0

Been having a problem for the last week - IE 6 shuts down when accessing certain websites only. So far haven't had the same problem with Firefox. Have done a virus check, nothing found. Have downloaded all the Windows updates. Have run Adaware and Spybot and removed all problems, IE 6 problem still happening. No error given, it just closes as soon as the page loads. I just ran HijackThis - here's my log. Thanks for the help!
-RH

Logfile of HijackThis v1.99.1
Scan saved at 10:50:50 PM, on 4/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\NDAS\System\ndassvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\NDAS\System\ndasmgmt.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\OPScan.exe
C:\Documents and Settings\Renee Hacker\My Documents\HJT\hijackthis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136063897296
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SNMP Trap Service (SNMPTRAP) - Unknown owner - C:\WINDOWS\system32\snmptrap.exe (file missing)
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

4
Contributors
8
Replies
9
Views
11 Years
Discussion Span
Last Post by eiuasa
0

Can anyone help with this? My IE 6 browser continues to close on me at random times...very frustrating!!

Thanks!

0

Hi, sorry for the late reply, we must have missed you. Please start HJT again, and check off the following items.

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://ie.redirect.hp.com/svs/rdr?TY...lion&pf=laptop

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost


Click Fix Checked

------------------------------------------------------------------------

Then please download ewido - www.ewido.net - Install. Update. Scan. Remove anything it finds. Save the log, and post it along with a new HJT log.

0

Ok, did as you instructed. Here is the hijackthis log and the ewido scan report. Incidently, IE 6 is still shutting down. :confused: Thanks for your help!
Renee

Logfile of HijackThis v1.99.1
Scan saved at 7:02:15 PM, on 4/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton Internet Security\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\NDAS\System\ndassvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\NDAS\System\ndasmgmt.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\ewido anti-malware\ewidoguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\OPScan.exe
C:\Documents and Settings\Renee Hacker\My Documents\HJT\hijackthis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [LSBWatcher] c:\hp\drivers\hplsbwatcher\lsburnwatcher.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: NDAS Device Management.lnk = C:\Program Files\NDAS\System\ndasmgmt.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop
O16 - DPF: {14C1B87C-3342-445F-9B5E-365FF330A3AC} (Hewlett-Packard Online Support Services) - http://h20278.www2.hp.com/HPISWeb/Customer/cabs/HPISDataManager.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eBay_Enhanced_Picture_Control_v1-0-3-36.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136063897296
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {BD8667B7-38D8-4C77-B580-18C3E146372C} (Creative Toolbox Plug-in) - http://www.imgag.com/cp/install/Crusher.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by101fd.bay101.hotmail.msn.com/activex/HMAtchmt.ocx
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: NDAS Service (ndassvc) - XIMETA, Inc. - C:\Program Files\NDAS\System\ndassvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SNMP Trap Service (SNMPTRAP) - Unknown owner - C:\WINDOWS\system32\snmptrap.exe (file missing)
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 6:58:25 PM, 4/27/2006
+ Report-Checksum: 8D809B87

+ Scan result:

:mozilla.6:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.97:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.124:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.176:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.177:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.353:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.354:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.371:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.382:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.383:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.407:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
:mozilla.422:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.423:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.424:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.425:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.426:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.429:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.430:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.431:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.432:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.475:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.476:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.477:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.493:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.494:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.495:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.496:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.497:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.498:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.499:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.502:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.503:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.534:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.535:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned with backup
:mozilla.572:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.616:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.617:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.618:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.619:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.620:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.621:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.622:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.623:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.624:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.625:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.626:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.627:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.628:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.629:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.630:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.631:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.632:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.633:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.634:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.635:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup
:mozilla.665:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.666:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
:mozilla.736:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.737:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.738:C:\Documents and Settings\Renee Hacker\Application Data\Mozilla\Firefox\Profiles\a8y48hcc.default\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Cookies\renee [email]hacker@2o7[1].txt[/email] -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Cookies\renee [email]hacker@bellglobemediapublishing.122.2o7[1].txt[/email] -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Cookies\renee [email]hacker@rotator.adjuggler[1].txt[/email] -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Cookies\renee [email]hacker@www.myaffiliateprogram[1].txt[/email] -> TrackingCookie.Myaffiliateprogram : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@adopt.specificclick[1].txt[/email] -> TrackingCookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@burstnet[2].txt[/email] -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@com[1].txt[/email] -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@dealnews.122.2o7[1].txt[/email] -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@msnportal.112.2o7[1].txt[/email] -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@tacoda[1].txt[/email] -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Renee Hacker\Local Settings\Temp\Cookies\renee [email]hacker@www.burstbeacon[1].txt[/email] -> TrackingCookie.Burstbeacon : Cleaned with backup


::Report End

0

Hmm, the Ewido log's clean except for cookies, which is alrite.

The HJT log is clean, except for 1 entry. Fix the following:

O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop

Now thinking about it, it wouldn't hurt to redownload IE.

Follow these steps:

Please go to:
start-->run

and type this in:
regedit

Then click on the FILE menu and select export
Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL

Then, go to start-->run

and type this in:
notepad

Paste this into the box:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\
{89820200-ECBD-11cf-8B85-00AA005B4383}]
"IsInstalled"=dword:00000000

Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file


Now double click on fixreg.reg and insert it into the registry.

Then, go here, and reinstall Internet Explorer:
Internet Explorer Update

After doing all of this, post back with an update on how it's comin along.

Thanks.

0

Like many other users I clicked on the link too. I have no idea what to do. But I did do the HijackThis thing. If anyone can help, that would be great! Here's my log:


Logfile of HijackThis v1.99.1
Scan saved at 11:05:08 PM, on 4/27/2006
Platform: Windows XP SP2 (WinNT

5.01.2600)
MSIE: Internet Explorer v6.00 SP2

(6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program

Files\Java\jre1.5.0_03\bin\jusched.exe
C:\Program Files\CA\eTrust EZ

Armor\eTrust

Anti-Spam\QSP-2.1.215.5\QOELoader.exe
C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\CAVTray.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\AIM\aim.exe
C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\ISafe.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\regsvr32.exe
C:\Program Files\Common

Files\Real\Update_OB\realsched.exe
C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\Mozilla

Firefox\firefox.exe
C:\DOCUMENTS AND SETTINGS\ROBERTA NAD

AARON\DESKTOP\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customiz

e/ycomp/defaults/sb/*http://www.yahoo.co

m/search/ie.html
R1 - HKCU\Software\Microsoft\Internet

Explorer\Main,Search Page =

http://red.clientapps.yahoo.com/customiz

e/ycomp/defaults/sp/*http://www.yahoo.co

m
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Default_Page_URL =

http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet

Explorer\Main,Search Bar =

http://red.clientapps.yahoo.com/customiz

e/ie/defaults/sb/ymsgr6/*http://www.yaho

o.com/ext/search/search.html
R0 - HKLM\Software\Microsoft\Internet

Explorer\Main,Start Page =

http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet

Explorer\SearchURL,(Default) =

http://red.clientapps.yahoo.com/customiz

e/ie/defaults/su/ymsgr6/*http://www.yaho

o.com
O2 - BHO: AcroIEHlprObj Class -

{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -

C:\Program Files\Adobe\Acrobat

6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) -

{53707962-6F74-2D53-2644-206D7942484F} -

C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client]

"C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Firewall\ca.exe"
O4 - HKLM\..\Run: [TkBellExe]

"C:\Program Files\Common

Files\Real\Update_OB\realsched.exe"

-osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched]

C:\Program

Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [S3TRAY2] S3tray2.exe
O4 - HKLM\..\Run: [QuickTime Task]

"C:\Program Files\QuickTime\qttask.exe"

-atboottime
O4 - HKLM\..\Run: [QOELOADER]

"C:\Program Files\CA\eTrust EZ

Armor\eTrust

Anti-Spam\QSP-2.1.215.5\QOELoader.exe"
O4 - HKLM\..\Run: [MW1HelperStartUp]

C:\PROGRA~1\MAGICW~1\MW1HEL~1.EXE

/partner MW1
O4 - HKLM\..\Run: [Lexmark X74-X75]

"C:\Program Files\Lexmark

X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe

"C:\Program

Files\AIM\\DeadAIM.ocm",ExportedCheckODL

s
O4 - HKLM\..\Run: [CAVRID] "C:\Program

Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program

Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [AlcxMonitor]

ALCXMNTR.EXE
O4 - HKCU\..\Run: [Yahoo! Pager]

"C:\Program

Files\Yahoo!\Messenger\ypager.exe"

-quiet
O4 - HKCU\..\Run: [AIM] C:\Program

Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Microsoft

Office.lnk = C:\Program Files\Microsoft

Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to

Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCE

L.EXE/3000
O9 - Extra button: AIM -

{AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} -

C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows

Messenger -

{FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O16 - DPF:

{17492023-C23A-453E-A040-C7C580BBF700}

(Windows Genuine Advantage Validation

Tool) -

http://go.microsoft.com/fwlink/?linkid=3

9204
O23 - Service: CAISafe - Computer

Associates International, Inc. -

C:\Program Files\CA\eTrust EZ

Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: Microsoft DLL

Registration Component (DLLReg) -

Unknown owner - C:\WINDOWS\regsvr32.exe
O23 - Service: LexBce Server (LexBceS) -

Lexmark International, Inc. -

C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service

(VETMSGNT) - Computer Associates

International, Inc. - C:\Program

Files\CA\eTrust EZ Armor\eTrust EZ

Antivirus\VetMsg.exe
O23 - Service: TrueVector Internet

Monitor (vsmon) - Zone Labs Inc. -

C:\WINDOWS\system32\ZoneLabs\vsmon.exe

0

Ok, did everything you instructed, but when I try to reinstall IE I get this pop up windows message:

"Setup has detected a newer version on Internet Explorer already installed on this system. Setup cannot continue."

Looks like I'm running IE 6, SP2 - this download is for SP1. But I can't seem to find a download on Microsoft's website to reinstall the SP2 version.

Thoughts??

Renee

Hmm, the Ewido log's clean except for cookies, which is alrite.

The HJT log is clean, except for 1 entry. Fix the following:

O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q305&bd=pavilion&pf=laptop

Now thinking about it, it wouldn't hurt to redownload IE.

Follow these steps:

Please go to:
start-->run

and type this in:
regedit

Then click on the FILE menu and select export
Save the file as backup. Save the file somewhere you will remember and not delete.
IMPORTANT: make sure to set the export range to ALL

Then, go to start-->run

and type this in:
notepad

Paste this into the box:

Windows Registry Editor Version 5.00

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\
{89820200-ECBD-11cf-8B85-00AA005B4383}]
"IsInstalled"=dword:00000000

Then click on the FILE menu and select save as
Save the file as regfix.reg. Save the file to the desktop.
IMPORTANT: make sure to save the file as "all types" and NOT as a text file


Now double click on fixreg.reg and insert it into the registry.

Then, go here, and reinstall Internet Explorer:
Internet Explorer Update

After doing all of this, post back with an update on how it's comin along.

Thanks.

0

<Bump> Any thoughts on what I should do next since I couldn't reinstall IE6?

Renee

Ok, did everything you instructed, but when I try to reinstall IE I get this pop up windows message:

"Setup has detected a newer version on Internet Explorer already installed on this system. Setup cannot continue."

Looks like I'm running IE 6, SP2 - this download is for SP1. But I can't seem to find a download on Microsoft's website to reinstall the SP2 version.

Thoughts??

Renee

This topic has been dead for over six months. Start a new discussion instead.
Have something to contribute to this discussion? Please be thoughtful, detailed and courteous, and be sure to adhere to our posting rules.