Fatso913

Members
  • Content Count

    112
  • Joined

  • Last visited

Posts posted by Fatso913

  1. Hello, Welcome to BestTechie!

    I have seen this problem before ONCE.

    I would approach this with the following solution:

    Win XP and Win 2000 have a default setting to restart at just about any error. It makes things difficult to analyze when it blows through and restarts the computer. Settings / Control Panel / System / Advanced / Startup and Recovery / Settings. Make sure the box is UNCHECKED where it says "Automatically Restart" under System Failure."

  2. New HJT LOG!

    Logfile of HijackThis v1.99.1

    Scan saved at 9:57:27 PM, on 9/13/2006

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\Windows Media Connect 2\WMCCFG.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe

    C:\Program Files\ewido anti-spyware 4.0\ewido.exe

    C:\Program Files\RamBooster 2.0\Rambooster.exe

    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe

    C:\Program Files\Ares\Ares.exe

    C:\WINDOWS\system32\sistray.exe

    C:\Program Files\SpywareGuard\sgmain.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe

    C:\Program Files\ewido anti-spyware 4.0\guard.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Icecast2 Win32\icecastService.exe

    C:\Program Files\SpywareGuard\sgbhp.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

    C:\Program Files\Internet Explorer\iexplore.exe

    C:\WINDOWS\system32\wuauclt.exe

    C:\WINDOWS\system32\SearchIndexer.exe

    C:\WINDOWS\system32\SearchFilterHost.exe

    C:\WINDOWS\system32\SearchProtocolHost.exe

    C:\Program Files\mIRC\mirc.exe

    C:\Documents and Settings\Mike\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.trafficswarm.com/cgi-bin/swarm....18a20ca11a4c6b3

    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet

    O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"

    O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"

    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"

    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"

    O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"

    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized

    O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe

    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [1&1 EasyLogin] "C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe" HIDE

    O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h

    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

    O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab

    O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab

    O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab

    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

    O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://clubgames.pogo.com/online2/pogop/zu...aploader_v5.cab

    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab

    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe

    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe

    O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe" "C:\Program Files\Icecast2 Win32 (file missing)

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe

  3. ok here is the report:

    ---------------------------------------------------------

    ewido anti-spyware - Scan Report

    ---------------------------------------------------------

    + Created at: 7:15:16 PM 9/13/2006

    + Scan result:

    C:\Documents and Settings\Mike\Local Settings\Temp\Tspd.dll -> Adware.Agent : No action taken.

    C:\Documents and Settings\Mike\Local Settings\Temp\NNBar_VCSetup_876072.exe -> Adware.Mirar : No action taken.

    C:\Documents and Settings\Mike\Local Settings\Temp\mit17.tmp.cab/NNBar_VCSetup_876072.exe -> Adware.Mirar : No action taken.

    C:\Documents and Settings\Mike\Local Settings\Temp\mit17.tmp/NNBar_VCSetup_876072.exe -> Adware.Mirar : No action taken.

    C:\Program Files\WinAce\VVSNInst.exe -> Adware.SaveNow : No action taken.

    C:\WINDOWS\system32\bez6n4r21.exe -> Adware.SearchAssistant : No action taken.

    C:\WINDOWS\system32bez6n4r21.exe -> Adware.SearchAssistant : No action taken.

    C:\WINDOWS\system32\iqqr.exe -> Adware.Suggestor : No action taken.

    C:\WINDOWS\system32\ZICORN003.exe -> Adware.ZenoSearch : No action taken.

    C:\Documents and Settings\Mike\Local Settings\Temporary Internet Files\Content.IE5\O4WNFXBY\popup[1].htm -> Hijacker.Agent.a : No action taken.

    C:\Program Files\ComPlus Applications\mecewepym.html -> Hijacker.Small.jf : No action taken.

    C:\Program Files\MSN\pofozor.html -> Hijacker.Small.jf : No action taken.

    :mozilla.6:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.2o7 : No action taken.

    C:\Documents and Settings\Mike\Cookies\mike@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.

    C:\Documents and Settings\Tom\Cookies\tom@adbrite[1].txt -> TrackingCookie.Adbrite : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Addynamix : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Admarketplace : No action taken.

    C:\Documents and Settings\Tom\Cookies\tom@admarketplace[2].txt -> TrackingCookie.Admarketplace : No action taken.

    :mozilla.48:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.

    :mozilla.49:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.

    :mozilla.50:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.

    :mozilla.51:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.

    :mozilla.52:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Adrevolver : No action taken.

    C:\Documents and Settings\Mike\Cookies\mike@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Adtrak : No action taken.

    :mozilla.40:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Advertising : No action taken.

    :mozilla.41:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Advertising : No action taken.

    :mozilla.42:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Advertising : No action taken.

    :mozilla.43:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Advertising : No action taken.

    :mozilla.38:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Atdmt : No action taken.

    :mozilla.64:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.

    :mozilla.65:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.

    :mozilla.66:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Burstbeacon : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Burstbeacon : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Burstnet : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Burstnet : No action taken.

    :mozilla.73:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.

    :mozilla.74:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Casalemedia : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Com : No action taken.

    C:\Documents and Settings\Mike\Cookies\mike@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.

    C:\Documents and Settings\Tom\Cookies\tom@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.

    :mozilla.39:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Epilot : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Esomniture : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Euroclick : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Falkag : No action taken.

    :mozilla.54:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.

    :mozilla.55:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.

    :mozilla.56:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.

    :mozilla.57:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Fastclick : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Goclick : No action taken.

    :mozilla.81:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.

    :mozilla.82:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.

    :mozilla.83:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Hitbox : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Hitbox : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Hitbox : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Liveperson : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Masterstats : No action taken.

    :mozilla.69:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Mediaplex : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Mike\Cookies\mike@overture[2].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Overture : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Specificclick : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Starware : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Starware : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Starware : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][1].txt -> TrackingCookie.Starware : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : No action taken.

    C:\Documents and Settings\Tom\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][1].txt -> TrackingCookie.Targetnet : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Targetnet : No action taken.

    :mozilla.27:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.28:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.29:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.30:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.31:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.32:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.33:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.34:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.35:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Trafficmp : No action taken.

    :mozilla.70:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.

    C:\Documents and Settings\Mike\Cookies\[email protected][2].txt -> TrackingCookie.Valuead : No action taken.

    :mozilla.84:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.

    :mozilla.85:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Webtrendslive : No action taken.

    :mozilla.71:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.

    :mozilla.72:C:\Documents and Settings\Tom\Application Data\Mozilla\Firefox\Profiles\8znogvnx.default\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.

    ::Report end

  4. I keep getting these popups for downloading a antivirus software all the time :-( VERY ANNOYING

    This is my log:

    Logfile of HijackThis v1.99.1

    Scan saved at 6:13:38 PM, on 9/10/2006

    Platform: Windows XP SP2 (WinNT 5.01.2600)

    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:

    C:\WINDOWS\System32\smss.exe

    C:\WINDOWS\system32\winlogon.exe

    C:\WINDOWS\system32\services.exe

    C:\WINDOWS\system32\lsass.exe

    C:\WINDOWS\system32\svchost.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\spoolsv.exe

    C:\WINDOWS\System32\svchost.exe

    C:\Program Files\Icecast2 Win32\icecastService.exe

    C:\WINDOWS\System32\svchost.exe

    C:\WINDOWS\system32\SearchIndexer.exe

    C:\WINDOWS\Explorer.EXE

    C:\Program Files\QuickTime\qttask.exe

    C:\Program Files\Winamp\winampa.exe

    C:\Program Files\Windows Media Connect 2\WMCCFG.exe

    C:\Program Files\RamBooster 2.0\Rambooster.exe

    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe

    C:\WINDOWS\system32\ctfmon.exe

    C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe

    C:\WINDOWS\system32\sistray.exe

    C:\Program Files\SpywareGuard\sgmain.exe

    C:\Program Files\mIRC\mirc.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe

    C:\WINDOWS\system32\wscntfy.exe

    C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe

    C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

    C:\Program Files\SpywareGuard\sgbhp.exe

    C:\Documents and Settings\Mike\Desktop\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.mikedontcare.com/

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm

    O2 - BHO: SpywareGuard Download Protection - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll

    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

    O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    O4 - HKLM\..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe

    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

    O4 - HKLM\..\Run: [Windows Media Connect 2] "C:\Program Files\Windows Media Connect 2\WMCCFG.exe" /StartQuiet

    O4 - HKLM\..\Run: [JeticoPFStartup] "C:\Program Files\Jetico\Jetico Personal Firewall\fwsrv.exe"

    O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-2.1.215.5\QOELoader.exe"

    O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"

    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"

    O4 - HKLM\..\Run: [eTrustPPAP] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPActiveDetection.exe"

    O4 - HKLM\..\RunOnce: [Pest Cleaning] "C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\core\ppclean.exe" "clean" "trojan-clicker.win32.vb.ij" "2"

    O4 - HKCU\..\Run: [RamBooster] C:\Program Files\RamBooster 2.0\Rambooster.exe

    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"

    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

    O4 - HKCU\..\Run: [1&1 EasyLogin] "C:\Program Files\1&1\1&1 EasyLogin\EasyLogin.exe" HIDE

    O4 - Startup: SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe

    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

    O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\ssv.dll

    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL

    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB

    O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) - http://www.sis.com/ocis/OSInfo.cab

    O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/ocis/SiSAutodetectNT.cab

    O16 - DPF: {266B9238-31A5-4B53-9039-272FE846DF9D} (DiameterTransfer Control) - http://www.sis.com/download/SISTransfer.cab

    O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab

    O16 - DPF: {D1E7CBDA-E60E-4970-A01C-37301EF7BF98} (Measurement Services Client v.3.11) - http://gameadvisor.futuremark.com/global/msc311.cab

    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://clubgames.pogo.com/online2/pogop/zu...aploader_v5.cab

    O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX Control) - http://driveragent.com/files/driveragent.cab

    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/controls/msnchat45.cab

    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cab

    O17 - HKLM\System\CCS\Services\Tcpip\..\{1D2B6AB0-3D40-4CB9-8EF3-6CB5C559AE0F}: NameServer = 65.32.5.74,4.2.2.1

    O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

    O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL

    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll

    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll

    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe

    O23 - Service: Icecast Media Server (Icecast) - Unknown owner - C:\Program Files\Icecast2 Win32\icecastService.exe" "C:\Program Files\Icecast2 Win32 (file missing)

    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

    O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

    O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe