![]() |
|
#31
| |||
| |||
| okay, no worries.....think I know what's doing it. Now boot into Safe Mode. To learn how to do that, go to http://www.computerhope.com/issues/chsafe.htm. Run AVG again, Under Scanner, Settings, choose Quarantine under How to act?, choose all available files to scan, and put tics next to all options, also select that it automatically generate a report. Run a full system scan. Post the report and a new hjt log. Betcha that fixes it. thanks, v |
|
#32
| |||
| |||
| OK, Here is the latest HJT log : Logfile of HijackThis v1.99.1 Scan saved at 17:52:37, on 12/07/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Internet Explorer\iexplore.exe C:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPROV.EXE c:\PROGRA~1\COMMON~1\MICROS~1\Msinfo\OFFPRV10.EXE C:\WINDOWS\System32\msiexec.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://btinternet.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://btinternet.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://btinternet.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.btbroadbandstart.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S8C.tmp" /EF "HKCU" O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - http://esupport.epson-europe.com/sel...g/ESTPTest.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) - O17 - HKLM\System\CCS\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 O17 - HKLM\System\CS1\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe I will Now Post The AVG log Below |
|
#33
| |||
| |||
| Here is the AVG REPORT: THIS IS PART ONE,PART TWO ON NEXT POST!!!!! ---------------------------------------------------- AVG Anti-Spyware - Scan Report --------------------------------------------------------- + Created at: 17:46:43 12/07/2007 + Scan result: :mozilla.173:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.174:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.175:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.177:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.335:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.381:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@premiumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. :mozilla.442:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.443:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.444:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.176:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. :mozilla.178:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Adtech : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@adtech[2].txt -> TrackingCookie.Adtech : Cleaned. :mozilla.96:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.83:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.453:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.454:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.191:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. :mozilla.192:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Connextra : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@connextra[1].txt -> TrackingCookie.Connextra : Cleaned. :mozilla.224:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Dealtime : Cleaned. :mozilla.71:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. :mozilla.215:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.252:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.284:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.286:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.304:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.319:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.320:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.324:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.330:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.343:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.344:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.345:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.362:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.373:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.395:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkoapc5ceo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wfkycid5gfo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgkiumdzmdo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wgmiwlajgko.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6whmiwnajkaq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkokjajekp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjkysldpibq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4ckdpmaq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjl4qpazmeo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@e-2dj6wjlysidjiaq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.415:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.416:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.417:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.418:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.104:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.130:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. To big to post as one, next part in a mo below!!! |
|
#34
| |||
| |||
| Heres the rest of the AVG REPORT : :mozilla.20:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.445:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.446:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.447:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.448:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. :mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned. :mozilla.218:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.219:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Live : Cleaned. :mozilla.220:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Live : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@search.live[2].txt -> TrackingCookie.Live : Cleaned. :mozilla.308:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.457:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.239:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned. :mozilla.48:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned. :mozilla.419:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.420:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Msn : Cleaned. :mozilla.421:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Msn : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@auto.search.msn[1].txt -> TrackingCookie.Msn : Cleaned. :mozilla.164:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.165:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@ssl-hints.netflame[2].txt -> TrackingCookie.Netflame : Cleaned. :mozilla.100:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned. :mozilla.132:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Paypal : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned. :mozilla.298:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.299:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.261:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.262:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.263:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.264:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.265:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.436:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.462:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.357:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.358:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.359:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.360:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.122:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.123:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.124:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.211:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.212:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.213:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.414:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Owner\Cookies\owner@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.336:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\ebdan6iw.default\cookies.txt -> TrackingCookie.Xxxcounter : Cleaned. ::Report end And sad to say, still getting em!!!! Is this the time for new PC lol???? |
|
#35
| |||
| |||
| Jacob Every site that you go to on the internet will drop a cookie on you. This is not to say they all malicious. Obtaining a new pc will solve nothing. I know you may find this tedious but in the long term Valis will try his very best to get you back up and running. |
|
#36
| |||
| |||
| ok no probs, i really do appreciate all his help. fingers crossed lol |
|
#37
| |||
| |||
| open hjt, close all other windows, click 'perform system scan only', place a tick next to the following entries and click 'fix checked'. O17 - HKLM\System\CCS\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 O17 - HKLM\System\CS1\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 Reboot, and post a new log. Thanks, v |
|
#38
| |||
| |||
| Hi again!! Well heres the latest HJT log : Logfile of HijackThis v1.99.1 Scan saved at 23:17:09, on 12/07/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE C:\WINDOWS\system32\wscntfy.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Documents and Settings\Owner\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://btinternet.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://btinternet.com/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://btinternet.com/ R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.btbroadbandstart.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpdtlk02.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslstat.exe icon O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\BT Voyager 105 ADSL Modem\dslagent.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe O4 - HKCU\..\Run: [EPSON Stylus DX5000 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBVE.EXE /FU "C:\WINDOWS\TEMP\E_S8C.tmp" /EF "HKCU" O4 - Global Startup: BT Broadband Help.lnk = C:\Program Files\BT Broadband\Help\bin\matcli.exe O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM O8 - Extra context menu item: Lookup on Merriam Webster - file://C:\Program Files\ieSpell\Merriam Webster.HTM O8 - Extra context menu item: Lookup on Wikipedia - file://C:\Program Files\ieSpell\wikipedia.HTM O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/par...an_unicode.cab O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download Manager) - https://webdl.symantec.com/activex/symdlmgr.cab O16 - DPF: {79E0C1C0-316D-11D5-A72A-006097BFA1AC} (EPSON Web Printer-SelfTest Control Class) - http://esupport.epson-europe.com/sel...g/ESTPTest.cab O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0) - O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) - O17 - HKLM\System\CCS\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 O17 - HKLM\System\CS1\Services\Tcpip\..\{108DB8FD-F197-49AA-8627-EBB48F39E81D}: NameServer = 194.72.9.34 62.6.40.178 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe I have fixed the two you said and rebooted THREE TIMES!!!! But for some reason when I reboot,they reappear??????? Dont know why!!! Thanks |
|
#39
| |||
| |||
| try running hjt in safe mode and deleting them that way....see what happens....I'm pretty convinced that those are the issues....... thanks, v |
|
#40
| |||
| |||
| Hello again!!! Well it seems on the last hjt that no17 have now gone!! However as soon as i go back on line!! They reappear!!!!!! Just done anothjer scan now and there they are!!! Pretty clever ones I suppose!! So any ideas on where I go from here??? Once again,thanks for your help. Jim |
![]() |
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Software causing PC to go haywire? | SophieCella | General Software Chat | 3 | 9th Jun 2008 23:36 |
| Thread Tools | |
| |