Thanks for helping me out…. Below are the 3 different application. After goging through your recommendation.
HijackThis
***********************************************
Logfile of HijackThis v1.99.1
Scan saved at 10:26:41 PM, on 7/27/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\Common Files\Virtual Token\vtserver.exe
C:\WINDOWS\System32\ibmpmsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\Mcshield.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\WINDOWS\System32\QCONSVC.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\TpKmpSVC.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe
C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
C:\IBMTOOLS\UTILS\ibmprc.exe
C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
C:\WINDOWS\system32\RunDll32.exe
C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
C:\Program Files\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
C:\Program Files\Yahoo!\Yahoo! Desktop Search\YahooDesktopSearch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\mozila_firefox\firefox.exe
C:\Program Files\EditPlus 2\editplus.exe
C:\Downloads\HijackThis.exe
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [TPKMAPHELPER] C:\Program Files\ThinkPad\Utilities\TpKmapAp.exe -helper
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [ControlCenter] "C:\Program Files\IBM fingerprint software\ctlcntr.exe" /startup
O4 - HKLM\..\Run: [EZEJMNAP] C:\PROGRA~1\ThinkPad\UTILIT~1\EzEjMnAp.Exe
O4 - HKLM\..\Run: [UC_Start] C:\Program Files\IBM\Updater\\ucstartup.exe
O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe
O4 - HKLM\..\Run: [QCTRAY] C:\Program Files\ThinkPad\ConnectUtilities\QCTRAY.EXE
O4 - HKLM\..\Run: [QCWLICON] C:\Program Files\ThinkPad\ConnectUtilities\QCWLICON.EXE
O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor
O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE
O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor
O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
O4 - Startup: Yahoo! Desktop Search System Tray.lnk = C:\Program Files\Yahoo!\Yahoo! Desktop Search\YDSsystray.exe
O4 - Startup: Yahoo! Desktop Search.lnk = C:\Program Files\Yahoo!\Yahoo! Desktop Search\YahooDesktopSearch.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Edit with Altova X&MLSpy - C:\Program Files\Altova\XMLSpy2006\spy.htm
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_07\bin\npjpi150_07.dll
O9 - Extra button: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O9 - Extra 'Tools' menuitem: Edit with Altova X&MLSpy - {2222EF56-F49E-4d07-A14E-8D2B08766958} - C:\Program Files\Altova\XMLSpy2006\spy.htm
O11 - Options group: [JAVA_IBM] Java (IBM)
O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) -
http://admnotes.odu.edu/iNotes6W.cab
O20 - Winlogon Notify: MediaContentIndex - C:\WINDOWS\system32\enn8l15u1.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Apache - Unknown owner - C:\servers\Apache\Apache.exe" –ntservice (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe
O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Network Monitor - Unknown owner - C:\Program Files\Network Monitor\netmon.exe (file missing)
O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing)
O23 - Service: QCONSVC - IBM Corp. - C:\WINDOWS\System32\QCONSVC.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\system32\S24EvMon.exe
O23 - Service: IBM KCU Service (TpKmpSVC) - Unknown owner - C:\WINDOWS\system32\TpKmpSVC.exe
O23 - Service: Protector Suite Virtual Token (vtserver) - UPEK Inc. - C:\Program Files\Common Files\Virtual Token\vtserver.exe
************************************************************
Ewido logs after clean. it takes almost an hour for me to run the complete scan
***********************************************************************
———————————————————
ewido anti-spyware - Scan Report
———————————————————
+ Created at: 10:08:11 PM 7/27/2006
+ Scan result:
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP235\A0065914.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP235\A0065923.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP236\A0065969.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP236\A0066220.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP237\A0066248.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP237\A0066249.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066253.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066254.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066312.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066321.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066325.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066332.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066345.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066351.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066371.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066521.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066522.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP239\A0066550.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP239\A0066551.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066581.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066582.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066737.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066738.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066754.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066755.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066778.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066779.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066799.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066800.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066816.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066817.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066838.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP241\A0066839.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0066998.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067000.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067017.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067018.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067035.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067036.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067052.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067053.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067069.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067073.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067078.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067082.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067094.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067100.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067112.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067120.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP243\A0067127.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP245\A0067149.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP245\A0067164.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP245\A0067168.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP245\A0067172.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP245\A0067186.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP246\A0067208.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP246\A0067226.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP246\A0067235.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP246\A0067239.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP253\A0067589.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP253\A0067593.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP254\A0067668.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP254\A0067679.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP254\A0067710.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP254\A0068713.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068782.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068791.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068809.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068826.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068841.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP257\A0068853.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068879.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068894.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068898.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068904.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068929.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068933.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068937.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068950.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0068957.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP258\A0069972.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP260\A0071972.DLL -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP261\A0071988.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP261\A0072004.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP261\A0074001.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP262\A0075028.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\aorsvc.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cofview.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\cwusapi.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\doactfrm.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\f0l0la3m1d.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\fpn2035oe.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\irl0l53m1.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\jrsh400.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kfdir.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kkduzb.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\kzdpl.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\l48m0el1ehq.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ldkrn13n.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\lv0o09d3e.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mkisip.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\notlogon.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\WINDOWS\system32\seell32.dll -> Adware.Look2Me : Cleaned with backup (quarantined).
[644] C:\WINDOWS\system32\srclogon.dll -> Adware.Look2Me : Error during cleaning.
[736] C:\WINDOWS\system32\srclogon.dll -> Adware.Look2Me : Error during cleaning.
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP233\A0065331.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP233\A0065332.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP234\A0065357.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP234\A0065358.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066730.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Downloads\backups\backup-20060701-092718-979.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\Downloads\backups\backup-20060701-093019-304.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066341.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP238\A0066348.dll -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\gbe90qs.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ssn6tuu.exe -> Adware.Suggestor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP234\A0065359.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066722.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\dwdsregt.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\mwinqqez.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\system32\ppdsregk.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066728.exe -> Backdoor.VB.ary : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066723.exe -> Downloader.Agent.ala : Cleaned with backup (quarantined).
C:\Downloads\FMWorld_Radio\xmlspy\xmlspycrack\altovaxmlspy2004enterprisekeygencore.rar/install.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP232\A0065182.exe -> Downloader.Small.bwy : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win73F.tmp.exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
C:\Downloads\FMWorld_Radio\xmlspy\xmlspycrack\altovaxmlspy2004enterprisekeygencore.rar/crack.exe -> Downloader.VB.afo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP240\A0066727.exe -> Downloader.VB.afv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP262\A0075034.exe -> Downloader.Zlob.to : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP262\A0075035.exe -> Downloader.Zlob.xp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP254\A0067706.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP262\A0075038.dll -> Not-A-Virus.Hoax.Win32.Renos.dw : Cleaned with backup (quarantined).
:mozilla.29:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.30:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.31:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.32:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\mchokshi@americanexpress.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\mchokshi@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined).
:mozilla.28:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup (quarantined).
:mozilla.66:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned with backup (quarantined).
:mozilla.67:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\mchokshi@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined).
:mozilla.24:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined).
:mozilla.27:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup (quarantined).
:mozilla.58:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\mchokshi@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup (quarantined).
:mozilla.25:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned with backup (quarantined).
:mozilla.33:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.34:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned with backup (quarantined).
:mozilla.62:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
:mozilla.63:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined).
:mozilla.51:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.52:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.53:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.54:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.55:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\mchokshi@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined).
:mozilla.73:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.74:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.75:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined).
:mozilla.15:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.16:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.17:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.18:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
C:\Documents and Settings\mchokshi\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined).
:mozilla.10:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.11:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.12:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.13:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
:mozilla.14:C:\Documents and Settings\mchokshi\Application Data\Mozilla\Firefox\Profiles\n1cxojwo.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068804.dll -> Trojan.Mezzia : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{DAAD8284-5896-4B40-A753-8454BDC2E5A5}\RP256\A0068808.dll -> Trojan.Mezzia : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win5D6.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win743.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win764.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\win767.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\winC8A.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\Temp\winC99.tmp.exe -> Trojan.Pakes : Cleaned with backup (quarantined).
C:\WINDOWS\system32\nr1rnqm8.exe -> Trojan.Runner.j : Cleaned with backup (quarantined).
::Report end
**********************************************************
Rapport.txt
*******************************************************
SmitFraudFix v2.76
Scan done at 21:03:34.21, Thu 07/27/2006
Run from C:\Downloads\hijackthis_help\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode
»»»»»»»»»»»»»»»»»»»»»»»» Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» Killing process
»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix
GenericRenosFix by S!Ri
»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files
»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files
»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning
Registry Cleaning done.
»»»»»»»»»»»»»»»»»»»»»»»» After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!
SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll
»»»»»»»»»»»»»»»»»»»»»»»» End
****************************************************8
Unfortunately, The pop ups are still annoying and coming in the firefox too.