This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Am I Infected

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Can someone check my log please

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:55:55 PM, on 3/2/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182813660890
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://rimsupport.webex.com/client/T23L/support/ieatgpc.cab
O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - C:\WINDOWS\batmeter16.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
–
End of file - 13159 bytes
:welcome:

Open HijackThis > Do a System Scan Only, close your browser and all open windows including this one, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - C:\WINDOWS\batmeter16.dll



Please download OTM by OldTimer.
  • Save it to your desktop.
  • Please click OTM and then click >> run.
  • Copy the lines inside the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\batmeter16.dll


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]
  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.



Post the OTM log and a new HJT log please
Ken this is the message i got: Error: Unable to interpret in the current context! OTM by OldTimer - Version 3.1.10.0 log created on 03032010_203459
Ken this is the log. It appears to still be there.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:38:21 PM, on 3/3/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182813660890
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://rimsupport.webex.com/client/T23L/support/ieatgpc.cab
O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - C:\WINDOWS\batmeter16.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 13004 bytes
It doesn't look like you ran OTM correctly.

This is what you need to put in to fix, all in bold starting with :Processes and ending with Reboot. Start at :Processes ( make sure you get the : in front of Processes, its needed and drag your mouse all the way down to and including [Reboot] , then when its all highlighted , right click on it and select COPY and then PASTE it into OTM

:Processes
explorer.exe

:Services

:Reg

:Files
C:\WINDOWS\batmeter16.dll


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]




Not this
O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - C:\WINDOWS\batmeter16.dll
Updated OTM Script


This is what you need to copy and paste in to OTM



:Processes
explorer.exe

:Services

:Reg
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter]
{460734d1-772a-4d81-a6c6-30a07c34c0a8}=-

:Files
C:\WINDOWS\batmeter16.dll


:Commands
[purity]
[emptytemp]
[start explorer]
[Reboot]







  • Return to OTM, right click in the "Paste Instructions for items to be Moved" window (under the yellow bar) and choose Paste.
  • Click the red Moveit! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
  • Close OTM
Note: If an item cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Ken Here's the log. It still appears to be there….Ugh!!!



Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:08:50 PM, on 3/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182813660890
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://rimsupport.webex.com/client/T23L/support/ieatgpc.cab
O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - C:\WINDOWS\batmeter16.dll
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 12789 bytes
Hi Shakia,

Post the log for OTM.

C:\_OTM\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next reply

Go to My Computer
C:\ Drive
OTM Folder
Moved Files Folder <–and you can find the report in here.


Run this scan and post the log, it wont fix anything but It will give me a lot of info, there may be a hidden file blocking its removal

Download DDS by sUBs from one of the following links. Save it to your desktop.
  • DDS.com
  • DDS.scr
  • DDS.pif
  • Double click on the DDS icon, allow it to run.
  • A small box will open, with an explaination about the tool. No input is needed, the scan is running.
  • Notepad will open with the results, click no to the Optional_Scan
  • Follow the instructions that pop up for posting the results.
  • Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run. After downloading the tool, disconnect from the internet and disable all antivirus protection. Run the scan, enable your A/V and reconnect to the internet.
ken this is the log after that OTM program ran:


All processes killed
========== PROCESSES ==========
No active process named explorer.exe was found!
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Filter\\{460734d1-772a-4d81-a6c6-30a07c34c0a8} not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{460734d1-772a-4d81-a6c6-30a07c34c0a8}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{460734d1-772a-4d81-a6c6-30a07c34c0a8}\ deleted successfully.
========== FILES ==========
File/Folder C:\WINDOWS\batmeter16.dll not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temporary Internet Files folder emptied: 0 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: SHAKIA
->Temp folder emptied: 1237841422 bytes
->Temporary Internet Files folder emptied: 31836370 bytes
->Java cache emptied: 72071288 bytes
->Flash cache emptied: 1766631 bytes

User: STAN
->Temp folder emptied: 1034719 bytes
->Temporary Internet Files folder emptied: 34320 bytes
->Java cache emptied: 13690061 bytes
->Flash cache emptied: 348 bytes

User: TAMIA
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 67 bytes
->Flash cache emptied: 2311 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 42524180 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 23941692 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 34318 bytes
RecycleBin emptied: 240083837 bytes

Total Files Cleaned = 1,588.00 mb


OTM by OldTimer - Version 3.1.10.0 log created on 03052010_211644

Files moved on Reboot…
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZTZZIG5K\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNPUkdBTklaQVRJT04EZXh0ZnJvbQMEZmIDM
ARmcmNvZGUDY3NjX3ltYWlsY2cEaXNleHQDMARpdANzaG9ydGN1dHM6L3VzL2luc3RhbmNlL29yZ2F[2]
.adNoOp&fr=csc_ymailcg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\ZTZZIG5K\dref=http%253A%252F%252Fmessaging.myspace.com%252Findex[1].sent%2526type%253DInbox%2526messageID%253D26859689%2526fed%253DTrue%2526compose%253D0%2526friendID%253D297478153 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XWJ8BXHT\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ
nJjb2RlA2NzY195bWFpbGNnBGlzZXh0AzAEaXQDc2hvcnRjdXRzOi91cy9pbnN0YW5jZS9pZGVudGl[2]
.adNoOp&fr=csc_ymailcg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XWJ8BXHT\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGVfdHlwA2RpcmVjdARle
HRmcm9tAwRmYgMwBGZyY29kZQNjc2NfeW1haWxjZwRpc2V4dAMwBGl0A3Nob3J0Y3V[2].adNoOp&fr=csc_ymailcg&track=click not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XWJ8BXHT\BottomBanner1;pos=1;q=Treatment+For+Sunburn;tile=7;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutane;c[1] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XWJ8BXHT\RightBottomText1;pos=1;q=Treatment+For+Sunburn;tile=4;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutan[2] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\XWJ8BXHT\TopBanner1;pos=1;q=Treatment+For+Sunburn;tile=1;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutane;cat8[2] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjp5MWpGSU9SS3hQb3Z5TTppbWF
nZWNhY2hlMi5hbGxwb3N0ZXJzLmNvbS9pbWFnZXMvcGljLzE1My84NDY1MDN-U2NhcmZhY2UtUG9zdGVycy5qcGc,[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\click,UMkTAObCAgCt1A8AWvcEAAAA5AAAAAAABgAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFtMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F9,;ord=1215188059 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\click,UMkTAObCAgCt1A8AWvcEAAAApAAAAAAAAQAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANlLbkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215187929 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\click,UMkTAObCAgCt1A8AWvcEAAAAuAAAAAIAAwAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAAxMbkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215187980 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\click,UMkTAObCAgCt1A8AWvcEAAAAyAAAAAIABQAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAEJMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F2,;ord=1215188034 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\click,UMkTAObCAgCv1A8AWvcEAAAAyAAAAAAACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAEJMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F2,;ord=1215188034 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\dref=http%253A%252F%252Fviewmorepics.myspace.com%252Findex[1].editAlbumPhotos%2526albumID%253D588200%2526MyToken%253Dc5a1315f-e39b-4830-a43a-fffab611a5cf%2526m%253D1 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\dref=http%253A%252F%252Fviewmorepics.myspace.com%252Findex[1].editAlbumPhotos%2526albumID%253D630181%2526MyToken%253Def71374b-183f-4ab1-8262-886ed91ca54b%2526m%253D1 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\eds%2Fsnippets%3Fbq%3DBirthday%2520Glitter%2520Graphics%2520Myspace%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\W96R0LUZ\om%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DMyspace%2520Graphics%2520Quotes%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\click,UMkTAObCAgCt1A8AWvcEAAAA0AAAAAAABQAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAEhMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F4,;ord=1215188040 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\click,UMkTAObCAgCt1A8AWvcEAAAA3AAAAAAABgAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFVMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F7,;ord=1215188053 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\click,UMkTAObCAgCt1A8AWvcEAAAAsAAAAAAAAgAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAOJLbkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215187938 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\click,UMkTAObCAgCt1A8AWvcEAAIAoAAAAP8AAAAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANZLbkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215187926 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\dref=http%253A%252F%252Fviewmorepics.myspace.com%252Findex[1].editAlbumPhotos%2526albumID%253D588200%2526MyToken%253Dc6a4ada5-d884-434d-b047-d834c4a57157%2526m%253D1 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\jsonp[1].com%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DQuotes%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\UFM1OFUN\jsonp[2].com%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DGraphics%2520Myspace%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\SZSXH16V\%26rnd%3D425880046%26ged%3D0%3A0%3Amwvizjhim2u4zmi1ytu3n37p5bqsh8ftfif1qwgiwjyplyeb_kr8pexm3h85ja3rslalplbytqrl00-lpsmyq7dxouwyj-_c_8rhcqrt9kx8ef3kziivtso6dn0ev_d8,;ord=1213065480 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\SZSXH16V\3Dsunburn%26OVKEY%3Dsunburn%2520relief%26OVMTC%3Dadvanced%26OVADID%3D22182314012%26OVKWID%3D205416470012%26ysmwa%3DmlXEL3jTx_gGNGT0V7MCgEdLdiro0I6gFz72IHg5n3YgzbEOolfqxg2MClJ8Sn62 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\SZSXH16V\;!c=b;!c=s;!c=nptr;ec=ron;ec=tb;ec=pb;dr=or;p=1;p=2;ec=ph;ec=th;pec=h;upec=h;ec=tfi;ec=t
ls;ec=pfi;ec=pls;sc=onam;sc=nmbg;al=nmbg;sc=ar;al=ar;al=macy;atf=e;sc=drRON;al=dr
;lf=[2].5 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\SZSXH16V\RightTopText1;pos=1;q=Treatment+For+Sunburn;tile=3;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutane;c[2] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\click,UMkTAObCAgCv1A8AWvcEAAAA5AAAAAAACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFtMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F9,;ord=1215188059 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\click,UMkTAObCAgCv1A8AWvcEAAAA7AAAAAAACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAF5MbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F10,;ord=1215188062 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\click,UMkTAObCAgCv1A8AWvcEAAAAIAAAAAkACwAGDAIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAOhEbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F6,;ord=1215186152 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\click,UMkTAObCAgCv1A8AWvcEAAAApAAAAAIACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANpLbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215187930 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\dref=http%253A%252F%252Fviewmorepics.myspace.com%252Findex[1].editAlbumPhotos%2526albumID%253D588236%2526MyToken%253D906170a2-8eb2-4497-8f5f-b5d5cb0f0754%2526m%253D1 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\jsonp[1].com%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DGraphics%2520Quotes%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MV0H2TIL\m%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DGlitter%2520Graphics%2520Myspace%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\1941458%26ged%3D0%3A0%3Amwu5owyxmwq4mgm0mwiyzqvj0cmg797wv4ot4sujmlxyxd0pimkwbqzyowf-efwnsqdpm8fy32tqj-f52djivwmruhbya4py4vybzb-3hlw0o8irfnwsw3agpcxamiul5zhns_hunri,;ord=1215559254 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjpraWNaVkF4MmU1djluTTpuZXd
zLmZpbGVmcm9udC5jb20vd3AtY29udGVudC91cGxvYWRzLzIwMDcvMDcvc2NhcmZhY2UtdGhlLXdvcmxk
LWlzLXlvdXJzLTI[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjprNDJYdnNjNUlNbml3TTp3ZWJ
sb2dzLm5ld3NkYXkuY29tL3Nwb3J0cy9jb2x1bW5pc3RzL2ppbWJhdW1iYWNoL2Jsb2cvbGdwcDMwMDkz
JTI1MkJzY2FyZmF[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCt1A8AWvcEAAAAvAAAAAAABAAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAA9MbkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215187983 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCt1A8AWvcEAAAAxAAAAAIABQAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAD9MbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F1,;ord=1215188031 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCt1A8AWvcEAAAAzAAAAAIABQAGDQIAAgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAEVMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F3,;ord=1215188037 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCv1A8AWvcEAAAA4AAAAAEACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFhMbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F8,;ord=1215188056 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCv1A8AWvcEAAAAfAAAAAoACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAK5LbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215187886 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCv1A8AWvcEAAAAsAAAAAAACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAOJLbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215187938 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\click,UMkTAObCAgCv1A8AWvcEAAAAxAAAAAQACwAGDQIABgPK7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAD9MbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F1,;ord=1215188031 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\jsonp[1].com%2Fbase%2Ffeeds%2Fsnippets%3Fbq%3DMyspace%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\MIKWM7KG\pets%3Fbq%3DHappy%2520Birthday%2520Glitter%2520Graphics%2520Myspace%255Bcustomer%2520id(int)%253A7866%255D%26max-results%3D6%26start-index%3D1%26crowdby%3Dbrand(text)%26alt%3Djson not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAA-AEAAAIACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAAAAAAAAAAAAAAAAAAI1AbkgAAAAA,,http[2]
.com%2Fadservercontroller%2Findex%2Ftopleader%2F0,;ord=1215185037 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAA0AEAAAAACgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFdAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F3,;ord=1215184983 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAA2AAAAAAAAQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAALU-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184565 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAA4AAAAAAAAgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAALw-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184572 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAA8AAAAAIAAgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANU-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184597 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAEAEAAAAABQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAPI-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184626 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAkAEAAAEACQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAIc[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184775 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAALAAAAAAACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAOpAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215185130 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAlAEAAAAACQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAIw[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184780 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAMAEAAAAABwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAABQ[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F4,;ord=1215184660 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAnAEAAAQACQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAAVAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184901 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAPAAAAAAACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAO1AbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215185133 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,7CEAAGliAQCv1A8AWvcEAAAAXAEAAAAACAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFI[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184722 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,f9stAGliAQAPpwkAEGQDAAIAOAAAAP8AAAAGDAIACgKC7wUAzSUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAA87bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Ftennaya%2F14,;ord=1215183631 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,f9stAGliAQAPpwkAEGQDAAIAOAAAAP8AAAAGDAIACgKC7wUAzSUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAI7bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Ftennaya%2F12,;ord=1215183618 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,f9stAGliAQB8og4Av7MEAAIAWAAAAP8AAAAGDAIACgOC7wUA6tQGAI.-BgAAAAAAAAAAAAAAAAAAAAAAAAAAAFM7bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Fstars%2F3,;ord=1215183699 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\LN6BTDBB\click,f9stAGliAQB8og4Av7MEAAIAYAAAAP8AAAAGDAIACgOC7wUA6tQGAI.-BgAAAAAAAAAAAAAAAAAAAAAAAAAAAFo7bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Fstars%2F5,;ord=1215183706 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\KJHZU275\click,AAAAANzUAgBYBgoAR1QEAAIAAAAAAA8ABQAEFQIABgJJGQcAAnYGAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAIsebEg[2].ads%2Fmyspaceunfiltered%2Fros%2F728x90%2F1834%2Fss%2Fa%40top1,;ord=1215045259 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\KJHZU275\dref=http%253A%252F%252Fmessaging.myspace.com%252Findex[1].sent%2526type%253DInbox%2526messageID%253D26910443%2526fed%253DTrue%2526compose%253D0%2526friendID%253D297478153 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\KJHZU275\dref=http%253A%252F%252Fme[1].reply%2526friendId%253D297478153%2526type%253DInbox%2526messageID%253D26910443%2526fed%253DTrue%2526MyToken%253D13a33a83-b818-4cb4-b171-81aa08f5b639 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjptZDVBbUk2bFlmODNITTpqb3N
odWFwb2hsLmZpbGVzLndvcmRwcmVzcy5jb20vMjAwOC8wNC8xODQyMV9pcm9ubWFuLTAzX25vcm1hbC5q
cGc,[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAA2AEAAAAACgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAFxAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F4,;ord=1215184988 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAABAEAAAAABAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAN8-bkgAAAAA,,http[1].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184607 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAALAAAAAAACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAN9AbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215185119 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAALAEAAAAABwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAAk[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F2,;ord=1215184649 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAAmAEAAAAACQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAJE[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184785 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,7CEAAGliAQCv1A8AWvcEAAAAOAEAAAAACAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAABc[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F5,;ord=1215184663 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\IHGJI185\click,f9stAGliAQAPpwkAEGQDAAIAOAAAAP8AAAAGDAIACgKC7wUAzSUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAc7bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Ftennaya%2F13,;ord=1215183623 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\GB4QREDH\RightBanner2;pos=1;q=Treatment+For+Sunburn;tile=6;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutane;ca[2] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjpNZWtBVElQWG04a291TTp3d3c
ubWFydmVsLmNvbS91bml2ZXJzZTN6eC9pbWFnZXMvdGh1bWIvZi9mNS9Jcm9uTWFuX0hlYWQuanBnLzQ0
MHB4LUlyb25NYW5[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQAJpwkAEmQDAAIALAAAAP8AAAAGDAIAAgKC7wUAzyUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAI7bkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F11,;ord=1215183618 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQCv1A8AWvcEAAAAAAEAAAAAAwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANw-bkgAAAAA,,http[1].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184604 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQCv1A8AWvcEAAAAcAEAAAEACAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAG4[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184750 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQCv1A8AWvcEAAAAGAEAAAAABgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAPw-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184636 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQCv1A8AWvcEAAAAHAEAAAAABgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAP8-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184639 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,7CEAAGliAQCv1A8AWvcEAAAAQAAAAAAACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAPZAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215185142 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\C9CTU1Q1\click,f9stAGliAQATpwkAEWQDAAIAQAAAAP8AAAAGDAIACgKC7wUAziUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAABI7bkgAAAAA,,http%3A%2F%2Fwww[2].com%2Flayouts%2Ftennaya%2F15,;ord=1215183634 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjpHX1Zlbm1SMHNQLVE0TTp3d3c
ucGpsaWdodGhvdXNlLmNvbS93cC1jb250ZW50L3VwbG9hZHMvMjAwNy8xMC9pcm9uLW1hbi10aGUtdmlk
ZW8tZ2FtZS13YWx[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\aHR0cDovL2ltYWdlcy5nb29nbGUuY29tL2ltYWdlcz9xPXRibjpLWmdzN0VvVGMwNDlLTTppLmE
uY25uLm5ldC9zaS9mZWF0dXJlcy8yMDA3X3N3aW1zdWl0L2ltYWdlcy9waG90b3MvMDdfYmV5b25jZV8x
MC5qcGc=[1].jpg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQARpwkAD2QDAAIASAAAAP8AAAAGDAIABgKC7wUAzCUFAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAEo7bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F1,;ord=1215183690 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCCog4AybMEAAIAFAEAAP8AAAAGDAIAAgOC7wUA6tQGAJr-BgAAAAAAAAAAAAAAAAAAAAAAAAAAAPY-bkgAAAAA,,htt[2].com%2Fadservercontroller%2Findex%2Ftoprightbox%2F12,;ord=1215184630 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAA4AEAAAAACgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAF9AbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F5,;ord=1215184991 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAACAAAAAEACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAKdAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F4,;ord=1215185063 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAACAEAAAAABQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAOo-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184618 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAFAAAAAEACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAMBAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F8,;ord=1215185088 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAgAEAAAAACQAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAHc[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184759 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAIAAAAAEACwAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAANFAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215185105 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAQAEAAAAACAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAB0[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F6,;ord=1215184669 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAsAEAAAEACgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAABhAbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184920 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAVAEAAAIACAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAEU[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F11,;ord=1215184709 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAAAyAEAAAIACgAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAE5AbkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F2,;ord=1215184974 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\7TTJ0JXK\click,7CEAAGliAQCv1A8AWvcEAAIAzAAAAP8AAAAGDAIABgOC7wUAyCABAM1gBwAAAAAAAAAAA
AAAAAAAAAAAAAAAAKo-bkgAAAAA,,http[2].com%2Fadservercontroller%2Findex%2Ftopleader%2F12,;ord=1215184554 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\5V17H2RX\%26rnd%3D275325093%26ged%3D0%3A0%3Anwrlzgvjzdrkngm4ntgwni971qxtfkz3f56uctx9xq3giw2dpt3_gc9lc03wk_mxau62bfu9c7kcre
fuv_3kxpuw7uylk6pbkug1t1bzieqhcspvjhzdxybdhxw9uktn,;ord=1214841772 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\5V17H2RX\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ
nJjb2RlA2NzY195bWFpbGNnBGlzZXh0AzAEaXQDc2hvcnRjdXRzOi91cy9pbnN0YW5jZS9pZGVudGl[2]
.adNoOp&fr=csc_ymailcg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HUV05EV\;!c=b;!c=s;!c=nptr;ec=ron;ec=tb;ec=pb;dr=or;p=1;p=2;ec=ph;ec=th;pec=h;upec=h;ec=tfi;ec=t
ls;ec=pfi;ec=pls;sc=onam;sc=nmbg;al=nmbg;sc=ar;al=ar;al=macy;atf=e;sc=drRON;al=dr
;lf=[2].5 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HUV05EV\;_ylc=X1MDOTc1NDYxNjgEX3IDMgRjYXRlZ29yeQNJREVOVElGSUVSBGV4dGZyb20DBGZiAzAEZ
nJjb2RlA2NzY195bWFpbGNnBGlzZXh0AzAEaXQDc2hvcnRjdXRzOi91cy9pbnN0YW5jZS9pZGVudGl[2]
.adNoOp&fr=csc_ymailcg not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HUV05EV\click,IFQEAFXtBADyEQ4AqJIEAAIAAAAAAP8AAAACFQIAAgKSrgEAcM8GAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAANbITUgAAAAA,htt[2].com%2Fquestion%2Findex%3Fqid%3D20080607172103aa83ooi,;ord=1213057238 not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HUV05EV\RightBanner1;pos=1;q=Treatment+For+Sunburn;tile=2;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutane;ca[2] not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\Temporary Internet Files\Content.IE5\0HUV05EV\RightBottomText2;pos=1;q=Treatment+For+Sunburn;tile=5;cat1=;cat2=Support%3APsoriasis;cat3=skin_cancer;cat4=0032276518;cat5=;cat6=skin_and_sunburn_treatme
nts;cat7=Roaccutan[2] not found!
C:\Documents and Settings\SHAKIA\Local Settings\Temp\Google Toolbar\GoogleToolbarWelcome.log moved successfully.
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\JET11AB.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\JET4FFC.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\JET566.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\JET6299.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF73CF.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF73E3.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7565.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7578.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7733.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7746.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7CA9.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7D66.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF7F77.tmp not found!
File C:\Documents and Settings\SHAKIA\Local Settings\Temp\~DF8303.tmp not found!
C:\Documents and Settings\SHAKIA\Local Settings\Temporary Internet Files\Content.IE5\9X70EB0F\view_topic_subscriptions[1].html moved successfully.
C:\Documents and Settings\SHAKIA\Local Settings\Temporary Internet Files\Content.IE5\1TL5V5WQ\iframe[1].htm moved successfully.
C:\Documents and Settings\SHAKIA\Local Settings\Temporary Internet Files\Content.IE5\0FZ6FPVD\Am_I_Infected_t110667[1].htm moved successfully.
C:\Documents and Settings\SHAKIA\Local Settings\Temporary Internet Files\AntiPhishing\2CEDBFBC-DBA8-43AA-B1FD-CC8E6316E3E2.dat moved successfully.

Registry entries deleted on Reboot…

***********************************************************************

this is the log from Hijackthis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:35:13 PM, on 3/5/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe
C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\CA\CA Internet Security Suite\ccupdate\CCUpdate.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll
O2 - BHO: MSN Toolbar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: MSN Toolbar - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.0988.2\msneshellx.dll
O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlccmon.exe] "C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe"
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe"
O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [ISUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -scheduler
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://*.mcafee.com
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1182813660890
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) - http://www.adobe.com/products/acrobat/nos/gp.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} (RIM AxLoader) - http://mobileapps.blackberry.com/devicesoftware/AxLoader.cab
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://rimsupport.webex.com/client/T23L/support/ieatgpc.cab
O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - (no file)
O20 - Winlogon Notify: GoToAssist - C:\Program Files\Citrix\GoToAssist\516\G2AWinLogon.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files\Citrix\GoToAssist\516\g2aservice.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe

–
End of file - 13156 bytes
Boot to safemode. Dont let this scare you, its basically starting windows but with no programs so whatever is blocking the removal of this entry wont be running.

To Enter Safemode
  • Go to Start> Shut off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly,
    this will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to Safemode
  • Then press the Enter Key on your Keyboard
Tutorial if you need it How to boot into Safemode



Once in Safemode, remove this with Hijackthis

O18 - Filter hijack: text/html - {460734d1-772a-4d81-a6c6-30a07c34c0a8} - (no file)



To get our of Safemode, just go to Start > Shutdown> Restart and your computer will boot up to normal windows. Then run HJT and see if its gone
this is the log from DDS (i chose the 2nd one to click on) DDS (Ver_09-12-01.01) - NTFSx86 Run by [removed] at 21:46:12.93 on Fri 03/05/2010 Internet Explorer: 8.0.6001.18702 Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.510.173 [GMT -5:00] AV: CA Anti-Virus *On-access scanning enabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93} AV: ZoneAlarm Antivirus *On-access scanning disabled* (Outdated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF} FW: CA Personal Firewall *enabled* {14CB4B80-8E52-45EA-905E-67C1267B4160} FW: ZoneAlarm Firewall *disabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B} ============== Running Processes =============== C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup svchost.exe svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe svchost.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\WINDOWS\Explorer.EXE C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe C:\WINDOWS\system32\svchost.exe -k imgsvc C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe C:\Program Files\Analog Devices\Core\smax4pnp.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\Program Files\Dell\Media Experience\DMXLauncher.exe C:\Program Files\Dell Photo AIO Printer 924\dlccmon.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\DellSupport\DSAgnt.exe C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe C:\WINDOWS\system32\dlcccoms.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CAGlobal.exe C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe C:\WINDOWS\system32\wuauclt.exe C:\Documents and Settings\SHAKIA\Local Settings\Temporary Internet Files\Content.IE5\Q1E3IBK2\dds[1].scr ============== Pseudo HJT Report =============== uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8 uDefault_Page_URL = hxxp://www.msn.com uInternet Settings,ProxyOverride = *.local uSearchURL,(Default) = hxxp://www.google.com/search?q=%s BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\tfswshx.dll BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\5.5.4723.1820\swg.dll BHO: MSN Toolbar Helper: {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll BHO: CA Toolbar Helper: {fbf2401b-7447-4727-be5d-c19b2075ca84} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll TB: MSN Toolbar: {1e61ed7c-7cb8-49d6-b9e9-ab4c880c8414} - c:\program files\msn\toolbar\3.0.0988.2\msneshellx.dll TB: CA Toolbar: {10134636-e7af-4ac5-a1dc-c7c44bb97d81} - c:\program files\ca\ca internet security suite\ca website inspector\toolbar\CallingIDIE.dll TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll TB: {604BC32A-9680-40D1-9AC6-E06B23A1BA4C} - No File uRun: [DellSupport] "c:\program files\dellsupport\DSAgnt.exe" /startup uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe" uRun: [ISUSPM] "c:\program files\common files\installshield\updateservice\isuspm.exe" -scheduler uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe mRun: [SoundMAXPnP] c:\program files\analog devices\core\smax4pnp.exe mRun: [dla] c:\windows\system32\dla\tfswctrl.exe mRun: [ISUSPM Startup] "c:\program files\common files\installshield\updateservice\isuspm.exe" -startup mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start mRun: [DMXLauncher] c:\program files\dell\media experience\DMXLauncher.exe mRun: [DLCCCATS] rundll32 c:\windows\system32\spool\drivers\w32x86\3\DLCCtime.dll,_RunDLLEntry@16 mRun: [dlccmon.exe] "c:\program files\dell photo aio printer 924\dlccmon.exe" mRun: [igfxtray] c:\windows\system32\igfxtray.exe mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe mRun: [igfxpers] c:\windows\system32\igfxpers.exe mRun: [] mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe" mRun: [SunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe" mRun: [cctray] "c:\program files\ca\ca internet security suite\cctray\cctray.exe" mRun: [CAVRID] "c:\program files\ca\ca internet security suite\ca anti-virus\CAVRID.exe" mRun: [QOELOADER] "c:\program files\ca\ca internet security suite\ca anti-spam\qsp-6.0.1.33\QOELoader.exe" mRun: [cafw] c:\program files\ca\ca internet security suite\ca personal firewall\cafw.exe -cl mRun: [capfasem] c:\program files\ca\ca internet security suite\ca personal firewall\capfasem.exe mRun: [capfupgrade] c:\program files\ca\ca internet security suite\ca personal firewall\capfupgrade.exe mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\adober~1.lnk - c:\program files\adobe\acrobat 7.0\reader\reader_sl.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\kodake~1.lnk - c:\program files\kodak\kodak easyshare software\bin\EasyShare.exe mPolicies-explorer: EnableShellExecuteHooks = 1 (0x1) IE: Google Sidewiki… - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.html IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll LSP: c:\windows\system32\VetRedir.dll Trusted Zone: internet Trusted Zone: mcafee.com DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1182813660890 DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - hxxp://atv.disney.go.com/global/download/otoy/OTOYAX29b.cab DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.4.2/jinstall-1_4_2_03-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} - hxxp://www.adobe.com/products/acrobat/nos/gp.cab DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab DPF: {DAF7E6E6-D53A-439A-B28D-12271406B8A9} - hxxp://mobileapps.blackberry.com/devicesoftware/AxLoader.cab DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://rimsupport.webex.com/client/T23L/support/ieatgpc.cab Notify: GoToAssist - c:\program files\citrix\gotoassist\516\G2AWinLogon.dll Notify: igfxcui - igfxdev.dll Notify: PFW - UmxWnp.Dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SEH: ShellHook Class: {1869181a-9f50-4fcf-8bff-1b8588ecb85c} - c:\program files\ca\ca internet security suite\ca website inspector\linkadvisor\CIDLinkAdvisor.dll SecurityProviders: msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, mcenspc.dll ============= SERVICES / DRIVERS =============== R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-3-19 93712] R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-3-21 63504] R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-3-21 45584] R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-3-19 115216] R1 VET-FILT;VET File System Filter;c:\windows\system32\drivers\vet-filt.sys [2009-8-11 26352] R1 VET-REC;VET File System Recognizer;c:\windows\system32\drivers\vet-rec.sys [2009-8-11 21104] R1 VETEFILE;VET File Scan Engine;c:\windows\system32\drivers\vetefile.sys [2009-8-11 739696] R1 VETFDDNT;VET Floppy Boot Sector Monitor;c:\windows\system32\drivers\vetfddnt.sys [2009-8-11 21488] R1 VETMONNT;VET File Monitor;c:\windows\system32\drivers\vetmonnt.sys [2009-8-11 161008] R2 CAISafe;CAISafe;c:\program files\ca\ca internet security suite\ca anti-virus\isafe.exe [2009-8-11 144696] R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-6-4 134648] R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-3-21 66576] R2 UmxAgent;HIPS Event Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxAgent.exe [2007-10-18 1010192] R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\ca\sharedcomponents\hipsengine\UmxCfg.exe [2007-10-18 801296] R2 UmxPol;HIPS Policy Manager;c:\program files\ca\sharedcomponents\hipsengine\UmxPol.exe [2008-4-15 281104] R2 VETMSGNT;VET Message Service;c:\program files\ca\ca internet security suite\ca anti-virus\vetmsg.exe [2009-8-11 255216] R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-5-30 88816] R3 PPCtlPriv;PPCtlPriv;c:\program files\ca\ca internet security suite\ca anti-spyware\PPCtlPriv.exe [2009-8-11 185584] R3 VETEBOOT;VET Boot Scan Engine;c:\windows\system32\drivers\veteboot.sys [2009-8-11 133520] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-6 135664] S4 0063331182812236mcinstcleanup;McAfee Application Installer Cleanup (0063331182812236);c:\docume~1\shakia\locals~1\temp\006333~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service –> c:\docume~1\shakia\locals~1\temp\006333~1.exe c:\progra~1\common~1\mcafee\instal~1\cleanup.ini -cleanup -nolog -service [?] =============== Created Last 30 ================ 2010-03-04 01:34:30 0 d—–w- C:\_OTM 2010-02-11 02:05:21 0 d—–w- c:\program files\Zone Labs 2010-02-11 02:05:10 0 d—–w- c:\windows\Internet Logs 2010-02-11 01:21:36 0 —-a-w- c:\windows\Textart.INI ==================== Find3M ==================== 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k7 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k6 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k5 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k4 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k3 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k2 2010-03-06 02:25:43 64 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k1 2010-03-06 02:25:43 216764 —-a-w- c:\windows\system32\drivers\kmxcfg.u2k0 2010-02-11 02:06:46 5018 –sha-w- c:\windows\system32\KGyGaAvL.sys 2009-12-31 16:50:03 353792 ——w- c:\windows\system32\dllcache\srv.sys 2009-12-26 20:35:03 43412 —ha-w- c:\windows\system32\mlfcache.dat 2009-12-21 13:19:18 173056 ——w- c:\windows\system32\dllcache\ie4uinit.exe 2009-12-16 18:43:27 343040 —-a-w- c:\windows\system32\mspaint.exe 2009-12-16 18:43:27 343040 ——w- c:\windows\system32\dllcache\mspaint.exe 2009-12-14 07:08:23 33280 —-a-w- c:\windows\system32\csrsrv.dll 2009-12-14 07:08:23 33280 ——w- c:\windows\system32\dllcache\csrsrv.dll 2009-12-09 05:53:44 726528 —-a-w- c:\windows\system32\dllcache\jscript.dll 2009-12-08 19:27:51 2189184 —-a-w- c:\windows\system32\ntoskrnl.exe 2009-12-08 19:27:51 2189184 ——w- c:\windows\system32\dllcache\ntoskrnl.exe 2009-12-08 19:26:15 2145280 ——w- c:\windows\system32\dllcache\ntkrnlmp.exe 2009-12-08 18:43:51 2023936 ——w- c:\windows\system32\dllcache\ntkrpamp.exe 2009-12-08 18:43:50 2066048 —-a-w- c:\windows\system32\ntkrnlpa.exe 2009-12-08 18:43:50 2066048 ——w- c:\windows\system32\dllcache\ntkrnlpa.exe 2009-12-08 09:23:28 474112 ——w- c:\windows\system32\dllcache\shlwapi.dll 2009-03-19 23:34:28 32768 –sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009031920090320\index.dat ============= FINISH: 21:47:53.14 ===============
Key I'm resding from my blackberry. Question. Its asking if I want to proceed in safe mode. Its saying if u prefer 2 use system restore to restore my computer to a previous state click no. What do I do @ this point I'm stuck
well I went into safe mode——> I the opened hijackthis ran the scan w/log ——> this is the result. doent look like it did anything either I will let the expert be the judge w/ this one! here it is: wait…….awww man the copy option didn't take. huh!!!! Well I guess this is a sign 4 me to stop. I gonna resume this tomorrow I'm gonna restart the computer, hit the f8 key the i'm gonna scroll up to safe mode click yes to operate in safe mode. While in safe mode im gonna run the scan in HJT click on that 018 problem click fix check, the run it again w/ the log copy and paste info in what the tech. I will logg on sometime tomorrow w/ the results in the "safemode" setting!
Shakia,

When you ran the DDS scan it picked up some other nasty junk. Just forget about the Safemode fix for now and run a program called Combofix. You can download it but before you run it you need to temporarily disable your CA Anti Virus and Firewall

Right click on the CA AV icon in the task bar. Cursor down to "CA Anti Virus" and then left click on "Snooze Anti Virus Protection". Set the length of time, you want it to remain inctive, in the menu that pops up and then left click on "Snooze". I believe you can do this for the firewall as well. Set if for an hour or so .

Download ComboFix from one of these locations:

Link 1
Link 2


* IMPORTANT !!! Save ComboFix.exe to your Desktop


  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.

  • Double click on ComboFix.exe & follow the prompts.

  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.

  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.


[external image: Posted Image]



Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]


Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply along with a New Hijackthis log.

*If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI