This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Not sure what my computer has picked up but need help getting rid of i

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried just about everything to get rid of pesky popups in IE to no avail. I even had to uninstall Firefox because it was happening there also. Spybot S&D & AdAware both say they have cleaned files but something is still there.
See my hjt log below. Thanks much.

Logfile of HijackThis v1.99.1
Scan saved at 9:33:03 PM, on 3/7/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\RssReader\RssReader.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O15 - Trusted Zone: *.crosskirknet.com
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.filesharingaccess.com
O15 - Trusted Zone: *.gimmycash.com
O15 - Trusted Zone: *.gimmysmileys.com
O15 - Trusted Zone: *.imagesrvr.com
O15 - Trusted Zone: *.kabum.pl
O15 - Trusted Zone: *.kazaa-forum.com
O15 - Trusted Zone: *.media-motor.com
O15 - Trusted Zone: *.mediatickets.net
O15 - Trusted Zone: *.sxload.com
O15 - Trusted Zone: *.traffic-stats.org
O15 - Trusted Zone: *.crosskirknet.com (HKLM)
O15 - Trusted Zone: *.dollarrevenue.com (HKLM)
O15 - Trusted Zone: *.filesharingaccess.com (HKLM)
O15 - Trusted Zone: http://click.getmirar.com (HKLM)
O15 - Trusted Zone: *.gimmycash.com (HKLM)
O15 - Trusted Zone: *.gimmysmileys.com (HKLM)
O15 - Trusted Zone: *.imagesrvr.com (HKLM)
O15 - Trusted Zone: *.kabum.pl (HKLM)
O15 - Trusted Zone: *.kazaa-forum.com (HKLM)
O15 - Trusted Zone: *.media-motor.com (HKLM)
O15 - Trusted Zone: *.mediatickets.net (HKLM)
O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)
O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)
O15 - Trusted Zone: *.traffic-stats.org (HKLM)
O15 - Trusted Zone: *.winantivirus.com (HKLM)
O15 - Trusted Zone: *.yoursitebar.com (HKLM)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O20 - Winlogon Notify: RunOnce - C:\WINDOWS\system32\ktlul7391.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
Download THIS file to your desktop.

Right-click on the deldomains.inf file and select 'Install'

Once it is finished your Zones should be reset.

Note, if you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection.

NEXT

Please download Look2Me-Destroyer.exe to your desktop.
  • Close all windows before continuing.
  • Double-click Look2Me-Destroyer.exe to run it.
  • Put a check next to Run this program as a task .
  • You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 10 seconds. Click OK
  • When Look2Me-Destroyer re-opens, click the Scan for L2M button , your desktop icons will disappear, this is normal.
  • Once it's done scanning, click the Remove L2M button .
  • You will receive a Done Scanning message, click OK .
  • When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK .
  • Your computer will then shutdown.
  • Turn your computer back on.
  • Please post the contents of C:\Look2Me-Destroyer.txt and a new HiJackThis log.
If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339'. please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32. Directory
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX
Here is the l2m log & the hjt log after follwing your instructions. Have gotten a couple of popups since but nowhere near as many as before.


Look2Me-Destroyer V1.0.7

Scanning for infected files…..
Scan started at 3/7/2006 11:46:15 PM

Infected! C:\WINDOWS\system32\ktlul7391.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP425\A0175752.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175937.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175943.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175947.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175979.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175982.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175983.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175984.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175985.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175987.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175991.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176009.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176033.dll
Infected! C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176037.dll
Infected! C:\WINDOWS\system32\CGDBUIRoxio.dll
Infected! C:\WINDOWS\system32\k4js0e17eh.dll
Infected! C:\WINDOWS\system32\ktlul7391.dll
Infected! C:\WINDOWS\system32\wmn87em.dll
Infected! C:\WINDOWS\system32\guard.tmp

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\ktlul7391.dll
C:\WINDOWS\system32\ktlul7391.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP425\A0175752.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP425\A0175752.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175937.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175937.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175943.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175943.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175947.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP426\A0175947.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175979.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175979.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175982.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175982.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175983.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175983.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175984.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175984.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175985.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175985.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175987.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175987.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175991.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0175991.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176009.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176009.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176033.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176033.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176037.dll
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP427\A0176037.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\CGDBUIRoxio.dll
C:\WINDOWS\system32\CGDBUIRoxio.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\k4js0e17eh.dll
C:\WINDOWS\system32\k4js0e17eh.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\ktlul7391.dll
C:\WINDOWS\system32\ktlul7391.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\wmn87em.dll
C:\WINDOWS\system32\wmn87em.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\guard.tmp
C:\WINDOWS\system32\guard.tmp Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnce

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0AEC0E99-06A9-4020-B09C-1AA4A0396262}"
HKCR\Clsid\{0AEC0E99-06A9-4020-B09C-1AA4A0396262}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E1BBFF8F-F7A2-4BBB-8A4E-ACDC47E7B000}"
HKCR\Clsid\{E1BBFF8F-F7A2-4BBB-8A4E-ACDC47E7B000}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{CED77F07-2B20-4AC2-A962-F03BE752EBD9}"
HKCR\Clsid\{CED77F07-2B20-4AC2-A962-F03BE752EBD9}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{61FFCFF8-1F67-4FB8-B24D-DD7AB840ADC6}"
HKCR\Clsid\{61FFCFF8-1F67-4FB8-B24D-DD7AB840ADC6}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A198B33E-20A1-4152-86EA-292895DAB433}"
HKCR\Clsid\{A198B33E-20A1-4152-86EA-292895DAB433}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{0801122D-9996-4DDE-B3FB-F0F10A78AF79}"
HKCR\Clsid\{0801122D-9996-4DDE-B3FB-F0F10A78AF79}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

And here is the hjt log

Logfile of HijackThis v1.99.1
Scan saved at 12:34:16 AM, on 3/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\Program Files\RssReader\RssReader.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Program Files\Spyware Doctor\swdoctor.exe" /Q
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Thanks
Please download the trial version of Ewido Security Suite here:
http://www.ewido.net/en/download/

Install it, and update the definitions to the newest files.

Next, please reboot your computer in Safe Mode by doing the following:
1) Restart your computer
2) After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
3) Instead of Windows loading as normal, a menu should appear
4) Select the first option, to run Windows in Safe Mode.

Then please run Ewido, and run a full scan. Save the logfile from the scan.

Restart your computer in normal mode and please post a new HijackThis log, as well as the log from the Ewido scan.
Here is the ewido log after running in safe mode.

———————————————————
ewido anti-malware - Scan report
———————————————————

+ Created on: 9:01:29 PM, 3/8/2006
+ Report-Checksum: AA3EADB2

+ Scan result:

C:\Documents and Settings\Louise\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\louise@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\louise@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\louise@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\louise@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\louise@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Louise\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@2o7[2].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@com[1].txt -> TrackingCookie.Com : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@skyauction.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temporary Internet Files\Content.IE5\4QBLFEFY\AppWrap[1].exe -> Adware.AdURL : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temporary Internet Files\Content.IE5\GTSGDBR4\AppWrap[1].exe -> Adware.Zestyfind : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temporary Internet Files\Content.IE5\JKOEO9WH\AppWrap[1].exe -> Adware.AdURL : Cleaned with backup
C:\Documents and Settings\Louise\Local Settings\Temporary Internet Files\Content.IE5\OVEPGF4V\AppWrap[1].exe -> Adware.AdURL : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Zach\Application Data\Mozilla\Firefox\Profiles\erwgu9s6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Zach\Application Data\Mozilla\Firefox\Profiles\erwgu9s6.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Zach\Cookies\zach@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Zach\Local Settings\Temp\!update.exe -> Downloader.PurityScan.bw : Cleaned with backup
C:\Documents and Settings\Zach\Local Settings\Temporary Internet Files\Content.IE5\KPUZEBOX\!update-3595[1].0000 -> Downloader.PurityScan.bw : Cleaned with backup
C:\Program Files\Common Files\Οracle\ati2evxx.exe -> Downloader.PurityScan.bw : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@epilot[1].txt -> TrackingCookie.Epilot : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned with backup
C:\WINDOWS\Temp\Cookies\louise@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\WINDOWS\Temp\Cookies\[removed][1].txt -> TrackingCookie.Adserver : Cleaned with backup


::Report End

And here is the hjt logdone after rebooting.

Logfile of HijackThis v1.99.1
Scan saved at 9:09:19 PM, on 3/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\savedump.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\Program Files\RssReader\RssReader.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\Dantz\RETROS~1\retrospect.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
It's running much better. I can now leave my computer on for long periods without fear of it locking up because of all the popups. Now I only get the occasional popup when I actually open IE. Is there a way to get rid of them completely? Thanks so much for your help.
Please do an online scan with Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then start to download the latest definition files.
  • Once the scanner is installed and the definitions downloaded, click Next.
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
      • Extended (If available otherwise Standard)
    • Scan Options:
      • Scan Archives
      • Scan Mail Bases
  • Click OK
  • Now under select a target to scan select My Computer
  • The scan will take a while so be patient and let it run. Once the scan is complete it will display if your system has been infected.
  • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post as well as a bew hijackthis log please.
Here is the log from the KASPERSKY scan. That one really took awhile & it found quite a few things.

——————————————————————————-
KASPERSKY ON-LINE SCANNER REPORT
Friday, March 10, 2006 02:11:03
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 10/03/2006
Kaspersky Anti-Virus database records: 170163
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
K:\

Scan Statistics:
Total number of scanned objects: 179880
Number of viruses found: 13
Number of infected objects: 71
Number of suspicious objects: 4
Duration of the scan process: 12477 sec

Infected Object Name - Virus Name
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy26.zip/adv.exe Suspicious: Password-protected-EXE
C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy26.zip Suspicious: Password-protected-EXE
C:\Documents and Settings\Louise\Local Settings\Temp\temp.frDCD3 Infected: Trojan.Win32.Crypt.t
C:\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w
C:\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip Infected: Trojan-Downloader.Java.OpenStream.w
C:\Documents and Settings\Zach\Desktop\netpumper-1.20.1-setup.exe/data0079 Infected: Trojan-Downloader.Win32.Swizzor.cx
C:\Documents and Settings\Zach\Desktop\netpumper-1.20.1-setup.exe Infected: Trojan-Downloader.Win32.Swizzor.cx
C:\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.ja
C:\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.nn
C:\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe Infected: Trojan-Downloader.Win32.IstBar.nn
C:\Documents and Settings\Zach\Local Settings\Temp\jetip.exe Infected: Trojan.Win32.Crypt.t
C:\Program Files\Calypso3\Mailbox\backup\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
C:\Program Files\Calypso3\Mailbox\backup\My Mail.box Infected: Trojan.JS.Relink.b
C:\Program Files\Calypso3\Mailbox\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
C:\Program Files\Calypso3\Mailbox\My Mail.box Infected: Trojan.JS.Relink.b
C:\System Volume Information\_restore{A0C99121-C4A0-4F08-B645-9CD95AB7EA23}\RP441\A0176739.exe Infected: Trojan-Downloader.Win32.PurityScan.bw
C:\WINDOWS\secure32.html Infected: not-virus:Hoax.Win32.Renos.y
C:\WINDOWS\system32\a.exe Infected: Trojan-Clicker.Win32.VB.lb
C:\WINDOWS\system32\datsethc.exe Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\system32\mqclsapi.exe Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\system32\wmpcjt32.exe Infected: Trojan.Win32.Crypt.t
C:\WINDOWS\YOINSI.exe/data0002 Infected: Trojan.Win32.Scapur.k
C:\WINDOWS\YOINSI.exe Infected: Trojan.Win32.Scapur.k
E:\Courier Email\Mailbox\My Mail.old.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
E:\Courier Email\Mailbox\My Mail.old.box Infected: Trojan.JS.Relink.b
E:\Downloads\3dEggs.exe/SETUP_POWERSEARCH.EXE/data0003 Infected: Trojan-Downloader.Win32.Keenval.k
E:\Downloads\3dEggs.exe/SETUP_POWERSEARCH.EXE Infected: Trojan-Downloader.Win32.Keenval.k
E:\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE/data0002 Infected: Trojan-Downloader.Win32.Keenval.k
E:\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE/data0003 Infected: Trojan-Downloader.Win32.Keenval.j
E:\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE Infected: Trojan-Downloader.Win32.Keenval.j
E:\Downloads\3dEggs.exe Infected: Trojan-Downloader.Win32.Keenval.j
E:\old malibox\backup\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
E:\old malibox\backup\My Mail.box Infected: Trojan.JS.Relink.b
E:\old malibox\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
E:\old malibox\My Mail.box Infected: Trojan.JS.Relink.b
E:\old malibox\My Mail.box.bak/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
E:\old malibox\My Mail.box.bak Infected: Trojan.JS.Relink.b
G:\Fullbackup\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy26.zip/adv.exe Suspicious: Password-protected-EXE
G:\Fullbackup\C\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\ExactAdvertisingBargainsBuddy26.zip Suspicious: Password-protected-EXE
G:\Fullbackup\C\Documents and Settings\Louise\Local Settings\Temp\temp.frDCD3 Infected: Trojan.Win32.Crypt.t
G:\Fullbackup\C\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip/javainstaller/InstallerApplet.class Infected: Trojan-Downloader.Java.OpenStream.w
G:\Fullbackup\C\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip Infected: Trojan-Downloader.Java.OpenStream.w
G:\Fullbackup\C\Documents and Settings\Zach\Desktop\netpumper-1.20.1-setup.exe/data0079 Infected: Trojan-Downloader.Win32.Swizzor.cx
G:\Fullbackup\C\Documents and Settings\Zach\Desktop\netpumper-1.20.1-setup.exe Infected: Trojan-Downloader.Win32.Swizzor.cx
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temp\!update.exe Infected: Trojan-Downloader.Win32.PurityScan.bw
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe/data0001 Infected: Trojan-Downloader.Win32.IstBar.ja
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe/data0003 Infected: Trojan-Downloader.Win32.IstBar.nn
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe Infected: Trojan-Downloader.Win32.IstBar.nn
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temp\jetip.exe Infected: Trojan.Win32.Crypt.t
G:\Fullbackup\C\Documents and Settings\Zach\Local Settings\Temporary Internet Files\Content.IE5\KPUZEBOX\!update-3595[1].0000 Infected: Trojan-Downloader.Win32.PurityScan.bw
G:\Fullbackup\C\Program Files\Calypso3\Mailbox\backup\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\C\Program Files\Calypso3\Mailbox\backup\My Mail.box Infected: Trojan.JS.Relink.b
G:\Fullbackup\C\Program Files\Calypso3\Mailbox\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\C\Program Files\Calypso3\Mailbox\My Mail.box Infected: Trojan.JS.Relink.b
G:\Fullbackup\C\WINDOWS\secure32.html Infected: not-virus:Hoax.Win32.Renos.y
G:\Fullbackup\C\WINDOWS\system32\a.exe Infected: Trojan-Clicker.Win32.VB.lb
G:\Fullbackup\C\WINDOWS\system32\datsethc.exe Infected: Trojan.Win32.Crypt.t
G:\Fullbackup\C\WINDOWS\system32\mqclsapi.exe Infected: Trojan.Win32.Crypt.t
G:\Fullbackup\C\WINDOWS\system32\wmpcjt32.exe Infected: Trojan.Win32.Crypt.t
G:\Fullbackup\C\WINDOWS\YOINSI.exe/data0002 Infected: Trojan.Win32.Scapur.k
G:\Fullbackup\C\WINDOWS\YOINSI.exe Infected: Trojan.Win32.Scapur.k
G:\Fullbackup\E\Courier Email\Mailbox\My Mail.old.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\Courier Email\Mailbox\My Mail.old.box Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\Downloads\3dEggs.exe/SETUP_POWERSEARCH.EXE/data0003 Infected: Trojan-Downloader.Win32.Keenval.k
G:\Fullbackup\E\Downloads\3dEggs.exe/SETUP_POWERSEARCH.EXE Infected: Trojan-Downloader.Win32.Keenval.k
G:\Fullbackup\E\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE/data0002 Infected: Trojan-Downloader.Win32.Keenval.k
G:\Fullbackup\E\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE/data0003 Infected: Trojan-Downloader.Win32.Keenval.j
G:\Fullbackup\E\Downloads\3dEggs.exe/SETUP_INCREDIFIND_ONLY.EXE Infected: Trojan-Downloader.Win32.Keenval.j
G:\Fullbackup\E\Downloads\3dEggs.exe Infected: Trojan-Downloader.Win32.Keenval.j
G:\Fullbackup\E\old malibox\backup\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\old malibox\backup\My Mail.box Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\old malibox\My Mail.box/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\old malibox\My Mail.box Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\old malibox\My Mail.box.bak/Received Mail/Comcast/To:"Beverly Viola" <[removed]>, "Brian Kelly" <[removed]>, "Carol Montambeault" <[removed]>, "Denise Montambeault" <[removed]>, "Jeanet Infected: Trojan.JS.Relink.b
G:\Fullbackup\E\old malibox\My Mail.box.bak Infected: Trojan.JS.Relink.b

Scan process completed.

Here is the hjt log after I turned my computer back on.

Logfile of HijackThis v1.99.1
Scan saved at 2:16:04 PM, on 3/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\Program Files\RssReader\RssReader.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\mqsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator

5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter

Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art

Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital

Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program

files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program

files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program

files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program

files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program

files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -

C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -

http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -

http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -

http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -

http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} -

http://cabs.elitemediagroup.net/cabs/mediaview.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program

Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido

anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development

Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation -

C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program

Files\Spyware Doctor\sdhelp.exe

Thanks
Download CCleaner from here >>>>> http://www.majorgeeks.com/download4191.html

Save it to your desktop. Open CCleaner and click on "run cleaner" at the bottom right.

Next

Click Start | Settings | Control Panel
Click the Java Plugin Icon
Click the Cache tab
Click the Clear button and click OK to confirm

Next

Click here to run ActiveScan.
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location.
Paste the contents of the Panda scan report along with a new HijackThis Log in your next reply.
Okay here is the scan report from Panda. Incident Status Location Adware:adware/purityscan Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\!update.exe Adware:adware/superspider Not disinfected C:\WINDOWS\SYSTEM32\a.exe Potentially unwanted tool:application/mywebsearch Not disinfected C:\WINDOWS\SYSTEM32\f3PSSavr.scr Adware:adware/look2me Not disinfected C:\WINDOWS\TEMP\bw2.com Potentially unwanted tool:application/funweb Not disinfected C:\WINDOWS\DOWNLOADED PROGRAM FILES\f3initialsetup1.0.0.15.inf Adware:adware/adurl Not disinfected C:\WINDOWS\icont.exe Adware:adware/secure32 Not disinfected C:\WINDOWS\secure32.html Adware:adware/cws.searchmeup Not disinfected C:\WINDOWS\uniq Adware:adware/wupd Not disinfected C:\PROGRAM FILES\MediaGateway Adware:adware/maxifiles Not disinfected C:\PROGRAM FILES\COMMON FILES\Download Adware:adware/mediatickets Not disinfected Windows Registry Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Louise\Cookies\louise@trafficmp[2].txt Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\!update.exe Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@888[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@888[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@azjmp[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@belnk[1].txt Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@cassava[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\[removed][2].txt Spyware:Cookie/go Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@go[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Louise\Local Settings\Temp\Cookies\louise@realmedia[2].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Zach\Application Data\Mozilla\Firefox\Profiles\erwgu9s6.default\cookies.txt[] Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip[InstallerApplet.class] Spyware:Cookie/64.62.232 Not disinfected C:\Documents and Settings\Zach\Cookies\zach@64.62.232[4].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Zach\Cookies\zach@888[1].txt Spyware:Cookie/888 Not disinfected C:\Documents and Settings\Zach\Cookies\zach@888[2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Gorillanation Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Zach\Cookies\zach@adultfriendfinder[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Zach\Cookies\zach@azjmp[2].txt Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Zach\Cookies\zach@banner[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Zach\Cookies\zach@belnk[2].txt Spyware:Cookie/Barelylegal Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Cassava Not disinfected C:\Documents and Settings\Zach\Cookies\zach@cassava[1].txt Spyware:Cookie/Ccbill Not disinfected C:\Documents and Settings\Zach\Cookies\zach@ccbill[1].txt Spyware:Cookie/Centralmedia Not disinfected C:\Documents and Settings\Zach\Cookies\zach@centralmedia[1].txt Spyware:Cookie/360i Not disinfected C:\Documents and Settings\Zach\Cookies\zach@ct.360i[2].txt Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Zach\Cookies\zach@did-it[2].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/empnads Not disinfected C:\Documents and Settings\Zach\Cookies\zach@empnads[1].txt Spyware:Cookie/GoStats Not disinfected C:\Documents and Settings\Zach\Cookies\zach@gostats[2].txt Spyware:Cookie/Screensavers Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/Bettersearch Not disinfected C:\Documents and Settings\Zach\Cookies\zach@index[1].txt Spyware:Cookie/MediaTickets Not disinfected C:\Documents and Settings\Zach\Cookies\zach@kinghost[1].txt Spyware:Cookie/Kount Not disinfected C:\Documents and Settings\Zach\Cookies\zach@kount[2].txt Spyware:Cookie/LinkExchange Not disinfected C:\Documents and Settings\Zach\Cookies\zach@linkexchange[2].txt Spyware:Cookie/Mp3search Not disinfected C:\Documents and Settings\Zach\Cookies\zach@mp3search[4].txt Spyware:Cookie/OfferOptimizer Not disinfected C:\Documents and Settings\Zach\Cookies\zach@offeroptimizer[2].txt Spyware:Cookie/Mircx Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Rightmedia Not disinfected C:\Documents and Settings\Zach\Cookies\zach@rightmedia[1].txt Spyware:Cookie/Rn11 Not disinfected C:\Documents and Settings\Zach\Cookies\zach@rn11[1].txt Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/SpywareStormer Not disinfected C:\Documents and Settings\Zach\Cookies\zach@spywarestormer[1].txt Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Zach\Cookies\zach@target[2].txt Spyware:Cookie/TeensForCash Not disinfected C:\Documents and Settings\Zach\Cookies\zach@teensforcash[2].txt Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Zach\Cookies\zach@toplist[1].txt Spyware:Cookie/Tickle Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\Zach\Cookies\zach@webpower[1].txt Spyware:Cookie/WinFixer Not disinfected C:\Documents and Settings\Zach\Cookies\zach@winfixer[2].txt Spyware:Cookie/Maxifiles Not disinfected C:\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Mp3s Hits Not disinfected C:\Documents and Settings\Zach\Cookies\zach@www.mp3shits[2].txt Spyware:Cookie/Xiti Not disinfected C:\Documents and Settings\Zach\Cookies\zach@xiti[1].txt Spyware:Cookie/Xmts Not disinfected C:\Documents and Settings\Zach\Cookies\zach@xmts[2].txt Adware:Adware/MyDailyHoroscope Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\C1A25.tmp Adware:Adware/MyDailyHoroscope Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\C1A25.tmp[toolbar.exe] Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\i24.tmp Adware:Adware/IST.ISTBar Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\iinstall26710.exe Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\NI.UERS_0001_NI531020\setup.exe Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\rp1.tmp Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\rp2.tmp Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\rp3.tmp Spyware:Spyware/SurfSideKick Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\rp38.tmp Adware:Adware/TopRebates Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\webrebates.exe Adware:Adware/MediaTickets Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\xx.html Potentially unwanted tool:Application/Winfixer2005 Not disinfected C:\Documents and Settings\Zach\Local Settings\Temp\~ErrorSafeScannerSetup.exe Adware:Adware/Maxifiles Not disinfected C:\Program Files\DNS\cwebpage.dll Spyware:Spyware/LinkReplacer Not disinfected C:\Program Files\Jalmp\uninstall.exe Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Mozilla Firefox\plugins\NPMyWebS.dll Potentially unwanted tool:Application/FunWeb Not disinfected C:\WINDOWS\Downloaded Program Files\f3initialsetup1.0.0.15.inf Adware:Adware/Secure32 Not disinfected C:\WINDOWS\secure32.html Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\WINDOWS\system32\f3PSSavr.scr Adware:Adware/PurityScan Not disinfected C:\WINDOWS\system32\jbuj.dll Spyware:Cookie/Hbmediapro Not disinfected C:\WINDOWS\Temp\Cookies\[removed][2].txt Spyware:Cookie/Azjmp Not disinfected C:\WINDOWS\Temp\Cookies\louise@azjmp[2].txt Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Temp\Cookies\louise@belnk[1].txt Spyware:Cookie/Date Not disinfected C:\WINDOWS\Temp\Cookies\louise@date[1].txt Spyware:Cookie/Belnk Not disinfected C:\WINDOWS\Temp\Cookies\[removed][2].txt Spyware:Cookie/FortuneCity Not disinfected C:\WINDOWS\Temp\Cookies\louise@fortunecity[1].txt Spyware:Cookie/RealMedia Not disinfected C:\WINDOWS\Temp\Cookies\louise@realmedia[2].txt Adware:Adware/SaveNow Not disinfected E:\Downloads\3dEggs.exe[WUSVINST.EXE] Spyware:Cookie/RealMedia Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\i9ltn295.Default User\cookies.txt[] Spyware:Cookie/360i Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Application Data\Mozilla\Firefox\Profiles\q2vgcnmh.default\cookies.txt[] Spyware:Cookie/888 Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@888[1].txt Spyware:Cookie/888 Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@888[2].txt Spyware:Cookie/YieldManager Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/Hbmediapro Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/adultfriendfinder Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@adultfriendfinder[2].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][1].txt Spyware:Cookie/Azjmp Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@azjmp[2].txt Spyware:Cookie/Banner Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@banner[1].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@belnk[1].txt Spyware:Cookie/Cassava Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@cassava[1].txt Spyware:Cookie/Centralmedia Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@centralmedia[1].txt Spyware:Cookie/360i Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@ct.360i[1].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/Entrepreneur Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@entrepreneur[2].txt Spyware:Cookie/go Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@go[2].txt Spyware:Cookie/Screensavers Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/Kount Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@kount[2].txt Spyware:Cookie/Media-motor Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed]-motor[2].txt Spyware:Cookie/OfferOptimizer Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@offeroptimizer[1].txt Spyware:Cookie/Rightmedia Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@rightmedia[1].txt Spyware:Cookie/techtarget Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/Target Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@target[2].txt Spyware:Cookie/Toplist Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@toplist[1].txt Spyware:Cookie/Maxifiles Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\[removed][2].txt Spyware:Cookie/Xiti Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Cookies\louise@xiti[1].txt Adware:Adware/PurityScan Not disinfected G:\Fullbackup\C\Documents and Settings\Louise\Local Settings\Temp\!update.exe Spyware:Cookie/Hbmediapro Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Application Data\Mozilla\Firefox\Profiles\erwgu9s6.default\cookies.txt[] Adware:Adware/IST.ISTBar Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\javainstaller.jar-3c936701-234f78ce.zip[InstallerApplet.class] Spyware:Cookie/64.62.232 Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@64.62.232[4].txt Spyware:Cookie/888 Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@888[1].txt Spyware:Cookie/888 Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@888[2].txt Spyware:Cookie/Com.com Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Hbmediapro Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Gorillanation Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/adultfriendfinder Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@adultfriendfinder[1].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Azjmp Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@azjmp[2].txt Spyware:Cookie/Banner Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@banner[2].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@belnk[2].txt Spyware:Cookie/Barelylegal Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/GoStats Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/GoStats Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Cassava Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@cassava[1].txt Spyware:Cookie/Ccbill Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@ccbill[1].txt Spyware:Cookie/Centralmedia Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@centralmedia[1].txt Spyware:Cookie/360i Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@ct.360i[2].txt Spyware:Cookie/did-it Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@did-it[2].txt Spyware:Cookie/Belnk Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/empnads Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@empnads[1].txt Spyware:Cookie/GoStats Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@gostats[2].txt Spyware:Cookie/Screensavers Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/Com.com Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/Bettersearch Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@index[1].txt Spyware:Cookie/MediaTickets Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@kinghost[1].txt Spyware:Cookie/Kount Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@kount[2].txt Spyware:Cookie/LinkExchange Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@linkexchange[2].txt Spyware:Cookie/Mp3search Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@mp3search[4].txt Spyware:Cookie/OfferOptimizer Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@offeroptimizer[2].txt Spyware:Cookie/Mircx Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][1].txt Spyware:Cookie/Rightmedia Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@rightmedia[1].txt Spyware:Cookie/Rn11 Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@rn11[1].txt Spyware:Cookie/Searchportal Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\[removed][2].txt Spyware:Cookie/SpywareStormer Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@spywarestormer[1].txt Spyware:Cookie/Target Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@target[2].txt Spyware:Cookie/TeensForCash Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@teensforcash[2].txt Spyware:Cookie/Toplist Not disinfected G:\Fullbackup\C\Documents and Settings\Zach\Cookies\zach@toplist[1].txt
Please download Asquared from the link below.

http://www.emsisoft.com/en/software/download/

Safe it to your desktop. Next open and check for updates.

Boot to safe mode (tap f8 while bios loads)

Then scan your system (this will take some time) after the scan is compelte allow it to fix what it has found. If there is something that it can not clean please let me know what it was.

Then reboot and post a new hijackthis log.
I ran the asquared scan & it found & removed 45 objects. When I opened IE I got the winfixer popup! Doesn't happen often.
Here is the hjt log after the reboot.

Logfile of HijackThis v1.99.1
Scan saved at 7:21:40 PM, on 3/11/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\Program Files\RssReader\RssReader.exe
C:\Program Files\a-squared\a2guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\Dantz\RETROS~1\retrospect.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32Info.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program

Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program

files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator

5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter

Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art

Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat

7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital

Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital

Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program

files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program

files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program

files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program

files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel -

res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program

files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program

files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program

Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} -

C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program

Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} -

C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -

http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) -

http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -

http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -

http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) -

http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -

http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} -

http://cabs.elitemediagroup.net/cabs/mediaview.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. -

C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program

Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido

anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program

Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation -

C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development

Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation -

C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program

Files\Spyware Doctor\sdhelp.exe

Thanks for your help.
Download the trial version of trojan hunter from the link below. Update it scan your system and allow it to clean what it finds.

http://www.trojanhunter.com/

Let me know if it finds something it can not remove.

Then reboot and post a new hijackthis log please. Please make sure that in notepad that you choose format and make sure wordwrap is not checked before you post the nest log.
The TrojanHunter found 5 objects that it removed.

Here is a new hjt log after a reboot.

Logfile of HijackThis v1.99.1
Scan saved at 12:13:40 PM, on 3/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\msdtc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\HPZipm12.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\pctspk.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Java\jre1.5.0_02\bin\jucheck.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe
C:\WINDOWS\MXOALDR.EXE
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe
C:\Program Files\RssReader\RssReader.exe
C:\Program Files\a-squared\a2guard.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\WinZip\WZQKPICK.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Documents and Settings\Louise\My Documents\My Downloads\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.live.com/
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MaxtorOneTouch] C:\PROGRA~1\Maxtor\OneTouch\Utils\OneTouch.exe
O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\Dantz\RETROS~1\RetroExpress.exe /h
O4 - HKLM\..\Run: [MXOBG] C:\WINDOWS\MXOALDR.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Art Plus Wallpaper Calendar] "C:\Program Files\Art Plus\Wallpaper5\wallpaper.exe" /a
O4 - HKCU\..\Run: [RssReader] C:\Program Files\RssReader\RssReader.exe
O4 - HKCU\..\Run: [a-squared] "C:\Program Files\a-squared\a2guard.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZUxdm082YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .fpx: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O12 - Plugin for .ivr: C:\\Program Files\\Internet Explorer\\PLUGINS\\NPRVRT32.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/downloads/kws/kav…can_unicode.cab
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} (ewidoOnlineScan Control) - http://download.ewido.net/ewidoOnlineScan.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-36.cab
O16 - DPF: {8A0019EB-51FA-4AE5-A40B-C0496BBFC739} (Verizon Wireless Media Upload) - http://www.vzwpix.com/activex/VerizonWirel…loadControl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {9AC54695-69A4-46F1-BE10-10C74F9520D5} - http://cabs.elitemediagroup.net/cabs/mediaview.cab
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - Unknown owner - C:\WINDOWS\system32\pctspk.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Retrospect Express HD Restore Helper (RetroExp Helper) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\rthlpsvc.exe
O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - Dantz Development Corporation - C:\PROGRA~1\Dantz\RETROS~1\retrorun.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe

Thanks for your help.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI