Ok, sorry for the delay.
I ran Vundo - nothing found
Safe Mode:
ran ewido -
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 2:21:32 PM, 4/18/2006
+ Report-Checksum: A3B1223F
+ Scan result:
C:\Documents and Settings\admin\Cookies\anyuser@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\admin\Cookies\anyuser@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\admin\Cookies\anyuser@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned with backup
C:\Documents and Settings\admin\Cookies\anyuser@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@ads.x10[1].txt -> TrackingCookie.X10 : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@ads.x10[3].txt -> TrackingCookie.X10 : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@advertising[1].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@bfast[2].txt -> TrackingCookie.Bfast : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@bis.180solutions[1].txt -> TrackingCookie.180solutions : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@centrport[1].txt -> TrackingCookie.Centrport : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@commission-junction[1].txt -> TrackingCookie.Commission-junction : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@gm.preferences[1].txt -> TrackingCookie.Preferences : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@preferences[1].txt -> TrackingCookie.Preferences : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@servedby.advertising[2].txt -> TrackingCookie.Advertising : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\admin\Cookies\techuser01@zedo[3].txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.7:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup
:mozilla.112:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.113:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Qksrv : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.160:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.161:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.170:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.171:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Adserver : Cleaned with backup
:mozilla.172:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.173:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.174:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.187:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.188:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.189:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.190:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.191:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.192:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.193:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup
:mozilla.201:C:\Documents and Settings\Michael\Application Data\Mozilla\Profiles\default\4wa2ej9k.slt\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
C:\Documents and Settings\Michael\Cookies\michael@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned with backup
C:\Documents and Settings\Michael\Cookies\michael@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned with backup
C:\Documents and Settings\Michael\Cookies\michael@vdn.valuead[2].txt -> TrackingCookie.Valuead : Cleaned with backup
C:\Documents and Settings\Michael\Desktop\hjt\backups\backup-20060404-090310-274.dll -> Adware.MediaTickets : Cleaned with backup
C:\WINDOWS\SYSTEM32\ld1ACA.tmp -> Downloader.Zlob.jt : Cleaned with backup
C:\WINDOWS\SYSTEM32\oins.exe -> Downloader.PurityScan.bt : Cleaned with backup
::Report End
Ran HJT -
Logfile of HijackThis v1.99.1
Scan saved at 2:27:00 PM, on 4/18/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Michael\Desktop\hjt\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://search.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\windows\SYSTEM\blank.htm
O1 - Hosts: 216.19.0.250 idenupdate.motorola.com
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA8C3DA7-38E7-4453-A021-54CA1F232F0F}: Domain = GMADOM05754
O17 - HKLM\System\CCS\Services\Tcpip\..\{FA8C3DA7-38E7-4453-A021-54CA1F232F0F}: NameServer = 10.205.1.100,10.205.1.200
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\system32\ZoneLabs\isafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido anti-malware\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
Cleared prefetch and temp files
The original issue has been gone for a while but I'm hoping that nothing remains.
Do the logs look OK?