:\WINDOWS\System32\nwprovau.dll
Protocol #1: C:\WINDOWS\system32\mswsock.dll
Protocol #2: C:\WINDOWS\system32\mswsock.dll
Protocol #3: C:\WINDOWS\system32\mswsock.dll
Protocol #4: C:\WINDOWS\system32\rsvpsp.dll
Protocol #5: C:\WINDOWS\system32\rsvpsp.dll
Protocol #6: C:\WINDOWS\system32\mswsock.dll
Protocol #7: C:\WINDOWS\system32\mswsock.dll
Protocol #8: C:\WINDOWS\system32\mswsock.dll
Protocol #9: C:\WINDOWS\system32\mswsock.dll
Protocol #10: C:\WINDOWS\system32\mswsock.dll
Protocol #11: C:\WINDOWS\system32\mswsock.dll
Protocol #12: C:\WINDOWS\system32\mswsock.dll
Protocol #13: C:\WINDOWS\system32\mswsock.dll
Protocol #14: C:\WINDOWS\system32\mswsock.dll
Protocol #15: C:\WINDOWS\system32\mswsock.dll
Protocol #16: C:\WINDOWS\system32\mswsock.dll
Protocol #17: C:\WINDOWS\system32\mswsock.dll
Protocol #18: C:\WINDOWS\system32\mswsock.dll
Protocol #19: C:\WINDOWS\system32\mswsock.dll
Protocol #20: C:\WINDOWS\system32\mswsock.dll
Protocol #21: C:\WINDOWS\system32\mswsock.dll
Protocol #22: C:\WINDOWS\system32\mswsock.dll---------------------
Enumerating Windows NT/2000/XP services
abp480n5: \SystemRoot\System32\DRIVERS\ABP480N5.SYS (disabled)
Microsoft ACPI Driver: System32\DRIVERS\ACPI.sys (system)
adpu160m: \SystemRoot\System32\DRIVERS\adpu160m.sys (disabled)
Microsoft Kernel Acoustic Echo Canceller: system32\drivers\aec.sys (manual start)
AFD Networking Support Environment: \SystemRoot\System32\drivers\afd.sys (system)
Intel AGP Bus Filter: System32\DRIVERS\agp440.sys (system)
Compaq AGP Bus Filter: \SystemRoot\System32\DRIVERS\agpCPQ.sys (disabled)
Aha154x: \SystemRoot\System32\DRIVERS\aha154x.sys (disabled)
aic78u2: \SystemRoot\System32\DRIVERS\aic78u2.sys (disabled)
aic78xx: \SystemRoot\System32\DRIVERS\aic78xx.sys (disabled)
D-Link AirPlus Wireless Adapter: System32\DRIVERS\airplus.sys (manual start)
Alerter: %SystemRoot%\System32\svchost.exe -k LocalService (disabled)
Application Layer Gateway Service: %SystemRoot%\System32\alg.exe (manual start)
AliIde: \SystemRoot\System32\DRIVERS\aliide.sys (disabled)
ALI AGP Bus Filter: \SystemRoot\System32\DRIVERS\alim1541.sys (disabled)
AMD AGP Bus Filter Driver: \SystemRoot\System32\DRIVERS\amdagp.sys (disabled)
amsint: \SystemRoot\System32\DRIVERS\amsint.sys (disabled)
Application Management: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
1394 ARP Client Protocol: System32\DRIVERS\arp1394.sys (manual start)
asc: \SystemRoot\System32\DRIVERS\asc.sys (disabled)
asc3350p: \SystemRoot\System32\DRIVERS\asc3350p.sys (disabled)
asc3550: \SystemRoot\System32\DRIVERS\asc3550.sys (disabled)
ASP.NET State Service: %SystemRoot%\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (manual start)
RAS Asynchronous Media Driver: System32\DRIVERS\asyncmac.sys (manual start)
Standard IDE/ESDI Hard Disk Controller: System32\DRIVERS\atapi.sys (system)
Ati HotKey Poller: %SystemRoot%\system32\Ati2evxx.exe (autostart)
ati2mtag: System32\DRIVERS\ati2mtag.sys (manual start)
ATM ARP Client Protocol: System32\DRIVERS\atmarpc.sys (manual start)
Windows Audio: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Audio Stub Driver: System32\DRIVERS\audstub.sys (manual start)
Automatic LiveUpdate Scheduler: "C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe" (autostart)
basic2: System32\DRIVERS\HSF_BSC2.sys (manual start)
BCMNTIO: \??\C:\PROGRA~1\CheckIt\DIAGNO~1\BCMNTIO.sys (autostart)
Background Intelligent Transfer Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
MAC Bridge: System32\DRIVERS\bridge.sys (manual start)
MAC Bridge Miniport: System32\DRIVERS\bridge.sys (manual start)
Computer Browser: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
C-DillaCdaC11BA: C:\WINDOWS\System32\drivers\CDAC11BA.exe (autostart)
cbidf: \SystemRoot\System32\DRIVERS\cbidf2k.sys (disabled)
Closed Caption Decoder: System32\DRIVERS\CCDECODE.sys (manual start)
Symantec Event Manager: "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe" (autostart)
Symantec Internet Security Password Validation: "C:\Program Files\Norton Personal Firewall\ccPwdSvc.exe" (manual start)
Symantec Network Proxy: "C:\Program Files\Common Files\Symantec Shared\ccProxy.exe" (autostart)
Symantec Password Validation: "C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe" (manual start)
Symantec Settings Manager: "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe" (autostart)
cd20xrnt: \SystemRoot\System32\DRIVERS\cd20xrnt.sys (disabled)
CdaC15BA: \??\C:\WINDOWS\System32\drivers\CdaC15BA.SYS (autostart)
CD-ROM Driver: System32\DRIVERS\cdrom.sys (system)
Indexing Service: C:\WINDOWS\System32\cisvc.exe (autostart)
ClipBook: %SystemRoot%\system32\clipsrv.exe (disabled)
CmdIde: \SystemRoot\System32\DRIVERS\cmdide.sys (disabled)
COM+ System Application: C:\WINDOWS\System32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} (manual start)
Cpqarray: \SystemRoot\System32\DRIVERS\cpqarray.sys (disabled)
Creative Service for CDROM Access: C:\WINDOWS\System32\CTsvcCDA.exe (autostart)
Cryptographic Services: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Creative AC3 Software Decoder: System32\drivers\ctac32k.sys (manual start)
Creative Audio Driver (WDM): system32\drivers\ctaud2k.sys (manual start)
Creative DVD-Audio Device Driver: System32\drivers\ctdvda2k.sys (manual start)
Creative Proxy Driver: System32\drivers\ctprxy2k.sys (manual start)
Creative SoundFont Management Device Driver: System32\drivers\ctsfm2k.sys (manual start)
dac2w2k: \SystemRoot\System32\DRIVERS\dac2w2k.sys (disabled)
dac960nt: \SystemRoot\System32\DRIVERS\dac960nt.sys (disabled)
DCOM Server Process Launcher: %SystemRoot%\system32\svchost -k DcomLaunch (autostart)
DHCP Client: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Disk Driver: System32\DRIVERS\disk.sys (system)
Logical Disk Manager Administrative Service: %SystemRoot%\System32\dmadmin.exe /com (manual start)
dmboot: System32\drivers\dmboot.sys (disabled)
Logical Disk Manager Driver: System32\drivers\dmio.sys (system)
dmload: System32\drivers\dmload.sys (system)
Logical Disk Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Microsoft Kernel DLS Syntheiszer: system32\drivers\DMusic.sys (manual start)
DNS Client: %SystemRoot%\System32\svchost.exe -k NetworkService (autostart)
MS IEEE-1284.4 Driver: System32\DRIVERS\Dot4.sys (manual start)
Print Class Driver for IEEE-1284.4: System32\DRIVERS\Dot4Prt.sys (manual start)
Scan Class Driver for IEEE-1284.4: System32\DRIVERS\Dot4Scan.sys (manual start)
Dot4USB Filter Dot4USB Filter: System32\DRIVERS\dot4usb.sys (manual start)
dpti2o: \SystemRoot\System32\DRIVERS\dpti2o.sys (disabled)
Microsoft Kernel DRM Audio Descrambler: system32\drivers\drmkaud.sys (manual start)
Intel(R) PRO Adapter Driver: System32\DRIVERS\e100b325.sys (manual start)
3Com EtherLink XL 90XB/C Adapter Driver: System32\DRIVERS\el90xbc5.sys (manual start)
E-mu Plug-in Architecture Driver: System32\drivers\emupia2k.sys (manual start)
Error Reporting Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Event Log: %SystemRoot%\system32\services.exe (autostart)
COM+ Event System: C:\WINDOWS\System32\svchost.exe -k netsvcs (manual start)
ewido security suite control: C:\Program Files\ewido anti-malware\ewidoctrl.exe (autostart)
Fallback: System32\DRIVERS\HSF_FALL.sys (autostart)
Fast User Switching Compatibility: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Fax: %systemroot%\system32\fxssvc.exe (autostart)
Floppy Disk Controller Driver: System32\DRIVERS\fdc.sys (manual start)
Floppy Disk Driver: System32\DRIVERS\flpydisk.sys (manual start)
FltMgr: system32\drivers\fltmgr.sys (system)
Fsks: System32\DRIVERS\HSF_FSKS.sys (autostart)
Volume Manager Driver: System32\DRIVERS\ftdisk.sys (system)
GEARAspiWDM: System32\Drivers\GEARAspiWDM.sys (manual start)
Generic Packet Classifier: System32\DRIVERS\msgpc.sys (manual start)
Creative Hardware Abstract Layer Driver: System32\drivers\ha10kx2k.sys (manual start)
Creative P16V HAL Driver: System32\drivers\hap16v2k.sys (manual start)
Help and Support: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Human Interface Device Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Microsoft HID Class Driver: System32\DRIVERS\hidusb.sys (manual start)
hpn: \SystemRoot\System32\DRIVERS\hpn.sys (disabled)
HSFHWBS2: System32\DRIVERS\HSFHWBS2.sys (manual start)
HSF_DP: System32\DRIVERS\HSF_DP.sys (manual start)
hsf_msft: System32\DRIVERS\HSF_MSFT.sys (manual start)
HTTP: System32\Drivers\HTTP.sys (manual start)
HTTP SSL: %SystemRoot%\System32\svchost.exe -k HTTPFilter (manual start)
i2omp: \SystemRoot\System32\DRIVERS\i2omp.sys (disabled)
i8042 Keyboard and PS/2 Mouse Port Driver: System32\DRIVERS\i8042prt.sys (system)
i81x: System32\DRIVERS\i81xnt5.sys (manual start)
iAimFP0: System32\DRIVERS\wADV01nt.sys (manual start)
iAimFP1: System32\DRIVERS\wADV02NT.sys (manual start)
iAimFP2: System32\DRIVERS\wADV05NT.sys (manual start)
iAimFP3: System32\DRIVERS\wSiINTxx.sys (manual start)
iAimFP4: System32\DRIVERS\wVchNTxx.sys (manual start)
iAimTV0: System32\DRIVERS\wATV01nt.sys (manual start)
iAimTV1: System32\DRIVERS\wATV02NT.sys (manual start)
iAimTV2: System32\DRIVERS\wATV03nt.sys (manual start)
iAimTV3: System32\DRIVERS\wATV04nt.sys (manual start)
iAimTV4: System32\DRIVERS\wCh7xxNT.sys (manual start)
InstallDriver Table Manager: "C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe" (manual start)
IIS Admin: C:\WINDOWS\System32\inetsrv\inetinfo.exe (autostart)
CD-Burning Filter Driver: System32\DRIVERS\imapi.sys (system)
IMAPI CD-Burning COM Service: C:\WINDOWS\System32\imapi.exe (manual start)
ini910u: \SystemRoot\System32\DRIVERS\ini910u.sys (disabled)
IntelIde: System32\DRIVERS\intelide.sys (system)
Intel Processor Driver: System32\DRIVERS\intelppm.sys (system)
IPv6 Windows Firewall Driver: system32\drivers\ip6fw.sys (manual start)
IP Traffic Filter Driver: System32\DRIVERS\ipfltdrv.sys (manual start)
IP in IP Tunnel Driver: System32\DRIVERS\ipinip.sys (manual start)
IP Network Address Translator: System32\DRIVERS\ipnat.sys (manual start)
iPodService: C:\Program Files\iPod\bin\iPodService.exe (manual start)
RIP Listener: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
IPSEC driver: System32\DRIVERS\ipsec.sys (system)
IR Enumerator Service: System32\DRIVERS\irenum.sys (manual start)
PnP ISA/EISA Bus Driver: System32\DRIVERS\isapnp.sys (system)
K56: System32\DRIVERS\HSF_K56K.sys (autostart)
Keyboard Class Driver: System32\DRIVERS\kbdclass.sys (system)
Keyboard HID Driver: system32\DRIVERS\kbdhid.sys (system)
Microsoft Kernel Wave Audio Mixer: system32\drivers\kmixer.sys (manual start)
Logitech SetPoint PS/2 Mouse Filter Driver: system32\DRIVERS\L8042mou.Sys (manual start)
Server: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Workstation: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
LiveUpdate: "C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.exe" (manual start)
TCP/IP NetBIOS Helper: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
Logitech SetPoint Mouse Filter Driver: system32\DRIVERS\LMouKE.Sys (manual start)
TCP/IP Print Server: %SystemRoot%\System32\tcpsvcs.exe (manual start)
MAPMEM: \??\C:\PROGRA~1\CheckIt\DIAGNO~1\MAPMEM.sys (autostart)
mdmxsdk: System32\DRIVERS\mdmxsdk.sys (autostart)
Sony Memory Stick controller (PCI): System32\DRIVERS\MemStPCI.SYS (manual start)
Messenger: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
NetMeeting Remote Desktop Sharing: C:\WINDOWS\System32\mnmsrvc.exe (manual start)
Unimodem Streaming Filter Device: system32\drivers\MODEMCSA.sys (manual start)
Mouse Class Driver: System32\DRIVERS\mouclass.sys (system)
Mouse HID Driver: System32\DRIVERS\mouhid.sys (manual start)
Message Queuing access control: \??\C:\WINDOWS\System32\drivers\mqac.sys (manual start)
mraid35x: \SystemRoot\System32\DRIVERS\mraid35x.sys (disabled)
WebDav Client Redirector: System32\DRIVERS\mrxdav.sys (manual start)
MRXSMB: System32\DRIVERS\mrxsmb.sys (system)
MSCSPTISRV: "C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe" (manual start)
Distributed Transaction Coordinator: C:\WINDOWS\System32\msdtc.exe (manual start)
Windows Installer: C:\WINDOWS\system32\msiexec.exe /V (manual start)
Microsoft Streaming Service Proxy: system32\drivers\MSKSSRV.sys (manual start)
Message Queuing: C:\WINDOWS\System32\mqsvc.exe (autostart)
Message Queuing Triggers: C:\WINDOWS\System32\mqtgsvc.exe (autostart)
Microsoft Streaming Clock Proxy: system32\drivers\MSPCLOCK.sys (manual start)
Microsoft Streaming Quality Manager Proxy: system32\drivers\MSPQM.sys (manual start)
Microsoft System Management BIOS Driver: System32\DRIVERS\mssmbios.sys (manual start)
Microsoft Streaming Tee/Sink-to-Sink Converter: system32\drivers\MSTEE.sys (manual start)
NABTS/FEC VBI Codec: System32\DRIVERS\NABTSFEC.sys (manual start)
Norton AntiVirus Auto-Protect Service: "C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe" (autostart)
NAVENG: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060315.006\NAVENG.Sys (manual start)
NAVEX15: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20060315.006\NavEx15.Sys (manual start)
Microsoft TV/Video Connection: System32\DRIVERS\NdisIP.sys (manual start)
Remote Access NDIS TAPI Driver: System32\DRIVERS\ndistapi.sys (manual start)
NDIS Usermode I/O Protocol: System32\DRIVERS\ndisuio.sys (manual start)
Remote Access NDIS WAN Driver: System32\DRIVERS\ndiswan.sys (manual start)
NetBIOS Interface: System32\DRIVERS\netbios.sys (system)
I: System32\DRIVERS\netbt.sys (system)
Network DDE: %SystemRoot%\system32\netdde.exe (disabled)
Network DDE DSDM: %SystemRoot%\system32\netdde.exe (disabled)
Net Logon: %SystemRoot%\System32\lsass.exe (manual start)
Network Connections: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
1394 Net Driver: System32\DRIVERS\nic1394.sys (manual start)
Network Location Awareness (NLA): %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
NIC Management Service Configuration Driver: \??\C:\WINDOWS\System32\drivers\NMSCFG.SYS (manual start)
Intel(R) NMS: C:\WINDOWS\System32\NMSSvc.exe (manual start)
Norton Unerase Protection Driver: \??\C:\WINDOWS\system32\Drivers\NPDRIVER.SYS (manual start)
Norton AntiVirus Firewall Monitor Service: "C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe" (autostart)
Norton Unerase Protection: C:\PROGRA~1\NORTON~3\NORTON~1\NPROTECT.exe (autostart)
Norton Protection Center Service: "C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.exe" (manual start)
NT LM Security Support Provider: %SystemRoot%\System32\lsass.exe (manual start)
Removable Storage: %SystemRoot%\system32\svchost.exe -k netsvcs (manual start)
nv: System32\DRIVERS\nv4_mini.sys (manual start)
Client Service for NetWare: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
IPX Traffic Filter Driver: System32\DRIVERS\nwlnkflt.sys (manual start)
IPX Traffic Forwarder Driver: System32\DRIVERS\nwlnkfwd.sys (manual start)
NWLink IPX/SPX/NetBIOS Compatible Transport Protocol: System32\DRIVERS\nwlnkipx.sys (autostart)
NWLink NetBIOS: System32\DRIVERS\nwlnknb.sys (autostart)
NWLink SPX/SPXII Protocol: System32\DRIVERS\nwlnkspx.sys (autostart)
NetWare Rdr: System32\DRIVERS\nwrdr.sys (manual start)
SAP Agent: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
OHCI Compliant IEEE 1394 Host Controller: System32\DRIVERS\ohci1394.sys (system)
OMCI WDM Device Driver: System32\DRIVERS\omci.sys (system)
Creative OS Services Driver: system32\drivers\ctoss2k.sys (manual start)
Intel PentiumIII Processor Driver: System32\DRIVERS\p3.sys (system)
PACSPTISVR: "C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe" (manual start)
Parallel port driver: System32\DRIVERS\parport.sys (manual start)
PCANDIS5 Protocol Driver: \??\C:\PROGRA~1\D-LINK~1\PCANDIS5.SYS (manual start)
PCI Bus Driver: System32\DRIVERS\pci.sys (system)
PCIIde: \SystemRoot\System32\DRIVERS\pciide.sys (disabled)
Low level access layer for CD devices: System32\Drivers\Pcouffin.sys (manual start)
perc2: \SystemRoot\System32\DRIVERS\perc2.sys (disabled)
perc2hib: \SystemRoot\System32\DRIVERS\perc2hib.sys (disabled)
Padus ASPI Shell: system32\drivers\pfc.sys (manual start)
PfModNT: \??\C:\WINDOWS\System32\PfModNT.sys (autostart)
Plug and Play: %SystemRoot%\system32\services.exe (autostart)
IPSEC Services: %SystemRoot%\System32\lsass.exe (autostart)
WAN Miniport (PPTP): System32\DRIVERS\raspptp.sys (manual start)
Processor Driver: System32\DRIVERS\processr.sys (system)
Protected Storage: %SystemRoot%\system32\lsass.exe (autostart)
QoS Packet Scheduler: System32\DRIVERS\psched.sys (manual start)
Direct Parallel Link Driver: System32\DRIVERS\ptilink.sys (manual start)
PxHelp20: System32\Drivers\PxHelp20.sys (system)
ql1080: \SystemRoot\System32\DRIVERS\ql1080.sys (disabled)
Ql10wnt: \SystemRoot\System32\DRIVERS\ql10wnt.sys (disabled)
ql12160: \SystemRoot\System32\DRIVERS\ql12160.sys (disabled)
ql1240: \SystemRoot\System32\DRIVERS\ql1240.sys (disabled)
ql1280: \SystemRoot\System32\DRIVERS\ql1280.sys (disabled)
Remote Access Auto Connection Driver: System32\DRIVERS\rasacd.sys (system)
Remote Access Auto Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WAN Miniport (L2TP): System32\DRIVERS\rasl2tp.sys (manual start)
Remote Access Connection Manager: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
Remote Access PPPOE Driver: System32\DRIVERS\raspppoe.sys (manual start)
Direct Parallel: System32\DRIVERS\raspti.sys (manual start)
Rdbss: System32\DRIVERS\rdbss.sys (system)
RDPCDD: System32\DRIVERS\RDPCDD.sys (system)
Terminal Server Device Redirector Driver: System32\DRIVERS\rdpdr.sys (manual start)
Remote Desktop Help Session Manager: C:\WINDOWS\system32\sessmgr.exe (manual start)
Digital CD Audio Playback Filter Driver: System32\DRIVERS\redbook.sys (system)
Routing and Remote Access: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Remote Registry: %SystemRoot%\system32\svchost.exe -k LocalService (autostart)
Rksample: System32\DRIVERS\HSF_SAMP.sys (manual start)
Reliable Multicast Protocol driver: \??\C:\WINDOWS\System32\drivers\RMCast.sys (manual start)
Remote Procedure Call (RPC) Locator: %SystemRoot%\System32\locator.exe (manual start)
Remote Procedure Call (RPC): %SystemRoot%\system32\svchost -k rpcss (autostart)
QoS RSVP: %SystemRoot%\System32\rsvp.exe (manual start)
Security Accounts Manager: %SystemRoot%\system32\lsass.exe (autostart)
SAVRT: \??\C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVRT.SYS (manual start)
SAVRTPEL: \??\C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVRTPEL.SYS (system)
SAVScan: "C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe" (manual start)
SBP-2 Transport/Protocol Bus Driver: System32\DRIVERS\sbp2port.sys (system)
ScriptBlocking Service: C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe (autostart)
Smart Card: %SystemRoot%\System32\SCardSvr.exe (manual start)
Task Scheduler: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
SDdriver: \??\C:\WINDOWS\system32\Drivers\sddriver.sys (manual start)
Secdrv: System32\DRIVERS\secdrv.sys (manual start)
Secondary Logon: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
System Event Notification: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
Serenum Filter Driver: System32\DRIVERS\serenum.sys (manual start)
Serial port driver: System32\DRIVERS\serial.sys (system)
Windows Firewall/Internet Connection Sharing (ICS): %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Shell Hardware Detection: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Simple TCP/IP Services: %SystemRoot%\System32\tcpsvcs.exe (autostart)
SIS AGP Bus Filter: \SystemRoot\System32\DRIVERS\sisagp.sys (disabled)
BDA Slip De-Framer: System32\DRIVERS\SLIP.sys (manual start)
Simple Mail Transfer Protocol (SMTP): C:\WINDOWS\System32\inetsrv\inetinfo.exe (autostart)
Symantec Network Drivers Service: "C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe" (autostart)
SNMP Service: %SystemRoot%\System32\snmp.exe (autostart)
SNMP Trap Service: %SystemRoot%\System32\snmptrap.exe (manual start)
SoftFax: System32\DRIVERS\HSF_FAXX.sys (autostart)
Sony Digital Imaging Base: System32\DRIVERS\sonyhcb.sys (system)
Sony Digital Imaging Video: System32\DRIVERS\sonyhcs.sys (manual start)
Sony USB Filter Driver (SONYPVU1): System32\DRIVERS\SONYPVU1.SYS (manual start)
Sparrow: \SystemRoot\System32\DRIVERS\sparrow.sys (disabled)
SPBBCDrv: \??\C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (manual start)
Symantec SPBBCSvc: "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe" (manual start)
SpeakerPhone: System32\DRIVERS\HSF_SPKP.sys (autostart)
Speed Disk service: C:\PROGRA~1\NORTON~3\NORTON~1\SPEEDD~1\NOPDB.exe (autostart)
Microsoft Kernel Audio Splitter: system32\drivers\splitter.sys (manual start)
Print Spooler: %SystemRoot%\system32\spoolsv.exe (autostart)
Sony SPTI Service: "C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe" (manual start)
System Restore Filter Driver: \SystemRoot\System32\DRIVERS\sr.sys (disabled)
System Restore Service: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Srv: System32\DRIVERS\srv.sys (manual start)
SSDP Discovery Service: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
SonicStage SCSI Service: C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (manual start)
Windows Image Acquisition (WIA): %SystemRoot%\System32\svchost.exe -k imgsvc (autostart)
BDA IPSink: System32\DRIVERS\StreamIP.sys (manual start)
Software Bus Driver: System32\DRIVERS\swenum.sys (manual start)
Microsoft Kernel GS Wavetable Synthesizer: system32\drivers\swmidi.sys (manual start)
MS Software Shadow Copy Provider: C:\WINDOWS\System32\dllhost.exe /Processid:{261FF5D6-55B3-4D28-8348-7DBC93E219F0} (manual start)
Symantec Core LC: C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (autostart)
symc810: \SystemRoot\System32\DRIVERS\symc810.sys (disabled)
symc8xx: \SystemRoot\System32\DRIVERS\symc8xx.sys (disabled)
SYMDNS: \SystemRoot\System32\Drivers\SYMDNS.SYS (manual start)
SymEvent: \??\C:\Program Files\Symantec\SYMEVENT.SYS (manual start)
SYMFW: \SystemRoot\System32\Drivers\SYMFW.SYS (manual start)
SYMIDS: \SystemRoot\System32\Drivers\SYMIDS.SYS (manual start)
SYMIDSCO: \??\C:\PROGRA~1\COMMON~1\SYMANT~1\SymcData\idsdefs\20060314.071\symidsco.sys (manual start)
symlcbrd: \??\C:\WINDOWS\system32\drivers\symlcbrd.sys (autostart)
SYMNDIS: \SystemRoot\System32\Drivers\SYMNDIS.SYS (manual start)
SYMREDRV: \SystemRoot\System32\Drivers\SYMREDRV.SYS (manual start)
SYMTDI: \SystemRoot\System32\Drivers\SYMTDI.SYS (system)
sym_hi: \SystemRoot\System32\DRIVERS\sym_hi.sys (disabled)
sym_u3: \SystemRoot\System32\DRIVERS\sym_u3.sys (disabled)
Microsoft Kernel System Audio Device: system32\drivers\sysaudio.sys (manual start)
Performance Logs and Alerts: %SystemRoot%\system32\smlogsvc.exe (manual start)
Telephony: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
TCP/IP Protocol Driver: System32\DRIVERS\tcpip.sys (system)
Terminal Device Driver: System32\DRIVERS\termdd.sys (system)
Terminal Services: %SystemRoot%\System32\svchost -k DComLaunch (manual start)
Themes: %SystemRoot%\System32\svchost.exe -k netsvcs (autostart)
Telnet: C:\WINDOWS\System32\tlntsvr.exe (disabled)
Tones: System32\DRIVERS\HSF_TONE.sys (autostart)
TosIde: \SystemRoot\System32\DRIVERS\toside.sys (disabled)
Distributed Link Tracking Client: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
ultra: \SystemRoot\System32\DRIVERS\ultra.sys (disabled)
Windows User Mode Driver Framework: C:\WINDOWS\system32\wdfmgr.exe (autostart)
Microcode Update Driver: System32\DRIVERS\update.sys (manual start)
Universal Plug and Play Device Host: %SystemRoot%\System32\svchost.exe -k LocalService (manual start)
Uninterruptible Power Supply: %SystemRoot%\System32\ups.exe (manual start)
Sony Digital Imaging Audio: system32\drivers\usbaudio.sys (manual start)
Microsoft USB 2.0 Enhanced Host Controller Miniport Driver: System32\DRIVERS\usbehci.sys (manual start)
Microsoft USB Standard Hub Driver: System32\DRIVERS\usbhub.sys (manual start)
USB Mass Storage Driver: System32\DRIVERS\USBSTOR.SYS (manual start)
Microsoft USB Universal Host Controller Miniport Driver: System32\DRIVERS\usbuhci.sys (manual start)
V124: System32\DRIVERS\HSF_V124.sys (autostart)
VGA Display Controller.: \SystemRoot\System32\drivers\vga.sys (system)
VIA AGP Bus Filter: \SystemRoot\System32\DRIVERS\viaagp.sys (disabled)
ViaIde: \SystemRoot\System32\DRIVERS\viaide.sys (disabled)
VSP1284D: \??\C:\WINDOWS\system32\VSP1284D.SYS (autostart)
Volume Shadow Copy: %SystemRoot%\System32\vssvc.exe (manual start)
Windows Time: %SystemRoot%\system32\svchost.exe -k netsvcs (autostart)
World Wide Web Publishing: %SystemRoot%\System32\inetsrv\inetinfo.exe (autostart)
Remote Access IP ARP Driver: System32\DRIVERS\wanarp.sys (manual start)
WAN Miniport (ATW): System32\DRIVERS\wanatw4.sys (manual start)
WAN Miniport (ATW) Service: "C:\WINDOWS\wanmpsvc.exe" (autostart)
USB Bridge Cable Driver: System32\Drivers\usbbc.sys (manual start)
Microsoft WINMM WDM Audio Compatibility Driver: system32\drivers\wdmaud.sys (manual start)
WebClient: %SystemRoot%\System32\svchost.exe -k LocalService (autostart)
winachsf: System32\DRIVERS\HSF_CNXT.sys (manual start)
Windows Management Instrumentation: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Windows Media Connect (WMC): c:\program files\windows media connect\mswmccds.exe (manual start)
Windows Media Connect (WMC) Helper: C:\Program Files\Windows Media Connect\mswmcls.exe (manual start)
WMDM PMSP Service: C:\WINDOWS\System32\MsPMSPSv.exe (autostart)
Portable Media Serial Number Service: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Windows Management Instrumentation Driver Extensions: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
WMI Performance Adapter: C:\WINDOWS\System32\wbem\wmiapsrv.exe (manual start)
Windows Socket 2.0 Non-IFS Service Provider Support Environment: \SystemRoot\System32\drivers\ws2ifsl.sys (system)
Security Center: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
World Standard Teletext Codec: System32\DRIVERS\WSTCODEC.SYS (manual start)
Automatic Updates: %systemroot%\system32\svchost.exe -k netsvcs (autostart)
Wireless Zero Configuration: %SystemRoot%\System32\svchost.exe -k netsvcs (disabled)
Network Provisioning Service: %SystemRoot%\System32\svchost.exe -k netsvcs (manual start)
---------------------Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*Windows NT checkdisk command:
BootExecute = autocheck autochk *Windows NT 'Wininit.ini':
PendingFileRenameOperations: *Registry value not found*---------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll---------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run*Registry key not found*
---------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run*No values found*
---------------------
End of report, 49,280 bytes
Report generated in 0.141 secondsCommand line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Help with "iworm_attck_v122.02a"

I don't see lop.com. How is your computer running and did you find and delete the files/folders in response #10.

jaback,
I'm a little unclear as to the significance of the absence of the "lop.com" file. Should I have this file? Delete this file?
I deleted the files and folders in response #10 and the computer seems to be running okay (i.e., the annoying popup warnings about the presence of a virus are now gone.). I also installed the newest version of Java without problem.
Unless there is something more to address re: the "lop.com" file, I think you've got me back in working order. If so, I want to thank you very much for all your assistance. You've been invaluable.
Best regards,
grichman
Help with "iworm_attck_v122.02a"

Lop.com is not present on your computer.To be sure of that was important because problem would begin to reoccur.
Glad we could help.

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |