Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Trojan-spy.HTML.smitfraud.c infestation-LauraM[RESOLVED]


  • This topic is locked This topic is locked

#1
LauraannM

LauraannM

    Member

  • Member
  • PipPip
  • 19 posts
Hi. My name is Laura. I have been having some serious problems with my computer lately, mostly, I believe from my son (9) downloading games with critters attached.

We recently moved; when I set up my 'puter, it crashed. I ended up reloading XP hoping that would solve my problems, as I could never find anything on scan (I have McAffee).

As of two days ago, things started happening in my browser (IE), and then I lost it. Before I lost it, I tried going to the McAffee homepage, and kept getting sent to a specific "search engine" instead, (web addy: http://www.seeq.com/...rer=&pop=false)

When I rebooted my system, I got the "Security Warning - A Fatal Error Has Occured" and then tells me is has been caused by "Trojan-spy.HTML.smitfraud.c". and am no longer able to run XP, and cannot even find the IE browser (I had to download netscape so that I could figure this stuff out!! The only way I have computer access is to hit "Control-alt-delete", and then when the window pops up, I have to click on new task, and then browse to access anything in my computer.

Long story short, I came accross your site while doing a search for the trojan's name on YaHoo! and after registering, I came to your page of what do do if I suspect "malware". I followed your recommendations, downloades the anti-spywares and then the scanning software, fixed the problems that were encountered, and deleted the trojans, etc. and then the computer required a reboot. NOW the blue screen with the "fatal error" has been replaced with a black screen with NO words. Luckily, my "control-alt-delete" method continues to function, hence my ability to write to you here now. I have been unable to "unzip" anything, so downloading a zipped file doesn't help me.

Please help me; I NEED my computer and I PROMISE that my son will NEVER touch it again!!!

LauraM

Edited by LauraannM, 20 May 2005 - 05:06 PM.

  • 0

Advertisements


#2
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 9:25:10 PM, on 5/16/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\Program Files\Hijack this\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapp.../search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapp...//www.yahoo.com
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunOnce: [BrandClearStubs] RUNDLL32 IEDKCS32.DLL,BrandCleanInstallStubs >{7C356477-EBB4-4C35-B5F9-39058275DCDC}
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\system32\SMSSU.EXE
O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\system32\Tmntsrv32.EXE
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\THEWEA~1.EXE
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra button: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Heavy Cannon by pogo - http://playweb04.pog...n-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.co...w-ob-assets.cab
O16 - DPF: Pebble Beach 3 Hole Challenge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Ricochet by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Tank Hunter by pogo - http://playweb06.pog...k-ob-assets.cab
O16 - DPF: Tube Runner by pogo - http://playweb14.pog...e-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - https://objects.aol....83/mcinsctl.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - https://objects.aol....,20/McGDMgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Thanks for helping me!!

LauraM
  • 0

#3
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
I'm sad. I posted 4 days ago, and not one reply....or acknowledgement to my plea for help!!

Here is my latest log:

Logfile of HijackThis v1.99.1
Scan saved at 6:49:42 PM, on 5/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\America Online 9.0d\waol.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0d\aolwbspd.exe
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\Program Files\Hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\McAfee.com\Agent\mcupdate.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\RunOnce: [BrandClearStubs] RUNDLL32 IEDKCS32.DLL,BrandCleanInstallStubs >{7C356477-EBB4-4C35-B5F9-39058275DCDC}
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\system32\SMSSU.EXE
O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\system32\Tmntsrv32.EXE
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\THEWEA~1.EXE
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra button: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Heavy Cannon by pogo - http://playweb04.pog...n-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.co...w-ob-assets.cab
O16 - DPF: Pebble Beach 3 Hole Challenge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Ricochet by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Tank Hunter by pogo - http://playweb06.pog...k-ob-assets.cab
O16 - DPF: Tube Runner by pogo - http://playweb14.pog...e-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - https://objects.aol....83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1116524475265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - https://objects.aol....,20/McGDMgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

:tazz:
  • 0

#4
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Ok, while I am waiting for replies, I have been reading replies to other people. I saw one that told the person to go to regedit and delete a couple of keys, and I checked my file also. Low and behold, I had the same "keys" so I deleted them...crossing my fingers all the while.

THEY WORKED!!! I now have access to windows and IE again!!!

However, when I clicked on IE, instead of my homepage, I get a blank screen which says "about:blank".

Does this mean I still have an infection???
  • 0

#5
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Logfile of HijackThis v1.99.1
Scan saved at 8:16:32 PM, on 5/20/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\wanmpsvc.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
c:\program files\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\THEWEA~1\THEWEA~1.EXE
C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\WINDOWS\system32\wuauclt.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\PROGRA~1\Netscape\Netscape\Netscp.exe
C:\Program Files\Hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\system32\SMSSU.EXE
O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\system32\Tmntsrv32.EXE
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\THEWEA~1.EXE
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra button: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Heavy Cannon by pogo - http://playweb04.pog...n-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.co...w-ob-assets.cab
O16 - DPF: Pebble Beach 3 Hole Challenge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Ricochet by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Tank Hunter by pogo - http://playweb06.pog...k-ob-assets.cab
O16 - DPF: Tube Runner by pogo - http://playweb14.pog...e-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - https://objects.aol....83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1116524475265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - https://objects.aol....,20/McGDMgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
  • 0

#6
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
That's what we called BUMPED to death.
There are so many replies in this thread that everyone must have thought you were being helped.

Close as many programs and windows as possible.

Copy the part below into notepad and save it as unhko.reg

REGEDIT4

[-HKEY_CLASSES_ROOT\CLSID\{60371670-81B9-4d06-9C42-4DEC1AABE62B}]

[-HKEY_CLASSES_ROOT\TypeLib\{4947DDCC-D549-4D0B-9685-AA58B20E9642}]

[-HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}]

[-HKEY_CLASSES_ROOT\CLSID\{60371670-81B9-4d06-9C42-4DEC1AABE62B}]

[-HKEY_CLASSES_ROOT\TypeLib\{4947DDCC-D549-4D0B-9685-AA58B20E9642}]

[-HKEY_CLASSES_ROOT\Interface\{0B6EF17E-18E5-4449-86EA-64C82D596EAE}]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\ATLASSstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\HTASSstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\MSMsgSvc]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SEHLPstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\WTLBAstp]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\iexplore.exe]

[-HKEY_CLASSES_ROOT\BHOASS.BHDP]

[-HKEY_CLASSES_ROOT\BHOASS.BHDP.1]


Doubleclick the file and confirm you want to merge it with the registry.

*Click Here to download Killbox by Option^Explicit.
*Extract the program to your desktop and double-click on its folder, then double-click on Killbox.exe to start the program.
*In the killbox program, select the Delete on Reboot option.
*Open the text file with these instructions in it, and copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\System32\SMSSU.EXE
C:\WINDOWS\System32\Tmntsrv32.EXE
C:\Windows\explorer32dbg.exe
C:\Windows\iexplore_dbg.exe


Return to Killbox, go to the File menu, and choose "Paste from Clipboard".
Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

After the reboot, check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

O4 - HKCU\..\Run: [SMSSU] C:\WINDOWS\system32\SMSSU.EXE
O4 - HKCU\..\Run: [Tmntsrv32] C:\WINDOWS\system32\Tmntsrv32.EXE

O9 - Extra button: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)
O9 - Extra 'Tools' menuitem: Microsoft AntiSpyware helper - {13AD183B-A46C-408E-A718-13E1641886F4} - (no file) (HKCU)

Reboot once more and post a new log.

Regards,
  • 0

#7
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Done.

Logfile of HijackThis v1.99.1
Scan saved at 6:45:11 PM, on 5/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\wanmpsvc.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\hkcmd.exe
c:\program files\mcafee.com\agent\mcagent.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Netscape\Netscape\Netscp.exe
C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
C:\Program Files\America Online 9.0d\aoltray.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
c:\progra~1\mcafee.com\vso\mcvsftsn.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O1 - Hosts: 64.91.255.87 www.dcsresearch.com
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PosHelp - {CDEEC43D-3572-4E95-A2A5-F519D29F00C0} - C:\PROGRA~1\ADVANC~1\ADVANC~1.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Mozilla Quick Launch] "C:\Program Files\Netscape\Netscape\Netscp.exe" -turbo
O4 - HKCU\..\Run: [Desktop Weather 3] C:\PROGRA~1\THEWEA~1\The Weather Channel.exe
O4 - HKCU\..\Run: [DWHeartbeatMonitor] C:\PROGRA~1\THEWEA~1\DWHeartbeatMonitor.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0d\aoltray.exe
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O9 - Extra button: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O9 - Extra 'Tools' menuitem: Advanced Searchbar - {57F02779-3D88-4958-8AD3-83C12D86ADC7} - C:\PROGRA~1\ADVANC~1\advancedsearchbar.dll
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: Bump by pogo - http://playweb02.pog...p-ob-assets.cab
O16 - DPF: Canasta by pogo - http://game1.pogo.co...a-ob-assets.cab
O16 - DPF: First Class Solitaire by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Harvest Mania by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Heavy Cannon by pogo - http://playweb04.pog...n-ob-assets.cab
O16 - DPF: Jigsaw Detective by pogo - http://game1.pogo.co...w-ob-assets.cab
O16 - DPF: Pebble Beach 3 Hole Challenge by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Pirate's Gold by pogo - http://game1.pogo.co...d-ob-assets.cab
O16 - DPF: Pop Fu by pogo - http://game1.pogo.co...u-ob-assets.cab
O16 - DPF: Poppit by pogo - http://game1.pogo.co...2-ob-assets.cab
O16 - DPF: Ricochet by pogo - http://game1.pogo.co...t-ob-assets.cab
O16 - DPF: Tank Hunter by pogo - http://playweb06.pog...k-ob-assets.cab
O16 - DPF: The Sims Pinball by pogo - http://game1.pogo.co...l-ob-assets.cab
O16 - DPF: Tube Runner by pogo - http://playweb14.pog...e-ob-assets.cab
O16 - DPF: Tumble Bees by pogo - http://game1.pogo.co...e-ob-assets.cab
O16 - DPF: Word Whomp Whackdown by pogo - http://game1.pogo.co...n-ob-assets.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - https://objects.aol....83/mcinsctl.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupd...b?1116524475265
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai...all/xscan53.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1....loadManager.ocx
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - https://objects.aol....,20/McGDMgr.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
  • 0

#8
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
The log looks good. :tazz:

Does the computer behave accordingly?

Please have a look at my site for some tips on how to remove and prevent spyware.

Regards,
  • 0

#9
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Hi Pieter:

For the most part, it looks fine. Two things I'm finding, tho:

1-when I type in www.mcaffee.com, I still get sent to the seeq search page
(http://www.seeq.com/...rrer=&pop=false)

and

2-I have noticed lately that I cannot work on aol and also IE or Netscape at the same time. Whichever one I've opened first seems to be the "dominant" program and I cannot use the internet via the other....If I'm on aol and try to open IE, my home page will come up, but if I type in a URL, it acts as if it's searching, and then I get a "unable to find page" type of error message. However, if I sign off AOL and refresh the page, then it loads fine.

Not sure if this is "virus" activity, but it's only been happening the last few months or so.

Thanks so much for all your help!

Laura
  • 0

#10
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
  • Download the Registry Search Tool.
  • Unzip the contents of RegSrch.zip to a convenient location.
  • Double-click on RegSrch.vbs.
  • If you have an anti-virus installed it might prompt you about a running script. Please ignore this warning and allow the script to run.
  • In the "Enter search string (case insensitive) and click OK..." box paste this string:
    • seeq.com
  • Click "OK" to search the registry for that string.
  • Wait for a few minutes while it completes the search.
  • Click "OK" to open the results in WordPad.
  • Copy and paste the entire results into your next post.
Regards,
  • 0

Advertisements


#11
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
Done. The only response I got was a little box which states:

"Search completed in 35 seconds.
No instances of "seeq.com" found."

However, if I open a new browser (it doesn't matter whether it's IE or Netscape)
and type in the URL www.mcaffee.com, I still get sent to this page...
http://www.seeq.com/...rrer=&pop=false

LauraM
  • 0

#12
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Please download Agent Ransack from:
http://www.mythicsof...m/agentransack/

Run the program and make sure there are Checkmarks in the Expert User and Containing Text boxes on the Advanced tab.

In the bottom bar type or paste seeq.com

Then click Start Search.

It will take quite a while before it's done.

When it is click "Save results" (icon #4 from the left)
Choose save to clipboard and paste them into your next post.

Regards,
  • 0

#13
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
C:\Documents and Settings\Owner.LAURAANNM\Application Data\Mozilla\Profiles\default\injbsy59.slt\Cache\85EF2390d01 (27 KB, 5/24/2005 12:41:24 AM)
120 <!-- BEGIN COREMETRICS SUPPORT --> <script language="javascript1.1" type="text/javascript"> <!-- var cmJv="1.1"; //--> </script> <script language="javascript1.2" type="text/javascript"> <!-- var cmJv="1.2"; //--> </script> <script language="javascript1.3" type="text/javascript"> <!-- var cmJv="1.3"; //--> </script> <script language="javascript1.4" type="text/javascript"> <!-- var cmJv="1.4"; //--> </script> <script language="javascript1.5" type="text/javascript"> <!-- var cmJv="1.5"; //--> </script> <script language="javascript1.1" type="text/javascript"> <!-- var cm_ClientID="90065742"; //--> </script> <script language="javascript1.1" src="/coremetrics/v40/eluminate.js" type="text/javascript"> </script> <script language="javascript1.1" src="/coremetrics/cmdatatagutils.js" type="text/javascript"> </script> <script language="javascript1.1" src="/coremetrics/v40/techprops.js" type="text/javascript"> </script> <script language="javascript1.1" type="text/javascript"> <!-- function seeqShop9(productId, categoryId, revenue) { cmCreateShopAction9Tag(productId, productId, '1', revenue, 'O75WSL1AVI8NU126UANVRD5Y8MX8NI4T', 'O75WSL1AVI8NU126UANVRD5Y8MX8NI4T', revenue, categoryId); cmDisplayShop9s(); cmCreateOrderTag('O75WSL1AVI8NU126UANVRD5Y8MX8NI4T', revenue, '0.00', 'O75WSL1AVI8NU126UANVRD5Y8MX8NI4T', null, null, null); return true; } cmSetProduction(); cmCreateProductviewTag("mcaffee.com : mcafee", "mcaffee.com : mcafee", "Seeq.com"); cmCreateTechPropsTag("/home.jsp", null); //--> </script> <!-- END COREMETRICS --> <table cellpadding="0" cellspacing="0" border="0" class="mainwidth"> <tr height="71"><td height="71"> <table cellpadding="0" cellspacing="0" border="0" align="left" width="100%"> <tr height="71"> <td class="logo" style="padding-bottom:0px;" width="180" height="71" ><a href="/home.jsp?portal_id=1&domain=mcaffee.com"><img src="/images/seeq.gif" border="0" align="left" hspace="0" vspace="0"></a ></td> <td align="center"> <table cellpadding="0" cellspacing="0" border="0" width="400"> <tr> <td><img src="/images/search.gif" border="0" alt="search the web" style="margin-right:8px"></td> <td> <form name="search" action="/results.jsp"> <input type="hidden" name="portal_id" value="1"> <input type="hidden" name="domain" value="mcaffee.com"> <input type="hidden" name="tag" value="typedseeq"> <input type="hidden" name="additionalParams" value="dmxargs%3D03u3hs9yoaScsyBByLS5PzMkLzCyptUtUN8lITc_Mzc2wTk9LTU1LqQSDVQqpzMm1TQA3QwMTAxcDQwMjUEcIHKs-00NHYxMLAwMDA3NzSzNQJyKcAHGlT"> <input type="text" name="keyword" value="" class="searchbox"> </td> <td> <input style="margin-left:8px" type="image" src="/images/button.gif" border="0"> </form> </td> </tr> </table> </td> <td align="right" style="padding-right:20px" nowrap> <a href="http://www.seeqmail.com" class="loginlink color2">Login to SeeqMail</a><br> <a href="http://www.seeqmail....com/names.html" class="loginlink color2">Sign Up for FREE Email</a><br> <a href="/about.jsp?portal_id=1&domain=seeq.com" class="loginlink color2">About Seeq</a></td> </td> </tr> </table> </td></tr><tr><td valign="top">
230 <a class="color2" style="text-decoration:underline;font-family:verdana;font-size:14px;font-weight:bold;line-height:16px;" href="/click.jsp?page=sindex&amp;tag=null&amp;domain=mcaffee.com&amp;data=www.inklineglobal.com%3Amcafee&amp;url=http%3A%2F%2Fwww21.overture.com%2Fd%2Fsr%2F%3Fxargs%3D15KPjg18dSzYK9k7PyMPiIRvydhRlLisTqqZc3UcQuQ4oMoS5zAr8icfKV2JQkGK94sUiFj7bRvvIJarCUx63cR0zhFBDJTLCmjdCrkNhsYPr0R4kD2u86lefgl4ZYbQZyb2%252D1fNS7mOfFIdbvfQc%255F84sDvh2Z9YMasMewtpVtFc7OigssR2nkBuhcrq0ogMnAKZkIQ7RTec%255FaxnfUI8Q5v9F9l%252DXSPSEVWyKjkWd4o1yD0ANMxfeQKYIJ6YXBio6YbeOJnNhbaTXm4qganBOUuniYyv9hIDjBhLBQllcMXe%252DFIDnQ2lR74biM3ayEd51uKhWfXtqabhH6YEJle1t4Ur3sO0OYKGEqgk%255FFN8sTM8T8v2rqX%252DzXVH5kDQ9DgIfheoYQoVyWlTdvHSTJAYLniR90Y7Q5iEaX8iXX9hQ5m%252DpD%255FvfBLdBLpYmAh0LHXWUR%252DBQol7v%252DC%255FmYrUIM4xAbzw%252E%252E%26" title="mcafee" target="_self" onclick="return seeqShop9(&quot;mcaffee.com : mcafee&quot;,&quot;Seeq.com&quot;,&quot;0.8&quot;);"><b>McAfee VirusScan 2005: $39.95</b></a><br><span style="font-family:verdana;font-size:12px;font-color:#333333;line-height:16px;">Get improved virus protection with new McAfee VirusScan 9.0. Scans and cleans infected PCs immediately. Detects spyware and other online threats. Authorized dealer. 60-day guarantee. $39.95.</span> <br><a class="color3 underline" style="line-height:16px;font-size:12px;" href="/click.jsp?page=sindex&amp;tag=null&amp;domain=mcaffee.com&amp;data=www.inklineglobal.com%3Amcafee&amp;url=http%3A%2F%2Fwww21.overture.com%2Fd%2Fsr%2F%3Fxargs%3D15KPjg18dSzYK9k7PyMPiIRvydhRlLisTqqZc3UcQuQ4oMoS5zAr8icfKV2JQkGK94sUiFj7bRvvIJarCUx63cR0zhFBDJTLCmjdCrkNhsYPr0R4kD2u86lefgl4ZYbQZyb2%252D1fNS7mOfFIdbvfQc%255F84sDvh2Z9YMasMewtpVtFc7OigssR2nkBuhcrq0ogMnAKZkIQ7RTec%255FaxnfUI8Q5v9F9l%252DXSPSEVWyKjkWd4o1yD0ANMxfeQKYIJ6YXBio6YbeOJnNhbaTXm4qganBOUuniYyv9hIDjBhLBQllcMXe%252DFIDnQ2lR74biM3ayEd51uKhWfXtqabhH6YEJle1t4Ur3sO0OYKGEqgk%255FFN8sTM8T8v2rqX%252DzXVH5kDQ9DgIfheoYQoVyWlTdvHSTJAYLniR90Y7Q5iEaX8iXX9hQ5m%252DpD%255FvfBLdBLpYmAh0LHXWUR%252DBQol7v%252DC%255FmYrUIM4xAbzw%252E%252E%26">www.inklineglobal.com</a><br> <br><a class="color2" style="text-decoration:underline;font-family:verdana;font-size:14px;font-weight:bold;line-height:16px;" href="/click.jsp?page=sindex&amp;tag=null&amp;domain=mcaffee.com&amp;data=www.secureie.com%3Amcafee&amp;url=http%3A%2F%2Fwww21.overture.com%2Fd%2Fsr%2F%3Fxargs%3D15KPjg1xRS74K9k7PyMPiIRvydhRlLit7hoY4sWsgsAYYBrW0%252DTuB%255FbbyQxYEhC7Ulq03SzfKRrrgZb6y%252D2qjfBw36EgzNRvb92teRhMxidPu0WqUa1OJ6k7%255Fyi4RIYzlVOjDKTa3Y%255FGv9YJLIm0Z5vdxSk3INyGhdg5eF3JcuIIOciQFt%252DCi0QegSvq0giczVeON9R7BUftmZlSH2QKx33Z4M5OCgSCZnIVrT4W4JqF%252DFUTR%252Dt%255FyUKDM8iZKCwsyVaOL0n9xcYkSW9PN1q0vHiy3FsP5uPn2K%255F7BYly0NSt70FDPbi%255F8cm8qG0afWKYxThDGvTcytF3DyYzMOahklbJPRSVStIxBN9FzEfpZPd8Cm7GfHQLKLX39zK0Vxx%252DLrZocLeyv41iwtcgaVR5XJvzFAMvxq1gylrmeC7S0ozK1prLXSfpQK797eyBqcFxwO%252Dmf488zjTPmSpl0M4SdprrcZK%252Ddix78E%252DHQ3%252Divc26qK284y5tVJY%255Fqk2S4M4ayzcUd2K65CV4ADT8VwfBfFApDBAQ%252E%252E%26" title="mcafee" target="_self" onclick="return seeqShop9(&quot;mcaffee.com : mcafee&quot;,&quot;Seeq.com&quot;,&quot;0.8&quot;);"><b>Download McAfee VirusScan 2005 - $39.95</b></a><br><span style="font-family:verdana;font-size:12px;font-color:#333333;line-height:16px;">Download new McAfee VirusScan 9.0 (2005) for complete virus protection. Protect and restore infected PCs now. Authorized McAfee partner. Full version, not OEM. Save $20 now.</span> <br><a class="color3 underline" style="line-height:16px;font-size:12px;" href="/click.jsp?page=sindex&amp;tag=null&amp;domain=mcaffee.com&amp;data=www.secureie.com%3Amcafee&amp;url=http%3A%2F%2Fwww21.overture.com%2Fd%2Fsr%2F%3Fxargs%3D15KPjg1xRS74K9k7PyMPiIRvydhRlLit7hoY4sWsgsAYYBrW0%252DTuB%255FbbyQxYEhC7Ulq03SzfKRrrgZb6y%252D2qjfBw36EgzNRvb92teRhMxidPu0WqUa1OJ6k7%255Fyi4RIYzlVOjDKTa3Y%255FGv9YJLIm0Z5vdxSk3INyGhdg5eF3JcuIIOciQFt%252DCi0QegSvq0giczVeON9R7BUftmZlSH2QKx33Z4M5OCgSCZnIVrT4W4JqF%252DFUTR%252Dt%255FyUKDM8iZKCwsyVaOL0n9xcYkSW9PN1q0vHiy3FsP5uPn2K%255F7BYly0NSt70FDPbi%255F8cm8qG0afWKYxThDGvTcytF3DyYzMOahklbJPRSVStIxBN9FzEfpZPd8Cm7GfHQLKLX39zK0Vxx%252DLrZocLeyv41iwtcgaVR5XJvzFAMvxq1gylrmeC7S0ozK1prLXSfpQK797eyBqcFxwO%252Dmf488zjTPmSpl0M4SdprrcZK%252Ddix78E%252DHQ3%252Divc26qK284y5tVJY%255Fqk2S4M4ayzcUd2K65CV4ADT8VwfBfFApDBAQ%252E%252E%26">www.secureie.com</a><br> <br><a class="color2" style="text-decoration:underline;font-family:verdana;font-size:14px;font-weight:bold;line-height:16px;" href="/click.jsp?page=sindex&amp;tag=null&amp;domain=mcaffee.com&amp;data=www.softwareoutlet.com%3Amcafee&amp;url=http%3A%2F%2Fwww21.overture.com%2Fd%2Fsr%2F%3Fxargs%3D15KPjg1%255FlSJYK9k7PyMPiIRvydhRlLit7rpI8pXtMsQJAarCcpT7MgM7yC35Q8FL94v0iQoq7FovNPcqTlwL%255FXThjdSFqIGfWupfjJy4M%252DM6akWNZHh6Vuv57knYVJSnsPZ264f9W%255FnubEVcCrZipG94gD227Bvvxvws2%252DzOYdGLzc3UQ7rg2WcsN9ma0hhsS1KpsOObtUCtHtmiCVhK9zr4UoxeCkbhAiRyqi4G94qluFJkEKt%255FK0CIIMuMSH642Yf6G%252DkdpXbU2b4rAaqB2bmyHJgJwwZyTd1%255FJUzQ1VHf6pdnmk6AYuqLDYkvvbN9lkqHaiSdq5RjOzPxc5cRc0G%
317 <td colspan="3" align="center" style="margin-top:17px;" class="subfooter">® 2005 Seeq.com &nbsp;&nbsp;<a href="/about.jsp?portal_id=1&domain=seeq.com" class="subfooter">About</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="/home.jsp?portal_id=1&domain=seeq.com" class="subfooter">Home</a>&nbsp;&nbsp;|&nbsp;&nbsp;<a href="http://www.buydomain...om/privacy.jsp" class="subfooter" target="_blank">Privacy Policy</a></td>

C:\Documents and Settings\Owner.LAURAANNM\Application Data\Mozilla\Profiles\default\injbsy59.slt\Cache\_CACHE_001_ (542 KB, 5/24/2005 1:09:39 AM)
54 GIF89a$$?rr蕕ffeVVx444WWVKKK|||턄rrrѧ뺺 ™mm䴴ßם??>٣Ĝϰ``_ii! ?,$$pH, Ȥrl:ШTVI_ fZ8[n ! g^87 AT" , # + 55 ( "*3G ( 6 +# (. +( .jG* 1 ,+ 6 6 5% .8=G #9 # ( Fԟ## . 9 1# %銬 9\̫w/߾~, $20^ &\ B 2dD ` u,"ѡB &X LÎ {!Rb.\[` H G ">*JXIA(L 2 ( U Mw 5T $ X]A@ ]1!ч?*ewڶ;vJS!v+^dQ@B +,< w&NYP#@F1 (<dFך w'@6L 7tS l7Άp! x`iW^\ ܅ wÁ 4P0:ǀ _ Q+'N @_ 1<`Lu$ p l`@- z=0=d vA v7]$h(h Y)~DH&J4h N];B!X q , L ;GIF89a$$?Ǖ*׶.ڪ'Ϸ͙ ո, ӥ@On߬yŝRՙڨ ٷjܽzɬw]fPȦhwB(%Zѿ߷R۰Kѱu~qLh! ?,$$pH, Ȥrl:ШtJZ z3+K.N312w)@\ d0(f#I5 < . 5! ]hG, =/ . {1 pqDu"==4 < < |oeD 7 *9* /,dE,%)=2 & 0 eCu & 4 **( qC' =$$4& / * ]*ؠ zܐ G Bt ~i , X ľ.0tх Dт /S e +>lV" c 68(`Cª e`=0 H +P؅ Ь }T`Z 5. b C1 # K p,0 mܹ; h Z@QƮrLY1 :eWd$21B gA3Б1 3c 쀺 q ^ .&ˋo> -0 ; 1<`Lu$ p l`@- z=0=d vA v7]$h(h Y)~DH&J#BuBt0MissedIconCache:http://www.seeq.com/favicon.icoIconMissed$BBfKp=7HTTP:http://us.i1.yimg.com/us.yimg.com/i/ww/bt1/ml.gifrequest-methodGETresponse-headHTTP/1.0 200 OK
142 Location: http://www.seeq.com/...rrer=&pop=false
145 BtBt<QHTTP:http://www.seeq.com/popupwrapper.jsp?domain=mcaffee.com&referrer=&pop=falserequest-methodGETresponse-headHTTP/1.1 200 OK
152 charsetISO-8859-1BtBt%HTTP:http://www.seeq.com/favicon.icorequest-methodGETresponse-headHTTP/1.1 302 Found
156 Location: http://www.seeq.com/
159 BtBtFHTTP:http://www.seeq.com/request-methodGETresponse-headHTTP/1.1 302 Found
164 Location: http://www.seeq.com/...rrer=&pop=false
175 BtBtkHTTP:http://www.seeq.com/bookmark.jsp?domain=mcaffee.com&pop=false&referrer=&portal_id=1&provider=overturerequest-methodGETresponse-headHTTP/1.1 200 OK
188 BtBtj@5HTTP:http://www.seeq.com/home.jsp?domain=mcaffee.comrequest-methodGETresponse-headHTTP/1.1 200 OK
194 charsetISO-8859-1BtBuB4>6JHTTP:http://www.seeq.com/coremetrics/v40/eluminate.jsrequest-methodGETresponse-headHTTP/1.1 200 OK
203 BuBuBC2;87JHTTP:http://www.seeq.com/coremetrics/cmdatatagutils.jsrequest-methodGETresponse-headHTTP/1.1 200 OK
218 var cm=new _cm("tid", BuBuB46GHTTP:http://www.seeq.com/coremetrics/v40/techprops.jsrequest-methodGETresponse-headHTTP/1.1 200 OK
227 BuBuB4)9HTTP:http://www.seeq.com/images/seeq.gifrequest-methodGETresponse-headHTTP/1.1 200 OK
236 GIF89a@fffpppyyy⣣σ! ,@ Bpͻ n )Py0w U d CG / 7\8эb 0 ˅9p I ^@Ib/ $&, n )J %- iQ k E # Qb #i l =(- lr O G Q Q a-z )I OY I I l յo R> $H V^ O֘ @ #X ?E#mQ K l Gf b @p zx O x,( ` U$, u + XQLB 񭈸4 X `ͱA ; =χ #BuBuB4+8HTTP:http://www.seeq.com/images/search.gifrequest-methodGETresponse-headHTTP/1.1 200 OK
245 GIF89a*fffnnnpppǎyyyhhhiiigggmmm! ,*` u lY Ah K + + cl0@Ҡp( u ,M@1`, Ӟ &GB E X& < + Y*v *~/ <ki *r l/ s + t}.; uw* .p<VZ /`< g V -n i; + u.^"KN.P6C D $@'?(q"A 1f԰ ; Q pE q Q , u + XQLB 񭈸4 X `ͱA ; =χ #BuBuB4k+8HTTP:http://www.seeq.com/images/button.gifrequest-methodGETresponse-headHTTP/1.1 200 OK
254 BuBuB439HTTP:http://www.seeq.com/images/grassroots_new.gifrequest-methodGETresponse-headHTTP/1.1 200 OK
263 GIF89a ! ,@ D ;pP ջт.྅ 83)~ݛ m nkfGIF89a ! ,@ D ;pP ջт.྅ 83)~ݛ m nkfBuBuMQHTTP:http://www48.seeq.com/eluminate?tid=5&ci=90065742&vn2=e4.0&st=1116909685062&vn1=4.0.21&ec=ISO-8859-1&pr=mcaffee.com%20%3A%20mcafee&pm=mcaffee.com%20%3A%20mcafee&cg=Seeq.com&pc=N&rf=http%3A//www.seeq.com/popupwrapper.jsp%3Fdomain%3Dmcaffee.com%26referrer%3D%26pop%3Dfalse&ul=http%3A//www.seeq.com/home.jsp%3Fdomain%3Dmcaffee.comrequest-methodGETresponse-headHTTP/1.1 302 Found
267 Location: /cm?tid=5&ci=90065742&vn2=e4.0&st=1116909685062&vn1=4.0.21&ec=ISO-8859-1&pr=mcaffee.com%20%3A%20mcafee&pm=mcaffee.com%20%3A%20mcafee&cg=Seeq.com&pc=N&rf=http%3A//www.seeq.com/popupwrapper.jsp%3Fdomain%3Dmcaffee.com%26referrer%3D%26pop%3Dfalse&ul=http%3A//www.seeq.com/home.jsp%3Fdomain%3Dmcaffee.com&cvdone=s
269 BuBu+OHTTP:http://www48.seeq.com/cm?tid=5&ci=90065742&vn2=e4.0&st=1116909685062&vn1=4.0.21&ec=ISO-8859-1&pr=mcaffee.com%20%3A%20mcafee&pm=mcaffee.com%20%3A%20mcafee&cg=Seeq.com&pc=N&rf=http%3A//www.seeq.com/popupwrapper.jsp%3Fdomain%3Dmcaffee.com%26referrer%3D%26pop%3Dfalse&ul=http%3A//www.seeq.com/home.jsp%3Fdomain%3Dmcaffee.com&cvdone=srequest-methodGETresponse-headHTTP/1.1 200 OK

C:\Documents and Settings\Owner.LAURAANNM\Application Data\Mozilla\Profiles\default\injbsy59.slt\Cache\_CACHE_002_ (832 KB, 5/24/2005 1:09:40 AM)
2 ݸߤO<n;?[A(d9 l[-~ Ӧ"#m OEXtaɈK9쬌, }C c 8| p` y_P|)6N5;zWȀw@~#mk b5PX/ v~5 `M"¹QW@]>\ # 3ƄQg Um b 2 X WPr }kTH. >Y(BEZ0fPBοƫr@I ž )}C6+v'e eq'(bQ /*` kUdȨ%É)P92 /Jt =M 2k7#XxR =iPsX٧JD ]">;K7Csj9 ,R1 &xJG{´p z{Z^ k6{Mz $FX$Y [ $_*訝IV ,Q,Oͨ P',8=;ˎ>y Wu_ߗejl卫2F O K[{ Vtǩ[֠u'owGo1e{oDKG^ǂ ao )f\X _&|s9_/?]4֗ g]*4XZ*_|T ]>4/+34ƃd,5Prp 1> n.[ uu#|) Ϋ KR / ZTi [{y뷍*Tz~U]|Ѽq+GIF89aFF o-٪VbK,Zڴcڰ˪яљJDŽ:sNˌAK Q7 wp]@, Ʒȓf1ϔFX YǢfz3<_"ՠO! ,FF'dYF Rp,ǔH3=DPp( Ǡé\. H (4R2i Pp v =y?b [[ _ P e|f m[ q c-D 6 _I<z36 OJ/ H ᰴ ΢ HkW ` \xV fܒ@\ PJ{ * ܬ xbh PAB Pf m ]蠕h*`a B P ׅcH5k봋 @ z 2lm uB * `Pn \M ,! d6h a yq\R [:,Dk:M 8k ap8 Ji : AṔi K0'\ Ni[dA5o) y` l ~ w l;@ 's- | imXXU[ # "p0 ' t f xElCsTP`! Yf @@^;nb .5I KDHgPp@z4b eڕ E G `@ L- T@ (D @ r̎ J& /h H j1 \ I#&-\cƓ jh +@P A"|\ wlB` X J80 T L2YSaB8)6u{ J azи@OHR&btLE Ū,P S-U]E ic {\VJ\Sj?. N f Mڲwd2d3 B/ U 0 "t.?:yW'c OZ Xp6SKR< d @ 3 5fZ S_Hi ]; W' 0a [,DlAd v7 3 5{ s m&p RC N-D $n i& p1PӻLJp@ ( b @z @C U뇪A-=pAY A_縧u )|p9YY j ۇ8vVRS H Cc A8e! ! zrQ<\ Q'$EZ q J T 5" #% H\ BE .Fl \pM;q| KT D] %(D4>^Y 4 8Ogī sf + ":HO@ < > 6` Z `! u "X@j@ :! ZD2 K:! 86r`|Lp 6@ nSK! !3A: & "x 2 l1 {d ;xG+& iGE x LS@.< 7*p T < tHM =8)+ܴR H@U1 / (=$O{0T Q 6 H! Xs pt ) P <|ktW8': Њ G? ҙ P ' .+(0@HԨ<ȁ<2 6 r8# C) | P 1 *[w " *(n . A[ Ё n'\ce86#Y \h=$ ϺֵRE "$Ͷ}@Pe ' ų,Ix # -q@[T68rGꂐ . B;BuBu+HTTP:http://www48.seeq.com/eluminate?tid=6&ci=90065742&vn2=e4.0&st=1116909685062&vn1=4.0.21&ec=ISO-8859-1&pc=Y&pi=/home.jsp&jv=1.5&np0=Mozilla%2520ActiveX%2520control%2520and%2520plugin%2520support&np1=Mozilla%2520Default%2520Plug-in&np2=Shockwave%2520Flash&np3=McAfee%2520Clinic&np4=Java%2520Plug-in&np5=Java%2520Plug-in&np6=Java%2520Plug-in&np7=Java%2520Plug-in&np8=Java%2520Plug-in&np9=Java%2520Plug-in&np10=MetaStream%25203%2520Plugin&np11=Adobe%2520Acrobat&np12=QuickTime%2520Plug-in%25206.5&np13=QuickTime%2520Plug-in%25206.5&np14=QuickTime%2520Plug-in%25206.5&np15=QuickTime%2520Plug-in%25206.5&np16=QuickTime%2520Plug-in%25206.5&np17=QuickTime%2520Plug-in%25206.5&np18=QuickTime%2520Plug-in%25206.5&np19=Microsoft%25AE%2520DRM&np20=Microsoft%25AE%2520DRM&np21=Windows%2520Media%2520Player%2520Plug-in%2520Dynamic%2520Link%2520Library&je=y&sw=1024&sh=768&pd=32&tz=4&rf=http%3A//www.seeq.com/popupwrapper.jsp%3Fdomain%3Dmcaffee.com%26referrer%3D%26pop%3Dfalse&ul=http%3A//www.seeq.com/home.jsp%3Fdomain%3Dmcaffee.comrequest-methodGETresponse-headHTTP/1.1 200 OK

C:\Documents and Settings\Owner.LAURAANNM\Application Data\Mozilla\Profiles\default\injbsy59.slt\Cache\_CACHE_003_ (3308 KB, 5/24/2005 1:09:40 AM)
106 --> </style> </head> <script language="javascript1.2"> if (self != top) { // open it var str = "toolbar=yes,menubar=yes,status=yes,scrollbars=yes,location=yes,left=0,screenX=0,top=0,screenY=0,resizable"; if (window.screen) { var ah = screen.availHeight - 110; var aw = screen.availWidth - 10; str += ",height=" + ah; str += ",innerHeight=" + ah; str += ",width=" + aw; str += ",innerWidth=" + aw; } var x = window.open('http://www.seeq.com/popupwrapper.jsp?domain=mcaffee.com','pop_seeq',str); x.blur(); window.focus(); window.focus(); window.focus(); //if (document.images) // top.location.replace(window.location.href); //else // top.location.href = window.location.href; } </script> <script language="javascript"> <!-- var dc=document; var date_ob=new Date(); dc.cookie='h2=o; path=/;';var bust=date_ob.getSeconds(); if(dc.cookie.indexOf('e=llo') <= 0 && dc.cookie.indexOf('2=o') > 0) { dc.write('<scr'+'ipt language="javascript" src="http://media.fastclick.net'); dc.write('/w/pop.cgi?sid=19401&m=2&tp=2&v=1.8&c='+bust+'"></scr'+'ipt>'); date_ob.setTime(date_ob.getTime()+43200000); dc.cookie='he=llo; path=/; expires='+ date_ob.toGMTString(); } // --> </script> <frameset rows=0,* scrolling=no framespacing=0 frameborder=no noresize border="0" framespacing="0"> <frame name=bookmark src="/bookmark.jsp?domain=mcaffee.com&pop=false&referrer=&portal_id=1&provider=overture" marginwidth="0" marginheight="0" frameborder="no" noresize> <frame name=searchhere src="/home.jsp?domain=mcaffee.com" marginwidth="0" marginheight="0" frameborder="no" noresize> </frameset> </html> JFIFHHPhotoshop 3.08BIM C# %$" "!&+7/&)4)!"0A149;>>>%.DIC<H7=>;C ;("(;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;; " ĵ } !1A Qa "q 2 #B R$3br %&'()*456789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz ĵ w!1 AQ aq "2 B #3R br $4% &'()*56789:CDEFGHIJSTUVWXYZcdefghijstuvwxyz?mx[Mo>"* r/Zuj G$O 2ed M 쵿 xvU 4nc E ) ݞVl׽ a Lu7*kS =8 Rj\ f3/ I H?ҵGل3 3^x t~Bx+‰!s Tݜ֞ڗo OfEֱ+>]iWhp I O [ K*- Ts< 95|'H#H3tq?QԯO A <98\}iz6A)[j ' 2< : +L֡: y dv5|1QrBsԌgΞ Cs2:J Bu;&;)Z=u)%<C ] C $ɑ{ X /Lg3 u#/w(~S ~W?t Y*XEpby܂ {j? ܅5[OҧMFz|Vk˕X@ ^8Fk 2Np< ߀{: : * K * sq 6ƳLȢs= 끜u*Sm opӻ >{ C 1 6 B뵲r kߘ$*[ 8 e; s=3 23>f t ' 5R@Fe QY$<gEIH CGPe/+Of4t:3Fc=r =?P[ @4 Js ȭ f f{0$$2H w 5,l I8 OԌ-Q + Gs ¥OM C:U SrTߔEe mmb p=?Xyݪ>0Ҁ 8( >` 1 x }0: t)Dlwm y {#6zxdzFV ;~ kn[> , 8} mŠ?4{$ y}j [{h4 ([I #< ?^~ N A%n sB?F-]: yb O ^ fc.I _ Yb 7 arl0K P{۴'Yr nA?.{sP b_ ! 0 \(٤Ùw 2Rw ϯVcM 2oi 7* 4UBks /jrFB7psI ]z!b 2g/!` O%j6Hx 2O_ĊY즘")U R {㚅VXZH>z+*d-OáX④ c ngzԑLjg >Ԇ B& [!:` }j7| Ca9~<* i. Eh!p8܌qבVŅ뫙wqn =6? x O [o 1r`$j*_ r j)3F _ ?`i0)QE QE QE QE QE QE QE  ? _ QR< 0ZeEt5A# _ WCMQE ((((((( _ QG_ } @Ξ -~" /+(` QEQEQEQEQEQEQEy_ } /TgO Y ] skA @ QE0 ( ( ( ( ( ( (</Q Ak_cAj*P3F _ ?`i ( Q@ Q@ Q@ Q@ Q@ Q@ Q@ o Ak_cAj( ( 3u e "3%B6r: QO>[ F-mSBqoJW({$bS #Ŷ;$+ ~F\gқBI,'ґ`o -GEm .dX b*YFR @? E `[؟

126 cm_HOST="www48.seeq.com/eluminate?";

C:\Documents and Settings\All Users.WINDOWS\Application Data\AOL\C_America Online 9.0d\storage\cache.db (65536 KB, 5/24/2005 10:56:45 AM)
16723 f 02 429171c2|http://www.geekstogo.com/forum/style_images/1/spacer.gif 02 42b5805b|http://www.geekstogo.com/misc/grid.gif 02 4297b49a|http://www.geekstogo.com/forum/style_images/1/p_offline.gif 02 42b5e15c|http://www.geekstogo.com/misc/Powered_by_Geeks.gif 02 429a310a|http://www.geekstogo.com/forum/style_images/1/p_card.gif 02 42b5cc6e|http://www.geekstogo.com/forum/style_images/1/p_pm.gif 02 42b5cc71|http://www.geekstogo.com/forum/style_images/1/p_up.gif 02 42b5cc71|http://www.geekstogo.com/forum/style_images/1/p_quote.gif 02 42b5cc71|http://www.geekstogo.com/forum/style_images/1/p_mq_add.gif 02 42b5cc71|http://www.geekstogo.com/forum/style_images/1/pip.gif 02 42b2575f|http://www.geekstogo.com/forum/style_images/1/t_qr.gif 02 42b2219e|http://www.geekstogo.com/forum/style_images/1/exp_plus.gif 02 42b601fd|http://www.geekstogo.com/forum/style_images/1/t_options.gif 02 42b5cc77|http://www.geekstogo.com/forum/style_images/1/exp_minus.gif 02 42b60202|http://www.geekstogo.com/forum/style_emoticons/default/smile.gif 02 42a5ca60|http://www.geekstogo.com/forum/jscripts/ipb_global.js 02 428fb23a|http://www.geekstogo.com/images/blue/Left.gif 02 428fb23a|http://www.geekstogo.com/forum/style_images/1/background.gif 02 428fb23a|http://www.geekstogo.com/forum/style_images/1/folder_post_icons/icon14.gif 02 428fb23a|http://www.geekstogo.com/forum/style_images/1/nav.gif 02 428fb23a|http://www.geekstogo.com/forum/style_images/1/icon13.gif 02 428fb23a|http://www.geekstogo.com/misc/hosting.gif 02 428fb23a|http://www.geekstogo.com/forum/jscripts/ipb_forum.js 02 428fb23a|0 ߝߝҞߓϏϏߒ߄ϏϏߏܒ߄Ϗ͏ܒߛ߄Κ͚͚ΚՒ _"h i 6jXY.i\'`F FM ~c2 H#޺F FM ~c2 pїї nhnB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM i sP3PP=" Wh h h- h: D ATh!S3S2y?SESy `\їlї2p C2p ` z'`@CV@Content-Encodinggzip@ @ip8& H&/ `GETAcceptimage/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*Accept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)X-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.compopupwrapper.jspdomain=mcaffee.com&referrer=&pop=falseX @@[ x i B sP3PP=" !! y,=?p`' - :`3 6 :`p } l ` }`p ` ` CV`dk p6 < |`S W {`épH H ip8& `@Content-Length-1Ok5915Transfer-EncodingchunkedDateSat, 21 May 2005 21:16:06 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Cache-ControlprivateContent-Typeapplication/IDCX-TSD0FE03A6~6204Content-EncodingidcX-IWX1Age0ViaHTTP/1.1 dtc-ab04 (Traffic-Server/5.3.8 [cMsSf ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]X-CTYPEtext/htmlX-BaseDataCenter-0-1116548896X-IMgzip, chunked, vdeltatext/htmlContent-EncodinggzipHTTP/1.1 236 !<Via_AOL_TurboWeb_Cache> OK
16726 ĂѝҜĂѝҜܽĂѝҜܺĂЌЗÌߓݕ׌ߋߐߖ߉ߌ݋†Ӓ†ӌ†ӌ†ӓ†ӓӌӋӌӍߖ׈ь߄߉ߞߌў߉ߞߌўߌӗߞߌӖߞߌӈߞߌӖߞ߂߇ѝ߈љ߈љ߈љЖכіߋѓэ׈ѓїКߋѓї߈ѓїЌÌߓݕ߉ߛ›߉ߛ‘߻ߛќؗߏĉߝ›јߖכќіؚ“ߛќі߄ߛшÌؖߓݕߌݗВљёߛшЈЏќًْىٜԝЌؖߛьכјߛќؗ“ߏߚߛы߂ЌÙߍߌ‘ߙߙ‘ߑߝߙÙߑߌНѕ’ߙݑߑÙߑŒߌќߒߒߙݑߑЙЗߝܝ߄ϏߒɏĂܝߞ߄Ăܝߞŗ߄̺̺ܽĂܝ߄ܹďǏߏĂН܏ߊ߄ߍҌҖߊחЖіќќМΛЖБЙЙЍ _Cp 37O$ V.iQ!Q Ųr=뮱^) Ϟ޺ Ųr=뮱^)37p8**hB BX p_0 height=width="141">> </tr> 5> <t H qx p s CP$07 2:16 Wh 6KhB Q hV ` hp  h ATh̘̘y̘̘2y h `t2pC2p7 ; `G L z'`-javascriptX-TSCDB45 0EContent-EncodinggzipX IWX-Len Hs w `GETAcceptimage/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*Refererhttp://www.seeq.com/popupwrapper.jsp?domain=mcaffee.com&referrer=&pop=falseAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=lloX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comhome.jspdomain=mcaffee.comX B $ xj B w ch 5 yii?p`( . :`4 7 :`q ~ jj;fp `}`k)kp/ 4 `5 8 `9 < CV`kk p |` {`H H ip8& kkp ```588.Html
16731 Cookie:XCLGFcgversion=1; XCLGFBrowser=zhAACkKMy21KAQAAFxw; s_c1 0 / . , * ( ) + imagContent-Length-1Ok14131Transfer-EncodingchunkedDateSat, 21 May 2005 21:16:07 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Cache-ControlprivateSet-Cookieguid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZ; domain=.Seeq.com; path=/; expires=Sun, 21-May-2006 21:16:07 GMTContent-Typeapplication/IDCX-TSD0FE03A6Content-EncodingidcX-IWX1Age0ViaHTTP/1.1 dtc-ac10 (Traffic-Server/5.3.8 [cMsSf ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]X-CTYPEtext/htmlX-BaseDataCenter-0-1116695996X-IMgzip, chunked, vdeltatext/htmlContent-EncodinggzipHTTP/1.1 236 !<Via_AOL_TurboWeb_Cache> OK
16734 ѳќߜݙќО߃ÞߗݗЈѳќߜݙќО߃ÞߗݗЈѲќߜݙќО߃ÞߗݗЈѲќߜݙќО߃ÞߗݗЈѲќߜݙќО߃ÞߗݗЈѰќߜݙќО߃ÞߗݗЈѰќߜݙќОÝÞߗݗЈѬќߜݙќО߃ÞߗݗЈѬќߜݙќО߃ÞߗݗЈѬќߜݙќО߃ÞߗݗЈѬќߜݙќО߃ÞߗݗЈѫќߜݙќО߃ÞߗݗЈѫќߜݙќОÝÞߗݗЈѫќߜݙќО߃ÞߗݗЈѫќߜݙќО߃ÞߗݗЈѫќߜݙќО߃ÞߗݗЈѨќߜݙќО߃ÞߗݗЈѨќߜݙќОЋЋЋЋЋËËߜߞœߌݒҋȏÞߗݗЈјѐߋݠÖߌݖИјߞݘߝОЋЋËËߜߞݜߌݒҋȏߜ݌߬ќّّÞߗОѕٛŒќߜ݌ОّّăّّÞߗЗѕٛŒќߜ݌ОّّăّّÞߗݗЈѝќЏѕߜ݌ߋݠ߯ОЋЋЋЋЋЋÝÝНЗ VӬ,\dq^E" > & _ % P 9{ .i)M fy yc.KzY ! ޺ yc.KzYP pp nhnB BX p_0 { height=width="141">> </tr> E> <t H qx $ h 6/h h hh& AThUUyUU2yz 3h `T(d(2p C2p ` z'`H` g t `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comcoremetrics/v40/eluminate.jsX-IWX1GET http://www.seeq.com/...40/eluminate.js HTTP/1.1
16736 Referer: http://www.seeq.com/...ain=mcaffee.com
16741 Host: www.seeq.com
16751 {lJ S- wQP|N E _@'\ŲI z{s_wҿ\[ LZ -1RЦ Ɍ @47x) T4HX :QvF8޻ t ?,*h v9* X[y'# | f5}9; ib n?y u. #g3βٸ ,b" `=)fszW$O C .( q B/+v&Z=\(Nu )Qӽ`# )$ 'Uy5" z"k 5+w^?N5ޔ XG/ 2Hx˷x-p + u BC /%T v h ` l ^2P.$PÕ@ v;NTK h P8L1W7 c;(*0?%Wg2Z=6Zԃ <պy nsAg,\I. ~%- )#ۿ4 8)q t ތ<# \ Pj` ^*>ܥ3IQ(`$ ©eܺ @ y!J 5 K= -GR(4~ D7G .p d} Q t/ pҽ{0E m>A"O F} !4 = K` <‚|^W [ {*, APe]j$!Q_ 0ŞrAq >A v] e <Hb E+\`нsmq8̞Gx̺/ U^x]-lN+ZE "n@Va3wD|!! -: 9Nm ^BX 4O9* @ \7 #!AJ˄`ݛ4󏖟 S] t٥i 3S5m] 5s䶓qyAz [q -LTyɼ@P# p >#B6JWF*څ- xk]~ q? f 6PON=7#9˜#ij F±F8T ީL~. qA*NYW.ǁ dt;Т/: 0 nB=ɟ1qB b &x| _Р -u . 69TO z;n؍wF,jK` + 7o* R&i! zj{ < K[g! jltl+ݡ xa+sAI RlԪ RQaO ڜ \RA2 7N*OIU v #a)Ǜ ÐF@c L 2Ƙ BҔ1`>T5p5hp W= xq p a } { dp*v@a> tE2 F "sfP#wUU r͡d\S( B x4wPb'<i\Grь7Xg Di]=xG/ SỷK ߋ!y 7 FA xp?PF U ]๦ +𘱣σ4-; % [@ aUX+ ] (f@HV5|p{Y,lbZ/ L]< :\^=K xOÊ W胼Sjo*0 > "`d~ 9._ B\ ࣐ RX&s \_ !ط8` .'vb5^ . Q< u>G A} plķ $\8Z oC ˔[/ik΁}CV ;\# o@ GM^5Q[*~&R F-ߟI'&=w NI Nղ2C +; K%կy s9tBW U { /wAY*R> jXβSnX~ vJ UY0 C@%f). @2! sЋЋЋЋËߞݍߌݏҍϏߑÞߗݗЈьќߜݓߜߋ߬ОÝÞߗݗЈьќБї _J >1 Hu.i79KA ɜ rJ8 "Ϭ޺A ɜ rJ8>p(( Pj0jB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM $ h 6/h h hh& AThUUyUU2yz 3h `T(d(2p C2p ` z'`H* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comcoremetrics/v40/eluminate.jsX-X w.s J eluminat HTTP/1.1
16758 քšїїĜšёёĂœёלӋĖלל‹քߛ‘߻Ĝ›јĜלӜӜӜәĂĂߜ׏քĉߖӓӖӋӋĖœċזіݬċזіݭęזĖÜѓѓĖքœѓĖ޼քѐœדݐӓѐݜךӜĂߖޓќքўݜӜәēќĂ׏ݐքדїӋӋĂĂߜךքߛ‘߻Ĝ›јļלӜӜәĖޜלփքќݐĜÑĂߜךք‘ļĖלքݪĂļלӜӜәļļĖלќքߏšללļݜ݋ԜُԏĂלѐ֜ѐĖלޜوяˆ֜ќ‘ĚޜքזĖÜќѓĖքќѐ‘Ĝќѐ‘Ă߼יքߛ‘߻ĉߜ›јĖלל΃΃לҜքלӜӜӜәÜĂ߼քלքߜӜӏӜӜĜœًԜĜלٓԜٓԚלٗԚלď‘߰ļ׏ӜĜًԜًԜًԜԜԜٙԜٙԚלٞԜٙԚלيԚלٙԚלُԚ׏яٗԚלٜԚלĖ׏ъُэُъѓԏэѓÜ֜يԚ׏ъٍԚ׏эĖ޼ݜӜԜ֖޼ݜӜּݜ݋ԜُԚ׏яĂx Kȋ{ Nw8؏#h F%׊ nQ ") J 9pVcEa` r X%\UW{u[Sy KZ% fX WPX U V ْ WXl6d7Z9;|= W3PF[{`WPV 84}`f|`aq[ ;7 H `&bhW \vk} Fn{Y`WU Yy[fmuqwinN`VnbՕڅpGhs%j h [ y&Viu oUdh PtKI0)beZ}i< U}× q _ < *N~ -̗.i` _ Y} j #2޺_ Y} j< p˘p˘ ϘϘB BX p_0 } height=width="141">> </tr> E> <t H qx cT$ DSPCOR h 6/h h hh& AThwQ}QyQQ2yz 3h `\їlї2p C2p ` z'` @Ɓ|@428f Ha h u `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comcoremetrics/cmdatatagutils.jsX-IWX1GET http://www.seeq.com/...datatagutils.js HTTP/1.1
16760 Referer: http://www.seeq.com/...ain=mcaffee.com
16765 Host: www.seeq.com
16774 {3ȭ ^,`W\) YB Ʀ#S\2P Z d#r- E \bp4©& S e %V (k pb pbP KOnFRI dǀr|ә Y,O 63u&UVH /u} X $Z_v]O7 ]3lZ *;( NЙ EV ɸE~k~ [ : A o 6 YA=QjwQ?c gA eOdYL> > oq;j;- _ea0Daq*,2t3 Tz R Rc0U㕽 . d <L*D hqm :tazz:.zQjVŖV ց lI«#|N3 U i!kW/ }OUønF75j U 5p H\KA1 w枞}ŀ]k@G&t50Ɓ- ])|Xzy Yg3 3FyLD˔2 ЦVMW*p S2gb u I *8٘S& F ekaih 7N"cyˣR@LVi^@ p:$4*"B!!㱞 :Yиl qpY\ %](<j#T lvcT $ c1CVoМ(6*7 3XT +$Ie( +|h\\ = |+0` % }"<~]D D h½ ;R ;~wg 54 n l i`^ Ji` R Z ̆<]< qE gRb '?m}͑. ڀn YP}L{_ B㒴 d 9 8S(Eu PHD.B p cnHVʹVyh .| W['nQxQ6͠B.ݵ g r ^c:vHF¿ee kuSJ*N;dt y P xz v= S@ R *v /4pm# yۆ 5nd;s^G%#W !5賹g=! d'= Z 뼫A |m(D"wA2<^,_r x rMSIZTFޢ {wc) sȃuWJ_$C&p ಆ }v<S oo1:; U ا!^r]̚K @;SѼWTCr.h b`3kE<ΑP1n I e[ k-qG]QF+= ԌxCPџ[y wB 6 3l9 ]^r + \Vpۦs hNy Nk}2 +BvfuMz#g W xؙr{Z{yNb}4dCDWV =8 2l5 ]BҀ5B,9 .݀L 0 8m $qK/+SX J5!m? )h j x|% G^\iu<P 9 4GYN j= # | mA ! ` <včߜĂ߼בքלքלќٜќ֜ќќ‹ĜќĖלѐ֜ѐבĂ߼בքלքќĉߖ‘ĖלќٜќքœќĖќ‹Ăלѐޖޖќ֜ѐӖĂߜחӑքל̤֜‹ļבĂ߼בքלٜќٜќלќќքߖœќĖќ–ьĖьĖלѐ֜ѐӖќĂ _hG 8;1F a.i_n&ҝA $`޺&ҝA8;pїї nhnB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM cT$ DSPCOR h 6/h h hh& AThwQ}QyQQ2yz 3h `\їlї2p C2p ` z'` @Ɓ|@428f H* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comcoremetrics/cmdatatagutils.jsXX ww. K atatagutjs HTTP/1.1 ept: */* fere x cT0@4 _ DSPCOR `4e4 y,=?p`( . :`4 7 :`q ~ &` ` ` ` }`1Ap ``CV` p |`H H 428f {`&p `MSIE 6.0; AOL 9. ؗ8sE5(|Y nnection: Keep-A pؗ8sE 5M Z CDq=
16779 ߏі׋߄ߏьߋߌߏѓ׌ߏѓ߄ߏݛў߬߫߻߻߱׏і߄ߏьӏѓ׏כߑ߄߉ߛߑ߂߫ߑߙߋߞߓߐߏߞߏߐߞߊߏߋ߾ߖߋߓ߫ߐߗߋߌߜߐߝߊߏߖߋߎߌߒ׊ߖ߄߉ߑߊߖז߄߉ߝߤݛݏݞݍݢ߉ߏ߉ߏߑі߉ߏ߉ߔߑ߾߉ߘߖ׏߄ߑь׏ߑьߏߏь׉ߖߖÏѓߖ߄ߋ׉ߕߕÝѓߕ߄׏іם߄ߙטߋ߄ѓߏߔѕ߂ߖכߑ߄ߑߛבߖ߂ߍߑߖߑכќߑ߄߉ߙߛќёߖיіؒ߄ߛߛќёߛќёߒ߂ĚޜքזĖÜќѓĖքќѐ‘Ĝќѐ‘Ă߼יքߛ‘߻ĉߜ›ј _O p 9 d .it,m#W`s <oQx %I޺m#W`s <oQx pїї nhnB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM CP$07 2:16 h 6/h h hh& AThvQ|QyQQ2yz 3h `\їlї2p C2p ` z'`-javascriptX-TSCDB45 0EContent-EncodinggzipX IWX-Len H* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comcoremetrics/v40/techprops.jssXXH ww.H ` atatagutjs HTTP/1.1 ept: */*fere x CP0@4 O07 2:16 99 yH L `i o :`u x :` &` ` ``+ / }`; I `L O `T W CV`її@їїz'@,@/@ h@ontent-EncodinggzipX IWX-LenDateSat, 21 May 2005 16:46:27 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Last-ModifiedTue, 19 Apr 2005 22:18:58 GMTETag"14b887-39f-426583d2"Accept-RangesbytesContent-Typeapplication/x-javascriptX-TSD0FE03A6~927Content-Length927Age16181ViaHTTP/1.1 dtc-aa09 (Traffic-Server/5.3.8 [cHs f ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]HTTP/1.1 200 !<Via_AOL_TurboWeb_Cache> OK
16782 ߼ӼۭРяў™քߋ‘ߜבߜę׉ߐߖߋք׋‘݃ыіݙ֜ċœל׋ĂߋĂęߜքߑ‘ӝ‘ўӜ‹Ėםݱքѝݑ݂ߖםݲ߶ߺքѝݖ݂ѝщבўĂߜלքߑ‘ӈˆьċѕœĖלѝݑٜщ֙׉ߖĖÑяѓĖ֚؋ёԖ‘яԖآёĖלщքלщלѝݑ݃ѝݖքѕבѕ‹݆ݑĂלѝݖքќ‘ќċќ‘ќĂьˆшċьˆїċяˆќĖ׋яքяˆяĂߙˆљĖיքљ™݆ݑĂߋ‘߻ċы‹јĂ߼ߋߙߏߋߋߋߏߛߜք݈ьќК _ 0K3:}T.iܲsכwͬXjF rqŤk &޺wͬXjF rqŤk pX_8_ `@B BX p_0 height=width="141">> </tr> 5> <t H qx-AIM Q$"14b87- h 6/h h hh& AThI̘O̘y]̘o̘2yz 3h `^_2pMPC2p ` z'`nggzipH* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comimages/seeq.gif/techprXH H H ` agutjs H1.1 */* x52J Q0@4 O"14b87- yH L `i o :`u x :` &` ` ` ` }`- 5 $`Y g `k n `s v CV`S_X_z'@tZwZ h@DateSat, 21 May 2005 16:50:33 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Last-ModifiedTue, 19 Apr 2005 22:18:50 GMTETag"11b8ce-bc8-426583ca"Accept-RangesbytesContent-Typeimage/gifX-TSD0FE03A6~3016X-REPLAYkey=3fa522a8c8b7132732aadaf18ddb1b4bContent-Length3016Age15935ViaHTTP/1.1 dtc-ae09 (Traffic-Server/5.3.8 [cHs f ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]HTTP/1.1 200 !<Via_AOL_TurboWeb_Cache> OK
16785 GIF89aG=硧i߇/..癙ܳߕIC֛ϣœUם333988MMM۲yyy@@@FDC???VSOYYYƬטb`_qqq_\WllkQOJwusLICfff~zeb`dddhhh! ,G =χ # = h۰] \# P p CD 4 3 Nj ,Ab @ LiH c$mV "DI G<kTbI$ ,eEM P ̚ Uv,kvŎ%LPQA .8(͋ "ZXA ^M̛( X# "kXD rpn f" " 0 $!J \e V z=P\ 3u1 Q l;J(hLf DZm4" MG ds>53h/m] WdAiqF q a LSSV! G _ 8v@ @ >5D ?DQBl!i s!:Ȥ`4:H8 X Xt! [\` Ti% > XF L tt!i W6<Q(Pq4@ t VP l b9H t .ڕei`Ȧ[%H^,BO# `\ J@ "j( Z "Akw fOg$ O 돲\=WH { l0 " J B##KkE8 _qVK󢆬 T Q \L A K% : <l ] /W *%\M* "& ڢ $HV: Cp( @ `bH7 wSkXX 2s5 ڞ <[sB ]4 \ bƣ udP`ThK*5k s׈m hvUF A C`ӅЃ.k S1u^ B D>y l_6FS @ B@*8 ܙ> ~H6b፴sf" bq8k -۹ X @M7y ; քB0l! \pJmcߡL> ?=^"F >8 ?֝ &% cX@ $9 `` ?{7] 2؛#.p, 2 .C$S "X;A*-0 ػ x#W o Fx 1G { # ; F E :4Z 5s QXب)-@ ը3 1R c? p l@3 i 4DrHV RX4+D(`5'@y t co K ( k g 0 ^YB:`e,p9"ۋT ̎B%mZ ="H 1Y 9 i l.p,%װ/> Q/؀ 5 ); AZ%X \G3 $szɌ5x Mp Z-<֕Fe(%Tq, !1>A ^IH vgjkM tA ׁĻJ-G'H[oT ӊ 4% p89p i 4XϹ$ =@ r ) V ZXVM+ m6Tp1 ]W] A >miڄ 6 $ 7ऋ3``8tM{Z zwh 빒|w #` (XoLMP] [ Lp_* # P x-pBݻrt h0Af qsc1 @ d <d 4 A~ 6 ޷ X ت | ܱ A~ 3HAtu < 8~ f; q @qq0; , X9av*g ~ tXY%݀ ^(D ⶀ_ ]D L\ gV @DL > $ p 8Br A|H $ P; > NlL(A i{ 8 1 p-- H ^[ } [ h b`n (@ 8 @ o_ a 9 ; srf` ` Rv 6fRqB|` 4 @ B@ ` { @ 5 oT Cr7 M2[ "d P ) c :7J/ [a n{[Tw=fr\ 5Qnv; -BcP p'W M <|ԭtt ,`<9+ @ >_" 8vBiˀ L oB\ 9p `?ަ ֿ 0?>Nw'` 'pp l\ T 8 &b .f 60lk .kX 4t@C tk& kVZ 1XQ3 P% ,0n@ B8DXFxHJL؄N ;Ѫߖߏߗߒ߉ߞߋ _ X k %}.iB%3]`cA+ ԳZ| L ` ' ޺]`cA+ ԳZ| L `k p hB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM cT$3A0~9Ag h 6/h h hh& AThppypp2yz 3h ` 2p C2p ` z'`ww h@H* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comimages/button.gifechprXH H P H ` agutjs H1.1 */* x w.mc0@4 OUserAge yH L `i o :`u x :` &` ` ``$ `- 1 }`= @ `E H CV`eE32aIlSI'/+u_9g[E2> lVm^_#^L4H!Uail<`fML0T9FLHBak4\Q_E`qi<[slp+,QWt S=".,_E$,&E/e.?@dXLCN*j ?:A!@l1DateSat, 21 May 2005 16:47:31 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Last-ModifiedTue, 19 Apr 2005 22:18:50 GMTETag"11b8c8-16b-426583ca"Accept-RangesbytesContent-Length363Content-Typeimage/gifX-TSD0FE03A6~363Age16117ViaHTTP/1.1 dtc-af09 (Traffic-Server/5.3.8 [cHs f ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]HTTP/1.1 200 !<Via_AOL_TurboWeb_Cache> OK
16790 H* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comimages/search.gifechprXH H O H ` agutjs H1.1 */* xM NA cT0@4 O3A0~9Ag ԘԘ yH L `i o :`u x :` &` ` ``$ `- 1 }`= @ `E H CV` @ z'@ h@DateSat, 21 May 2005 16:47:31 GMTServerApacheP3PCP="NOI CURa ADMa OUR NOR BUS PHY ONL UNI PUR COM NAV STA"Last-ModifiedTue, 19 Apr 2005 22:18:59 GMTETag"1cb49a-1ab-426583d3"Accept-RangesbytesContent-Length427Content-Typeimage/gifX-TSD0FE03A6~427Age16117ViaHTTP/1.1 dtc-aa01 (Traffic-Server/5.3.8 [cHs f ]), HTTP/1.1 Turboweb [dtc-td111 8.3.0]HTTP/1.1 200 !<Via_AOL_TurboWeb_Cache> OK
16793 GIF89a@fffpppyyy⣣σ! ,@ Bpͻ n )Py0w U d CG / 7\8эb 0 ˅9p I ^@Ib/ $&, n )J %- iQ k E # Qb #i l =(- lr O G Q Q a-z )I OY I I l յo R> $H V^ O֘ @ #X ?E#mQ K l Gf b @p zx O x,( ` U$, u + XQLB 񭈸4 X `ͱA ;ddhhh! ,G =χ # _' h  efDuE]k.iI ՀbJah )ϝ޺I ՀbJah  pDD pcPcB BX p_0 height=width="141">> </tr> 5> <t H qx-AIM Q$"14b87- h 6/h h hh& ATh͘͘y ΘΘ2yz 3h `DDTD2p C2p ` z'`nggzipH* . : `GETAccept*/*Refererhttp://www.seeq.com/home.jsp?domain=mcaffee.comAccept-Languageen-usX-PageViewwww.mcaffee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)Cookieh2=o; he=llo; guid=BCBSO88LM3ET1866B4HDM1RZ63UMYYDZX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostwww.seeq.comX-AIMvdelta, inverse, chunked, gzip, deflatehttpwww.seeq.comimages/grassroots_new.gifXH H Q agutjs H1.1 */* xM NA View0@4 Oeflae
16805 Host: www.seeq.com
16963 /+GIF89a ! ,D ; ŵȔo = <> d]h X[<fZQL~ac>tvqLV uc &f E 3>lD p0̚T 4\ɲ˗. I̚8sTyӦ R i蹳ѣH M i\JJիXjݵ׫ n hӪ]˶- po#n n˷o TJ:a +N ] <Ȗ `s Ë uLҌM 5; 6Ӎ Q7 1 #ñ. HDa -Z [{m koH j kƮ-u5Ğ]8;; ؍C 0G ( . v@ ywG 0 > lp`Z "l cX 0P Q *@€ AikMH]96|X ( @@x  vWz(A .~P Иpq@x _Z (dQM.i.| / F _JB E:޺ F _JB p((@ hX ݐ 9ݬߐ߫ߨߘߍ H qx \ 6/`hl@C2@I I̔I۔甌ATI=CIVh2It|I<A @t w @|  CV@SS@SSz'@ TT @HGETRefererhttp://www.seeq.com/home.jsp?domain=mcaffee.com.aspAccXH X-PH /Accept-dinggzip, deeUser-Agozil H x U! J N `SS6*ISSITT I!T2TIATMTATITTITT2ITT# I$n)n @̄Ԅ I)) @ @CV@ @&,|@OkX-PLhttp://www.seeq.com/coremetrics/v40/eluminate.js 02 42980d28|http://www.seeq.com/coremetrics/cmdatatagutils.js 02 429029cc|http://www.seeq.com/coremetrics/v40/techprops.js 02 429747e3|http://www.seeq.com/images/seeq.gif 02 42974af8|http://www.seeq.com/images/button.gif 02 429748b2|http://www.seeq.com/images/search.gif 02 429748b0|http://www.seeq.com/images/grassroots_new.gif 02 4297d1b3H 0 ` } xnb mcaf0@4 _h=17WT. pu ͛ _`WH J+ bUP/וǂV-CP;5|td= FE޺ǂV-CP;5|td=Jp8** ((;B;BX ݐ ݬߐ߫ߨߘ5ߍ H qx<( U!$ Wh 6*h! 0 h5 ? hQ ` hm w ATh5c;cyJc\c2y h `LP\P2p뷘C2p ` |` z'`&,|@H' < `GETAcceptimage/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*Refererhttp://us.mcafee.com/virusInfo/default.aspAccept-Languageen-usX-PageViewwww.us.mcafee.com/Accept-Encodinggzip, deflateUser-AgentMozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; Advanced Searchbar)CookiePassportSignIn=http%3A%2F%2Fus%2Emcafee%2Ecom; PassportSignOut=http%3A%2F%2Fus%2Emcafee%2Ecom; campaignid=10529; langid=1; lUsrCtxSession=%3CUserContext%3E%3CAffID%3E0%3C%2FAffID%3E%3C%2FUserContext%3E%0D%0A; SiteID=1; lBounceURL=http%3A%2F%2Fus%2Emcafee%2Ecom%2FvirusInfo%2Fdefault%2Easp%3F; ASPSESSIONIDSQBCQQSD=AIHPIIOBDBJPEDLGKLJBGOBC; ASPSESSIONIDCARCSQQD=NBJPPLECMDOFMCLCHADDCGPN; ASPSESSIONIDCATATQQC=LMAGKFIAGEEPFAAMIMJENFGGX-IWX1ViaHTTP/1.1 (Velocity/1.0.5 [uScMs f p eN:t cCMp s ])Hostus.mcafee.comX-BaseDataCenter-0-1116428152X-AIMvdel
  • 0

#14
Metallica

Metallica

    Spyware Veteran

  • GeekU Moderator
  • 31,676 posts
Can you clear your Mozilla cache please.
Follow the instructions here
http://support.shaw....ozillacache.htm

Do the same for AOL:
Setting Cache
From the horizontal toolbar at the top of your screen, click on:
Settings - A box appears called "Settings: Essentials".
Click on Internet [Web] Options - this will launch a window called "AOL Internet Properties".
Click on the 'General' tab.
Under 'Temporary Internet Files', click on the "Settings" button.
On the 'Settings' page, make sure "Every visit to the page" is Selected.
Click OK.
When you return to the 'General' tab, click on "Delete Files" to clear the cache.
Click OK.

Let me know if that helps.

Regards,
  • 0

#15
LauraannM

LauraannM

    Member

  • Topic Starter
  • Member
  • PipPip
  • 19 posts
I posted a response, not sure why it's not here. I cleaned out the caches for Netscape, IE and AOL. I still get sent to the same page, except I get error messages on Netscape.

I just returned to my computer and found this message opened in a "pop-up window"....have no idea what it is or how it got there -- anything to worry about??

LauraM

Attached Thumbnails

  • Screen01.JPG

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP