Unable to access https websites and control panel - HELP!

  1. #1
    waimz is offline Newbie

    Unable to access https websites and control panel - HELP!

    Hi,

    I discovered this website when searching through google, and despite looking through all the current threads, i've been unable to find anyone with the same problem.

    A few weeks ago a window popped up asking if i wanted to download a anti-spyware/adware program (sorry can't remember which one it was). After clicking no, I was no longer able to access any security enabled webpages nor the control panel on my pc. Admittedly the pc is a little old, Windows NT Professional, but its stopping me from checking emails etc. Any thoughts on how to fix it?

    Ta.


  2. #2
    waimz is offline Newbie
    Sorry,

    forgot to add details. Have Norton Installed, scan reveals nothing. Also did a scan with the online Avast virus tool....nothing! and finally just downloaded HijackThis and did a scan. Here's the log:

    Logfile of HijackThis v1.99.1
    Scan saved at 7:20:06 PM, on 28/10/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\csrss.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\WINNT\System32\CTSVCCDA.EXE
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\hidserv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\RUNDLL32.EXE
    C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
    C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\Creative\ShareDLL\MediaDet.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\Go ogleToolbarNotifier.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Common Files\Symantec Shared\AdBlocking\NSMdtr.exe
    C:\Documents and Settings\davissl\Local Settings\Temporary Internet Files\Content.IE5\MZ6HQR69\aswclnr[1].exe
    C:\Documents and Settings\davissl\Local Settings\Temporary Internet Files\Content.IE5\MZ6HQR69\aswclnr[1].tmp
    C:\Program Files\Common Files\Symantec Shared\NMain.exe
    C:\Documents and Settings\davissl\Desktop\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.creative.com
    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
    O4 - HKCU\..\Run: [ErrorSafe] "C:\Program Files\ErrorSafe Free\UERS.exe" /min
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\2\E_SRCV03. EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
    O14 - IERESET.INF: START_PAGE_URL=http://www.creative.com
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/62...bridge-c46.cab
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-au/aup/games1.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7D06D416-778D-4BEF-AEB3-0E5BD2429076}: NameServer = 203.30.19.12,203.30.19.15
    O20 - Winlogon Notify: yvbb01 - C:\WINNT\SYSTEM32\yvbb01.dll
    O20 - Winlogon Notify: yvpp01 - yvpp01.dll (file missing)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSVCCDA.EXE
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

  3. #3
    VopThis is offline Senior Member (Canada)
    Uninstall 'ErrorSafe':

    http://www.bleepingcomputer.com/unin...1.3.139.3.html



    You are not running HijackThis (HJT) from a desired location. You really need to setup a dedicated folder for HJT items – to avoid horrible clutter and/or potential lost backup issues.

    It's best that the HijackThis tool NOT be located in its current location (particularly on your Desktop or in a TEMP folder). This way you can more easily undo any changes if something goes wrong.
    • Create a new folder in your C: Drive.
    • Name the FOLDER HijackThis (or HJT) such as C:\Program Files\HijackThis or C:\HJT and move the HijackThis.exe file into it.
    • Run HJT from there (and revise your shortcut accordingly).
    C:\Documents and Settings\davissl\Desktop\HijackThis.exe



    We will be restarting into Safe Mode later on in the fix and you might not be able to access the Internet. Accordingly, it is probably a good idea to print out the following directions or copy them to a text file on your desktop using NOTEPAD. Read these instructions carefully and feel free to ask if you're unsure about anything.




    Clean out TEMPORARY FILES procedures:
    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner http://www.ccleaner.com/downloadbuilds.asp

    Install Options:
    • Don't install any Toolbars, or other programs, should it ask you!
    • Just uncheck the option of installing the Yahoo toolbar.

    It will put a shortcut on your Desktop.

    Do not run CCleaner until requested later.





    Download and install AVG Anti-Spyware 7.5 (formally known as Ewido anti-spyware 4.0 - uninstall any previous version first).
    • Click the Download BUTTON. On the next page click the Download now BUTTON.
    • Save and then install (Run) from the save location.
    • Open/Run ewido anti-spyware
    • Wait a few moments and Ewido should Auto update itself (note date of last update). If it doesn't update, click the update ICON at top of screen:

    • Click on the Update now LINK at the top of the window
      • Click on the Start update button
      • Wait for the update to download and install
  4. This is very important to get the LATEST updates
  5. Click on the Status ICON
    • Under "Your computers Security"
      Click change status on Resident shield to inactive (ONLY consider activation of that feature once you are clean)
  6. Click on the Scanner ICON at the top of the window
  7. Click on the Settings tab then select Recommended Actions and choose Quarantine
  8. When updating has finished. Close Ewido.



  9. We will be using this tool in a later step.




    Reboot your computer in Safe Mode.
    • If the computer is running, shut down Windows, and then turn off the power.
    • Wait 30 seconds, and then turn the computer on.
    • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
    • Ensure that the Safe Mode option is selected.
    • Press Enter. The computer then begins to start in Safe mode.
    • Login on your usual account.
    ______________________________



    Run CCleaner .
    Select the ‘Cleaner’ BUTTON option (top LEFT), if not already selected. Use the ’Windows’ TAB up front by default.
    • Uncheck ‘Cookies’ option (advisable)
    • Optionally, Uncheck ‘Recently Typed URLs’ option (potentially still useful)
    • Click the ‘Analyse’ button.
    • Thereafter, click ‘Run Cleaner’ after you have reviewed what it proposes to clean.




    Close ALL open Windows / Programs / Folders. Please start Ewido, and run a full scan:
    • Click on the default Status ICON and select the Scan now LINK.

      OR

    • Click on the Scanner ICON . Select the Scan TAB.

      • Select Complete System Scan. Ewido will now begin to scan your system.

    • If Ewido finds anything it will list them in the Preview WINDOW:
      • Make sure that Set all elements to: shows Quarantine, if not click on the link and choose Quarantine from the popup menu.
      • Select Apply all actions at the bottom of the window (and the items found will be quarantined – and recoverable, if any items are needed back).

    • When the scan has completed, click on the Save Scan Report button and save the scan to your Desktop where it can be easily found.
    • Copy and paste the EWIDO scan results into your next post.
    • Close Ewido.


    Post your latest HijackThis log and let us know how your PC is now behaving.
Last edited by VopThis; 28-10-2006 at 04:38 PM.

  • #4
    waimz is offline Newbie
    Thanks for your help!

    I can't seem to download the updates for Ewido at the moment but noticed that a few other people have had this problem in the past (dodgy server!), so i'll try again in the morning and then proceed with the other steps.

    Thanks again!!!

  • #5
    waimz is offline Newbie
    Unfortunately I still can't update...but I did notice when trying to update Spybot that it wouldn't allow me to connect to the server there either but I haven't had any problems with my internet connection (broadband).

    I went ahead with the final steps and ran Ewido, but it hasn't helped fix the problem. :-(. I quarantined the Adware and deleted the rest, then rebooted my pc. A final detail, however, when i go to access my control panel, everything disappears from the screen and an old screensaver pops up, then remains frozen there. This same screensaver (a pic - one of my own) comes up when the pc logs in as well, initially anyway, and then the new screensaver resumes. Its been happening for so long now that i've gotten so used to it.

    Here are the results of the Ewido scan:
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 333 AM 29/10/2006

    + Scan result:



    HKLM\SOFTWARE\Gator.com -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\GInternet -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\GInternet\Proxy -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\dyn -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_gi -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_trickle -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\dyn\GCH\_ts -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Gator.com\Gator\stat -> Adware.Gator : Ignored.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Ignored.
    C:\Program Files\Media Access -> Adware.MediaAccess : Ignored.
    HKLM\SOFTWARE\Classes\MediaAccX.Installer -> Adware.WinAd : Ignored.
    HKLM\SOFTWARE\Classes\MediaAccX.Installer\CLSID -> Adware.WinAd : Ignored.
    HKLM\SOFTWARE\Classes\MediaAccess.Installer -> Adware.WinAd : Ignored.
    HKLM\SOFTWARE\Classes\MediaAccess.Installer\CLSID -> Adware.WinAd : Ignored.
    HKLM\SOFTWARE\Classes\MediaAccess.Installer\CurVer -> Adware.WinAd : Ignored.
    HKLM\SOFTWARE\Media Access -> Adware.WinAD : Ignored.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uni nstall\Media Access -> Adware.WinAD : Ignored.
    C:\WINNT\Downloaded Program Files\UERS_0001_N68M1801NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.d : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@247realmedia[2].txt -> TrackingCookie.247realmedia : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@2o7[2].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@americanexpress.1 22.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@aotgroup.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@eurostar.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@geosign.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@hertz.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@mckinseyknowledge .122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@msninvite.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@nbcuniversal.122. 2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@qantasairways.122 .2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@skyauction.122.2o 7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@symantec.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@taylorgifts.122.2 o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@thomascook.122.2o 7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@thriftyaustralia. 122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@virginmoneyaustra lia.122.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@wotifcom.112.2o7[1].txt -> TrackingCookie.2o7 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@adbrite[2].txt -> TrackingCookie.Adbrite : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@admarketplace[1].txt -> TrackingCookie.Admarketplace : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@adrevolver[2].txt -> TrackingCookie.Adrevolver : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@z1.adserver[1].txt -> TrackingCookie.Adserver : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@adtech[2].txt -> TrackingCookie.Adtech : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@servedby.advertis ing[1].txt -> TrackingCookie.Advertising : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@advertising[1].txt -> TrackingCookie.Advertising : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@servedby.advertis ing[1].txt -> TrackingCookie.Advertising : Ignored.
    C:\Documents and Settings\Administrator\Cookies\administrator@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@atdmt[1].txt -> TrackingCookie.Atdmt : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@bfast[2].txt -> TrackingCookie.Bfast : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@bfast[1].txt -> TrackingCookie.Bfast : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@bluemountain[1].txt -> TrackingCookie.Bluemountain : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@bluestreak[1].txt -> TrackingCookie.Bluestreak : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@rccl.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@burstnet[2].txt -> TrackingCookie.Burstnet : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@www.burstnet[1].txt -> TrackingCookie.Burstnet : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@casalemedia[2].txt -> TrackingCookie.Casalemedia : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@clickbank[2].txt -> TrackingCookie.Clickbank : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@com[1].txt -> TrackingCookie.Com : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfk4kgdpslo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfk4ugd5ckp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkiqnd5whq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkiwgdjiao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkiwhcjcgo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkyqkczgbo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkysgdzkco.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkysndjkbo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkyuidjcfo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfkywhdjmdp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfliakd5ihp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfliooczilo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfloehd5mco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfloqidzsap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wflosiajsco.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wflyamazchq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wflykgd5akp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wflyukcpklq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wflyundjobo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfmicgc5gkq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfmigndpadp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfmikodzghp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfmywjc5wao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wfmywncpwkp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgk4glcpwbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkialcjcfo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkisldpoap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkiuidzecq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkychajeeo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkyghdpccq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkyopazkbq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkyopdpwaq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgkyslajiao.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wglokoczoeq.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wglowgdzmco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wgmyujdzseo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6whkismc5gbp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjk4egazogo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjkyelczkfp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjkykicpodp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjl4agczeho.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjl4wmd5sco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjliopdjeeo.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlisic5sbp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlisoajeco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlocjc5gko.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlocmdzsfp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjloejajmep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlogid5idp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlokmdpmgp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjlyamcjedp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjmicmczgco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjmyagajalp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjmyaid5cco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjmyqgdpocq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjnyakazicq.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjnyckcpmap.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjnyepdjsep.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@e-2dj6wjnyokcjcco.stats.esomniture[2].txt -> TrackingCookie.Esomniture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@as-us.falkag[1].txt -> TrackingCookie.Falkag : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@fastclick[1].txt -> TrackingCookie.Fastclick : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@fastclick[1].txt -> TrackingCookie.Fastclick : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@fastclick[2].txt -> TrackingCookie.Fastclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@c.goclick[2].txt -> TrackingCookie.Goclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-alkemi.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-baa.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-designwithinreach.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-foxmovies.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-hobsons.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-lhw.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-netbankinc.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-pfizer.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-pureprofile.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-queenslanddpc.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-samsungusa.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-simon.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-thegoldmansachsgroup.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-theheritagefoundation.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-tourismqueensland.hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-uniontrib.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ehg-zoom.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@hg1.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@phg.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@hitbox[1].txt -> TrackingCookie.Hitbox : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@counter.hitslink[2].txt -> TrackingCookie.Hitslink : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@hotlog[1].txt -> TrackingCookie.Hotlog : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@ads.link4ads[2].txt -> TrackingCookie.Link4ads : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@linksynergy[2].txt -> TrackingCookie.Linksynergy : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@server.iad.livepe rson[1].txt -> TrackingCookie.Liveperson : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@www.myaffiliatepr ogram[1].txt -> TrackingCookie.Myaffiliateprogram : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@stat.onestat[2].txt -> TrackingCookie.Onestat : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@data1.perf.overtu re[2].txt -> TrackingCookie.Overture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@data2.perf.overtu re[1].txt -> TrackingCookie.Overture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@data4.perf.overtu re[2].txt -> TrackingCookie.Overture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@overture[1].txt -> TrackingCookie.Overture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@perf.overture[1].txt -> TrackingCookie.Overture : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@popupsponsor[1].txt -> TrackingCookie.Popupsponsor : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@pro-market[1].txt -> TrackingCookie.Pro-market : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@qksrv[1].txt -> TrackingCookie.Qksrv : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@www.qksrv[1].txt -> TrackingCookie.Qksrv : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@questionmarket[2].txt -> TrackingCookie.Questionmarket : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@stats1.reliablest ats[1].txt -> TrackingCookie.Reliablestats : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ads0.revenue[1].txt -> TrackingCookie.Revenue : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@revenue[2].txt -> TrackingCookie.Revenue : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@edge.ru4[1].txt -> TrackingCookie.Ru4 : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@ru4[1].txt -> TrackingCookie.Ru4 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@serving-sys[2].txt -> TrackingCookie.Serving-sys : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@adopt.specificcli ck[2].txt -> TrackingCookie.Specificclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@spylog[2].txt -> TrackingCookie.Spylog : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@statcounter[2].txt -> TrackingCookie.Statcounter : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@tacoda[1].txt -> TrackingCookie.Tacoda : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@trafficmp[1].txt -> TrackingCookie.Trafficmp : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@blp.valueclick[1].txt -> TrackingCookie.Valueclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@valueclick[1].txt -> TrackingCookie.Valueclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@valueclick[2].txt -> TrackingCookie.Valueclick : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@webstat[2].txt -> TrackingCookie.Web-stat : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@bnpparibas.webora ma[2].txt -> TrackingCookie.Weborama : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@statse.webtrendsl ive[2].txt -> TrackingCookie.Webtrendslive : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@statse.webtrendsl ive[1].txt -> TrackingCookie.Webtrendslive : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@x10[1].txt -> TrackingCookie.X10 : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@c1.zedo[1].txt -> TrackingCookie.Zedo : Ignored.
    C:\Documents and Settings\davissl\Cookies\davissl@zedo[1].txt -> TrackingCookie.Zedo : Ignored.
    C:\temp\sd2backup\Documents and Settings\davissl\Cookies\davissl@zedo[1].txt -> TrackingCookie.Zedo : Ignored.


    ::Report end


    And HiJackThis:

    Logfile of HijackThis v1.99.1
    Scan saved at 3:32:39 AM, on 29/10/2006
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\csrss.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    C:\Program Files\Norton Internet Security\ISSVC.exe
    C:\WINNT\system32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\WINNT\system32\spoolsv.exe
    C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINNT\System32\CTSVCCDA.EXE
    C:\WINNT\System32\svchost.exe
    C:\WINNT\system32\hidserv.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    C:\WINNT\System32\nvsvc32.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\WINNT\System32\mspmspsv.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\RUNDLL32.EXE
    C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe
    C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
    C:\Program Files\Creative\ShareDLL\CtNotify.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\Program Files\Creative\ShareDLL\MediaDet.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\WINNT\system32\ctfmon.exe
    C:\Program Files\MSN Messenger\msnmsgr.exe
    C:\Program Files\Skype\Phone\Skype.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\HiJackThis\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.creative.com
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: CNisExtBho Class - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
    O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [LoadQM] loadqm.exe
    O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
    O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
    O4 - HKLM\..\Run: [Drag'n Drop CD] C:\Program Files\Drag'n Drop CD\BinFiles\DragDrop.exe /StartUp
    O4 - HKLM\..\Run: [Creative WebCam Tray] C:\Program Files\Creative\WebCam Control\CAMTRAY.EXE
    O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
    O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\Go ogleToolbarNotifier.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINNT\system32\spool\drivers\w32x86\2\E_SRCV03. EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
    O14 - IERESET.INF: START_PAGE_URL=http://www.creative.com
    O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/62...bridge-c46.cab
    O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
    O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-au/aup/games1.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{7D06D416-778D-4BEF-AEB3-0E5BD2429076}: NameServer = 203.30.19.12,203.30.19.15
    O20 - Winlogon Notify: yvbb01 - C:\WINNT\SYSTEM32\yvbb01.dll
    O20 - Winlogon Notify: yvpp01 - yvpp01.dll (file missing)
    O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
    O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
    O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSVCCDA.EXE
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Program Files\Norton Internet Security\ISSVC.exe
    O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
    O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
    O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
    O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
    O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
    O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe

    Any further suggests are greatly appreciated!!!

  • #6
    VopThis is offline Senior Member (Canada)
    I went ahead with the final steps and ran Ewido, but it hasn't helped fix the problem. :-(. I quarantined the Adware and deleted the rest
    Your AVG Anti-Spyware LOG reports all items found by it were 'ignored'. Please re-read my instructions to set the default action to 'quarantine' and re-run AVG AS to verify that no items were missed (if there is any doubt).



    Download haxfix.exe and save it to your desktop.


    Double click on haxfix.exe to install it. Check "Create a desktop icon" and click "Next". When the installation is completed, make sure that that "Launch HaxFix" is checked. Click "Finish".

    A red "dos window" (dos box) will open with options:
    1. Make logfile
    2. Run auto fix
    3. Run manual fix
    E. Exit Haxfix

    Select option 1. Make logfile by typing 1 and then pressing Enter. Haxfix will start scanning the computer. When it is finished a logfile will open > haxlog.txt. Copy the contents of that logfile and paste it into this thread please.

  • #7
    waimz is offline Newbie
    Great news, its fixed!

    I ran ewido again, but not in safemode, and then haxfix, then rebooted. Somewhere along the line it must have cleared whatever it was that was stopping me from getting onto secure sites. Weird though that I still can't run updates on Ewido but Spybot is back up and running. No matter, as long as I can check my email again, I'm a happy camper!

    Thank you SO MUCH!

  • #8
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    The absence of obvious problems does not guarantee that all your malware issues have been resolved.

    You should post a revised HijackThis LOG and a HaxFix LOG (option 1 - did you select any other option while using this tool?).

  • + Reply to Thread

    Similar Threads