Susan,
Thanks for the help. I, unfortunately, did not see the piece about not running HiJackThis form the temp directory and thus, did not run it from a permanent folder yet. I will do so soon. I did run the rest of the steps and here are my results.
Logfile of HijackThis v1.99.1
Scan saved at 11:04:19 PM, on 11/21/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Common Files\AOL\1127874074\ee\AOLHostManager.exe
C:\DOCUME~1\Tara\LOCALS~1\Temp\temp25.exe
C:\Program Files\Spyware Doctor\swdoctor.exe
C:\Program Files\Common Files\AOL\1127874074\ee\AOLServiceHost.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\program files\common files\aol\1127874074\ee\services\antiSpywareApp\ver2_0_7\AOLSP Scheduler.exe
C:\Program Files\Common Files\AOL\1127874074\ee\AOLServiceHost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\HPHipm11.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Documents and Settings\Tara\Local Settings\Temp\Temporary Directory 2 for hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell4me.com/myway
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {B73F75B8-93F3-429D-FF34-660B206D897A} - C:\WINDOWS\System32\pifn.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
O4 - HKLM\..\Run: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
O4 - HKLM\..\Run: [Systemos Restart] Rundll32.exe pifn.dll, DllRegisterServer
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbOEAddOn.exe
O4 - HKLM\..\Run: [inmpoekc] C:\WINDOWS\System32\aolkvact.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1127874074\ee\AOLHostManager.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [xservice] C:\DOCUME~1\Tara\LOCALS~1\Temp\temp25.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1127091139031
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) -
http://www.kodakgall..._1/axofupld.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) -
http://h30043.www3.h.../qdiagh.cab?321
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Spysweeper:
I ran spysweeper and had it remove all that it found. I did not capture the log before it rebooted my computer but it removed hotbar along with a few others that all appeared to be programs that rediredcted my browser to search pages.
Ewido:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:59:51 PM, 11/21/2005
+ Report-Checksum: 6ADEA395
+ Scan result:
HKLM\SOFTWARE\Classes\Interface\{3C1A06CC-3981-4DB9-B5B6-B4B8ECB1D7F2}\TypeLib\\ -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{4921DB9C-64EA-430A-ABD2-D016DB5A0AC4}\ProxyStubClsid32\\ -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EA232A0A-46F8-4D44-A30B-50321518A828} -> Spyware.HotBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EA232A0A-46F8-4D44-A30B-50321518A828}\ProxyStubClsid32\\ -> Spyware.HotBar : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-21-951115610-2518554193-3362072689-1008\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Internet Explorer\Extensions\CmdMapping\\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Spyware.Alexa : Error during cleaning
C:\Documents and Settings\Tara\Local Settings\Temp\tmp16.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp17.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp18.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp1C.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp1D.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp1E.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp20.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp22.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp24.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp25.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp26.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp27.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp2B.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp2C.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp2D.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp31.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp32.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp33.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp35.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp36.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp37.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp3A.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp3C.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp41.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp42.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp43.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp45.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp46.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp48.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp49.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp4A.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp4B.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp51.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp52.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp53.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp54.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp5A.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp5B.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp5C.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp5D.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp60.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp61.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp62.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp67.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp69.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp6A.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp75.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp76.tmp -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp79.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp7B.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp7C.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp7D.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp7E.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp85.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmp86.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temp\tmpC.tmp -> TrojanDownloader.Murlo.b : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temporary Internet Files\Content.IE5\0X6NKD6V\34372[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temporary Internet Files\Content.IE5\0XSR8R0V\34372[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temporary Internet Files\Content.IE5\45IN0XI7\34372[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temporary Internet Files\Content.IE5\YMWNL50K\34372[1].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Documents and Settings\Tara\Local Settings\Temporary Internet Files\Content.IE5\YMWNL50K\34372[2].exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP386\A0017209.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP386\A0017214.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP387\A0017248.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP444\A0021947.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP451\A0022155.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP454\A0022239.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP454\A0022261.exe -> Spyware.HotBar : Cleaned with backup
C:\System Volume Information\_restore{CCA15F78-7193-4CA6-8115-2B570DD6546C}\RP454\A0022275.exe -> TrojanDownloader.Small.ait : Cleaned with backup
C:\WINDOWS\SYSTEM32\34887671.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\511343921.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\648031.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\82173187.exe -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\SYSTEM32\87050468.exe -> Spyware.Hijacker.Generic : Cleaned with backup
::Report End
CWShredder:
**** Run Keys ****
RUN: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
RUN: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
RUN: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
RUN: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
RUN: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
RUN: [UpdReg] C:\WINDOWS\UpdReg.EXE
RUN: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
RUN: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
RUN: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
RUN: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
RUN: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
RUN: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
RUN: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
RUN: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe
RUN: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
RUN: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
RUN: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
RUN: [VirusScan Online] c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
RUN: [EPSON Stylus CX6600 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATI9EA.EXE /P26 "EPSON Stylus CX6600 Series" /O6 "USB001" /M "Stylus CX6600"
RUN: [Systemos Restart] Rundll32.exe pifn.dll, DllRegisterServer
RUN: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.6.1.0\SbOEAddOn.exe
RUN: [inmpoekc] C:\WINDOWS\System32\aolkvact.exe
RUN: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
RUN: [HostManager] C:\Program Files\Common Files\AOL\1127874074\ee\AOLHostManager.exe
RUN: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
RUN: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
RUN: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
RUN: [xservice] C:\DOCUME~1\Tara\LOCALS~1\Temp\temp25.exe
RUN: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
**** Browser Helper Objects ****
BHO: [AcroIEHlprObj Class] C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
BHO: [] C:\PROGRA~1\SPYBOT~1\SDHelper.dll
BHO: [PCTools Site Guard] C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
BHO: [DriveLetterAccess] C:\WINDOWS\system32\dla\tfswshx.dll
BHO: [PCTools Browser Monitor] C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
BHO: [PCTools Browser Monitor] C:\WINDOWS\System32\pifn.dll
Edited by jpb, 22 November 2005 - 08:50 AM.