This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojans/malware/popups

27 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there, I've tried Adaware, Spy-bot and AVG antivirus and there's still something on my computer. I constantly get these popups at no request of my own. Unfortunately I did this to myslef by downloading a crack for WGA workaround. It had a patch.exe and installed this carp** on my computer that I cannot get off now. Here's my Hijack file. Thanks in advance for your help.

Logfile of HijackThis v1.99.1
Scan saved at 12:04:48 AM, on 2006-09-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Quick Lookup\QuickLookup.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\Common Files\AOL\1152926156\ee\AOLSoftware.exe
C:\program files\popupwithcast\septpop06apsept.exe
C:\kybrdff_e12.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\dfndrff_e12.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Azureus\Azureus.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Documents and Settings\Jonin\My Documents\Downloads\Torrents\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickLookup] C:\Program Files\Quick Lookup\QuickLookup.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1152926156\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [septpop06apsept] C:\program files\popupwithcast\septpop06apsept.exe
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e11.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e11.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Device Detector 3.lnk = C:\Program Files\Olympus\DeviceDetector\DevDtct2.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jonin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1140390121453
O16 - DPF: {754693AA-011F-40DD-B075-DD4644A47F54} (Importer.Imp) - http://www.imvu.com/catalog/invite/Importer.CAB
O16 - DPF: {958FCAB0-616B-11D3-A63F-00001B322780} (TimetickerLittleHelpers.usfServer) - http://www.timeticker.com/Timeset/TcpServer.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: WindowsUpdate - C:\WINDOWS\system32\hr0q05d5e.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Windows Event (WinEvent) - Unknown owner - C:\WINDOWS\winevent.exe (file missing)
Hi,

Welcome to TomCoyote Forums! Please follow these instructions exactly and in the order given.

• HijackThis is running from a Temp folder. The contents of a Temp folder periodically get deleted. Since HijackThis creates backups each time it fixes an entry, the program along with the backups are subject to being deleted. You will have to move it to a permanent folder.
Rather than create a new folder and move it, just download the current version from here and save it to a convenient location. This is a self-executing file, so just double-click the file and it will install itself in its own folder in Program Files. Use this version from now on. The other one will be deleted during the steps we will take.

• Please disable Ad-Watch as it may hinder the removal of some entries. You can re-enable it after your computer is clean.
To disable Ad-Watch:
1. Right click on the Ad-Watch icon in the system tray and select "Restore Ad-Watch".
2. At the bottom of the screen there will be two checkable items called "Active" and "Automatic".Active: Switches Monitoring On or Off without closing
Automatic: Switches Automatic Blocking On or Off
3. Uncheck (red X) both items.

Remember, when we have completed cleaning your machine, to turn Ad-Watch back on using the same steps - but select ONLY Active. Ad-Watch will prompt you to accept those registry changes that were made in the cleanup. They must be accepted.

• Now download Look2Me-Destroyer.exe to your desktop.

- Close all windows before continuing.
- Double-click Look2Me-Destroyer.exe to run it.
- Put a check next to Run this program as a task.
- You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 minute. Click OK
- When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
- Once it's done scanning, click the Remove L2M button.
- You will receive a Done Scanning message, click OK.
- When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
- Your computer will then shutdown.
- Turn your computer back on.

If you receive a message from your firewall about this program accessing the internet please allow it.

If you receive a runtime error '339' please download MSWINSCK.OCX from the link below and place it in your C:\Windows\System32 Directory.
http://www.ascentive.com/support/new/images/lib/MSWINSCK.OCX

• Please post the contents of Look2Me-Destroyer.txt and a new HiJackThis log.
Ok. Done. Here's the 2 log files

Look2Me-Destroyer:


Look2Me-Destroyer V1.0.12

Scanning for infected files…..
Scan started at 9/24/2006 7:19:02 PM

Infected! C:\WINDOWS\system32\agtiveds.dll
Infected! C:\WINDOWS\system32\caypt32.dll
Infected! C:\WINDOWS\system32\m4nqle551h.dll
Infected! C:\WINDOWS\system32\npwks.dll
Infected! C:\WINDOWS\system32\s6rslg9716.dll
Infected! C:\WINDOWS\system32\SITraRU.dll

Attempting to delete infected files…

Attempting to delete: C:\WINDOWS\system32\agtiveds.dll
C:\WINDOWS\system32\agtiveds.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\caypt32.dll
C:\WINDOWS\system32\caypt32.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\m4nqle551h.dll
C:\WINDOWS\system32\m4nqle551h.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\npwks.dll
C:\WINDOWS\system32\npwks.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\s6rslg9716.dll
C:\WINDOWS\system32\s6rslg9716.dll Deleted successfully!

Attempting to delete: C:\WINDOWS\system32\SITraRU.dll
C:\WINDOWS\system32\SITraRU.dll Deleted successfully!

Making registry repairs.


Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{575A2DFB-7E64-4340-8D8F-F3A7C99ADFCB}"
HKCR\Clsid\{575A2DFB-7E64-4340-8D8F-F3A7C99ADFCB}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{E3A36358-5118-4511-A39D-EC3E36418B6C}"
HKCR\Clsid\{E3A36358-5118-4511-A39D-EC3E36418B6C}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{9B2FC64B-2637-4250-B518-DF24BE44D9A3}"
HKCR\Clsid\{9B2FC64B-2637-4250-B518-DF24BE44D9A3}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{826263D3-16BE-4AEA-8B8D-195A591E0BD7}"
HKCR\Clsid\{826263D3-16BE-4AEA-8B8D-195A591E0BD7}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{DCFC2ABD-2ADC-44F3-9C63-22F560A409B5}"
HKCR\Clsid\{DCFC2ABD-2ADC-44F3-9C63-22F560A409B5}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A77B4CAD-EF2C-4A02-9961-CF46B3E553C8}"
HKCR\Clsid\{A77B4CAD-EF2C-4A02-9961-CF46B3E553C8}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{084A7EAE-2971-488F-A5C1-16432B5B05D5}"
HKCR\Clsid\{084A7EAE-2971-488F-A5C1-16432B5B05D5}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 7:34:35 PM, on 2006-09-24
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\PROGRA~1\MICROS~4\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.findthewebsiteyouneed.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.findthewebsiteyouneed.com
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
R3 - URLSearchHook: (no name) - {A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - C:\Program Files\DeluxeCommunications\DxcBho.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DeskbarBHO - {A8B28872-3324-4CD2-8AA3-7D555C872D96} - C:\Program Files\Deskbar\deskbar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [DeluxeCommunications] C:\Program Files\DeluxeCommunications\Dxc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Update Manager] "C:\Program Files\Rogers\Update Manager\UpdateManager.exe" /background
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jonin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.media-motor.net
O15 - Trusted Zone: *.mmohsix.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) - http://us.dl1.yimg.com/download.yahoo.com/…ntr_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1140390121453
O16 - DPF: {754693AA-011F-40DD-B075-DD4644A47F54} (Importer.Imp) - http://www.imvu.com/catalog/invite/Importer.CAB
O16 - DPF: {958FCAB0-616B-11D3-A63F-00001B322780} (TimetickerLittleHelpers.usfServer) - http://www.timeticker.com/Timeset/TcpServer.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - AppInit_DLLs: dxclib303562752.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Windows Event (WinEvent) - Unknown owner - C:\WINDOWS\winevent.exe (file missing)
Hi,

• Go to Start > Run and copy/paste: sc delete Windows Event - click OK
Again, go to Start > Run and copy/paste: sc delete WinEvent - click OK

• Start HijackThis, click System Scan Only and place a checkmark next to the following items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://searchbar.findthewebsiteyouneed.com
O23 - Service: Windows Event (WinEvent) - Unknown owner - C:\WINDOWS\winevent.exe (file missing)


Close ALL browsers and open windows/programs except HijackThis and click 'Fix Checked'. Then exit HijackThis.

Reboot your computer.

• Please download, install, and update ewido anti-spyware.
  • Load Ewido and then click the Update tab at the top. Under Manual Update click Start update.
  • After the update finishes (the status bar at the bottom will display "Update successful")
  • Then click on the Scanner tab at the top. Click the "Settings" tab and then change the recommended action to Quarantine and click Automatically generate report after every scan
  • Click back to the "Scan" tab and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
  • Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
  • Click on Save Report-, then "Save Report As". This will create a text file. Make sure you know where to find this file again (like on the Desktop).
  • Close Ewido and reboot!!
• Post back with the results of the ewido scan and a new HijackThis log. Also, let me know how your computer is running now.
Wel… what can I do now? I've tried running Ewido twice, the first time i finished the scan and then continued to Apply all actions which it did until it reached one of the listings and then said Error… unfortunately the program at that point froze and I had to end the program which didn't allow me to save a report. Then the second time I ran it in Safe mode where it finished the scan and I proceeded to Apply all actions and then it said done after the first listing and froze again where I had to end the program and could not generate a report either. Please advise. Thank you in advance. Oh yeah, the first time I ran it popups came up while it was scanning…
• Please download Combofix: http://download.bleepingcomputer.com/sUBs/combofix.exe
and save to the desktop.

1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new hijackthis log.

Notes:
* Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
* Do not proceed with the rest of the fix if you fail to run combofix
* Disable script blocking if you have NAV installed so it will not interfere with the fix. Trojan Hunter has been reported to detect combofix as Worm.Qiv.100

• Post back with the combofix.txt log and a new HijackThis log.
So while I'm doing the above, I just wanted to let you know that I booted in safe mode and ran a memory scan, registry scan and fast scan and included the logs below: ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 8:32:56 PM 2006-09-27 + Scan result: [288] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [340] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [352] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [512] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [576] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [748] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [784] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). ::Report end ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 8:33:48 PM 2006-09-27 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKLM\SOFTWARE\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKLM\SOFTWARE\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\.DEFAULT\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\.DEFAULT\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-18\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-18\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-21-746137067-1547161642-725345543-1003\Software\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-21-746137067-1547161642-725345543-1003\Software\DeluxeCommunications\Internet Explorer -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-21-746137067-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). ::Report end ——————————————————— ewido anti-spyware - Scan Report ——————————————————— + Created at: 8:42:54 PM 2006-09-27 + Scan result: HKLM\SOFTWARE\Classes\CLSID\{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). HKU\S-1-5-21-746137067-1547161642-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Run\\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined). C:\WINDOWS\Temp\TMP14.tmp\drsmartload106a.exe -> Adware.DollarRevenue : Cleaned with backup (quarantined). C:\WINDOWS\Temp\TMP14.tmp\mmxateam.exe -> Adware.DollarRevenue : Cleaned with backup (quarantined). C:\WINDOWS\Temp\TMP4.tmp\mmxateam.exe -> Adware.DollarRevenue : Cleaned with backup (quarantined). C:\WINDOWS\Temp\TMP5.tmp\mmxateam.exe -> Adware.DollarRevenue : Cleaned with backup (quarantined). C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [288] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [340] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [352] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [512] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [576] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [748] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). [784] C:\WINDOWS\system32\dxclib303562752.dll -> Adware.SurfSide : Cleaned with backup (quarantined). :mozilla.6:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.7:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned with backup (quarantined). :mozilla.10:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.11:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.12:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.13:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.14:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.15:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.16:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.17:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.18:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.19:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.20:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.21:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.22:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.23:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.24:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.25:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.26:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.27:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.281:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.28:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.29:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.31:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.32:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.33:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.34:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.35:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.36:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.37:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.383:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.38:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.39:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.40:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.417:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.41:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.42:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.43:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.44:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.45:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.46:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.47:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.48:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.49:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.50:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.51:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.52:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.53:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.54:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.55:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.56:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.8:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.9:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@chumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@supportsoft.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup (quarantined). :mozilla.637:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.638:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.86:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.87:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.88:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.89:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.90:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.91:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.92:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.93:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.94:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned with backup (quarantined). :mozilla.103:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned with backup (quarantined). :mozilla.100:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). :mozilla.101:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). :mozilla.102:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). :mozilla.98:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). :mozilla.99:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][1].txt -> TrackingCookie.Adorigin : Cleaned with backup (quarantined). :mozilla.104:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.105:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Adtech : Cleaned with backup (quarantined). :mozilla.660:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.661:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.662:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned with backup (quarantined). :mozilla.162:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.163:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned with backup (quarantined). :mozilla.175:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned with backup (quarantined). :mozilla.606:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.607:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup (quarantined). :mozilla.176:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.177:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.178:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.179:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.180:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.181:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.702:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup (quarantined). :mozilla.187:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.188:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.189:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.190:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup (quarantined). :mozilla.283:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Epilot : Cleaned with backup (quarantined). :mozilla.781:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Epilot : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned with backup (quarantined). :mozilla.266:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned with backup (quarantined). :mozilla.96:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup (quarantined). :mozilla.134:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.135:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.136:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.137:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.138:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.139:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup (quarantined). :mozilla.287:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup (quarantined). :mozilla.655:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.656:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup (quarantined). :mozilla.784:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined). :mozilla.785:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned with backup (quarantined). :mozilla.706:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.707:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.708:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned with backup (quarantined). :mozilla.686:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned with backup (quarantined). :mozilla.415:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.416:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.436:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned with backup (quarantined). :mozilla.423:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined). :mozilla.424:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned with backup (quarantined). :mozilla.717:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.718:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.719:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.720:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup (quarantined). :mozilla.478:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Revenue : Cleaned with backup (quarantined). :mozilla.495:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.496:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.497:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.498:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.499:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup (quarantined). :mozilla.191:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.192:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.193:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.194:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.195:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.196:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.197:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.198:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.199:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.200:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.201:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.202:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.203:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.204:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.205:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.206:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.207:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.208:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.209:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.210:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.211:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.212:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.213:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.214:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.215:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.216:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.217:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.218:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.219:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.220:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.221:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.222:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.223:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.224:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.225:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.226:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.227:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.228:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.229:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.230:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.231:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.232:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.233:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.234:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.235:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.236:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.237:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). :mozilla.238:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned with backup (quarantined). :mozilla.512:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Spylog : Cleaned with backup (quarantined). :mozilla.514:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.515:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.516:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.517:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.518:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.519:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.520:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.521:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.522:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.523:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.524:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.525:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.526:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.527:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.528:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.529:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.530:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.531:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.532:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.533:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.534:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.535:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.536:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.537:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.538:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.539:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.540:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.541:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.542:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.543:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.544:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.545:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.546:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.547:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.548:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.549:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.550:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.551:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.552:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.553:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.554:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.555:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.556:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.557:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.558:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup (quarantined). :mozilla.563:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.564:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.565:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). C:\Documents and Settings\Jonin\Cookies\jonin@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup (quarantined). :mozilla.593:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup (quarantined). :mozilla.594:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.595:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup (quarantined). :mozilla.597:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.598:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup (quarantined). :mozilla.439:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.440:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.441:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.442:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.469:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.470:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.471:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.472:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.473:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup (quarantined). :mozilla.621:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). :mozilla.622:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yadro : Cleaned with backup (quarantined). :mozilla.639:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.640:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.641:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.642:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.643:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.644:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.80:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.81:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.82:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.83:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup (quarantined). :mozilla.84:C:\Documents and Settings\Jonin\Application Data\Mozilla\Firefox\Profiles\9w6jlwlm.default\cookies.txt -> TrackingCookie.Yiel
• Please download Combofix: http://download.bleepingcomputer.com/sUBs/combofix.exe
and save to the desktop.

1. Double click on combo.exe & follow the prompts.
2. When finished, it will produce a logfile located at C:\ComboFix.txt.
3. Post the contents of that log in your next reply with a new hijackthis log.

Notes:
* Do not mouseclick combofix's window while it is running. That may cause your system to stall/hang.
* Do not proceed with the rest of the fix if you fail to run combofix
* Disable script blocking if you have NAV installed so it will not interfere with the fix. Trojan Hunter has been reported to detect combofix as Worm.Qiv.100

• Post back with the combofix.txt log and a new HijackThis log.
Here's the Combofix log:

Jonin - 06-09-28 19:51:27.67 Service Pack 2
ComboFix 06.09.28 - Running from: "C:\Documents and Settings\Jonin"

((((((((((((((((((((((((((((((( Files Created from 2006-08-28 to 2006-09-28 ))))))))))))))))))))))))))))))))))


2006-09-24 13:56 65,536 –a—— C:\WINDOWS\system32\YCRWin32.dll
2006-09-22 21:30 1,233 –a—— C:\WINDOWS\system32\lfoc9b2b.sys
2006-09-22 19:00 268,581 –a—— C:\WINDOWS\popupwithcast.exe
2006-09-22 19:00 0 –a—— C:\aumco.exe
2006-09-09 16:59 76,560 –a—— C:\WINDOWS\system32\drivers\tmcomm.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-09-28 19:50 ——– d——– C:\Program Files\Mozilla Firefox
2006-09-28 19:40 ——– d——– C:\Program Files\Common Files
2006-09-28 19:16 ——– d——– C:\Program Files\ewido anti-spyware 4.0
2006-09-28 06:35 ——– d——– C:\Program Files\Microsoft IntelliType Pro
2006-09-26 20:16 ——– d——– C:\Program Files\Windows Media Player
2006-09-26 20:16 ——– d——– C:\Program Files\Messenger
2006-09-25 04:53 ——– d——– C:\Documents and Settings\Jonin\Application Data\Azureus
2006-09-24 21:53 ——– d——– C:\Program Files\eMule
2006-09-24 17:43 ——– d——– C:\Program Files\Yahoo!
2006-09-24 15:05 ——– d——– C:\Program Files\Rogers
2006-09-23 01:08 ——– d——– C:\Documents and Settings\Jonin\Application Data\IMVU
2006-09-22 22:18 ——– d——– C:\Program Files\MSN
2006-09-22 19:01 0 –a—— C:\Program Files\swxf.exe
2006-09-22 19:01 0 –a—— C:\Program Files\secure32.html
2006-09-21 23:29 ——– d——– C:\Program Files\MSN Messenger
2006-09-21 19:25 ——– d——– C:\Program Files\IMVU
2006-09-13 23:03 ——– d——– C:\Program Files\Common Files\Symantec Shared
2006-09-13 23:01 ——– d——– C:\Program Files\Common Files\Scanner
2006-09-12 23:11 ——– d——– C:\Program Files\Alwil Software
2006-09-12 18:10 ——– d——– C:\Documents and Settings\Jonin\Application Data\Canon
2006-09-10 13:43 ——– d——– C:\Program Files\Azureus
2006-09-09 16:09 ——– d——– C:\Program Files\Symantec
2006-09-09 16:06 ——– d——– C:\Program Files\Norton SystemWorks
2006-08-28 19:36 ——– d——– C:\Program Files\Winamp
2006-08-27 13:40 ——– d——– C:\Program Files\Common Files\NSV
2006-08-27 13:37 ——– d——– C:\Program Files\Adobe
2006-08-21 22:28 ——– d——– C:\Program Files\Common Files\Adobe
2006-08-21 22:25 ——– d–h—– C:\Program Files\InstallShield Installation Information
2006-08-21 08:21 16896 –a—— C:\WINDOWS\system32\fltlib.dll
2006-08-21 05:14 23040 –a—— C:\WINDOWS\system32\fltmc.exe
2006-08-21 05:14 128896 ——— C:\WINDOWS\system32\drivers\fltmgr.sys
2006-08-21 01:09 ——– d——– C:\Program Files\Motherboard Monitor 5
2006-08-17 22:21 ——– d——– C:\Documents and Settings\Jonin\Application Data\Opera
2006-08-14 20:52 78848 –a—— C:\WINDOWS\system32\nsw20.dll
2006-08-13 13:08 ——– d——– C:\Documents and Settings\Jonin\Application Data\Adobe
2006-08-13 12:43 ——– d——– C:\Program Files\MagicDisc
2006-08-11 22:13 ——– d——– C:\Program Files\Internet Explorer
2006-08-07 18:32 ——– d—s—- C:\Documents and Settings\Jonin\Application Data\Microsoft
2006-07-30 01:56 ——– d——– C:\Program Files\FreshDevices
2006-07-29 19:32 48936 –a—— C:\WINDOWS\system32\sirenacm.dll
2006-07-27 09:24 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-07-21 04:24 72704 –a—— C:\WINDOWS\system32\hlink.dll
2006-07-09 00:17 1024 –a—— C:\Documents and Settings\Jonin\Application Data\WavCodec.wff


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickLookup"="C:\\Program Files\\Quick Lookup\\QuickLookup.exe"
"POINTER"="point32.exe"
"itype"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"!ewido"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"nForce Tray Options"="sstray.exe /r"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000001

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e2,03,\
00,00,04,00,00,c0
"RestoredStateInfo"=hex:18,00,00,00,4b,00,00,00,00,00,00,00,b5,04,00,00,e2,03,\
00,00,01,00,00,00

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]
"RunNarrator"=""

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Runonce]
"RunNarrator"=""

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="ewido anti-spyware 4.0"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
"{B84CCA60-06C2-4105-0329-040307230001}"="\"C:\\Program Files\\Common Files\\{B84CCA60-06C2-4105-0329-040307230001}\\Update.exe\" mc-110-12-0000169"

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
"{B84CCA60-06C2-4105-0329-040307230001}"="\"C:\\Program Files\\Common Files\\{B84CCA60-06C2-4105-0329-040307230001}\\Update.exe\" mc-110-12-0000169"

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Adobe Reader Speed Launch.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Reader Speed Launch.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Adobe\\ACROBA~1.0\\Reader\\READER~1.EXE "
"item"="Adobe Reader Speed Launch"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Device Detector 3.lnk]
"path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Device Detector 3.lnk"
"backup"="C:\\WINDOWS\\pss\\Device Detector 3.lnkCommon Startup"
"location"="Common Startup"
"command"="C:\\PROGRA~1\\Olympus\\DEVICE~1\\DevDtct2.exe "
"item"="Device Detector 3"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupfolder\C:^Documents and Settings^Jonin^Start Menu^Programs^Startup^Adobe Gamma.lnk]
"path"="C:\\Documents and Settings\\Jonin\\Start Menu\\Programs\\Startup\\Adobe Gamma.lnk"
"backup"="C:\\WINDOWS\\pss\\Adobe Gamma.lnkStartup"
"location"="Startup"
"command"="C:\\PROGRA~1\\COMMON~1\\Adobe\\CALIBR~1\\ADOBEG~1.EXE "
"item"="Adobe Gamma"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\!ewido]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ewido"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\ewido anti-spyware 4.0\\ewido.exe\" /minimized"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Acrobat Assistant 7.0]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Acrotray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Aim6]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\AVG7_CC]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="avgcc"
"hkey"="HKLM"
"command"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NMBgMonitor"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Common Files\\Ahead\\lib\\NMBgMonitor.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\ctfmon.exe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ctfmon"
"hkey"="HKCU"
"command"="C:\\WINDOWS\\system32\\ctfmon.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\defender]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dfndrff_e15"
"hkey"="HKLM"
"command"="c:\\\\dfndrff_e15.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\DeluxeCommunications]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Dxc"
"hkey"="HKLM"
"command"="C:\\Program Files\\DeluxeCommunications\\Dxc.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HostManager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="AOLSoftware"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\1152926156\\ee\\AOLSoftware.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\HPDJ Taskbar Utility]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="hpztsb04"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\IPHSend]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="IPHSend"
"hkey"="HKLM"
"command"="C:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\iTunesHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="iTunesHelper"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\itype]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="itype"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Microsoft IntelliType Pro\\itype.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\keyboard]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="kybrdff_e11"
"hkey"="HKLM"
"command"="C:\\\\kybrdff_e11.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\newname]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwnmff_e11"
"hkey"="HKLM"
"command"="C:\\\\nwnmff_e11.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\NWEReboot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKLM"
"command"=""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Omnipage]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="opware32"
"hkey"="HKLM"
"command"="C:\\Program Files\\ScanSoft\\OmniPageSE\\opware32.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\POINTER]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="point32"
"hkey"="HKLM"
"command"="point32.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickLookup]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="QuickLookup"
"hkey"="HKLM"
"command"="C:\\Program Files\\Quick Lookup\\QuickLookup.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\QuickTime Task]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="qttask"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\septpop06apsept]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="septpop06apsept"
"hkey"="HKLM"
"command"="C:\\program files\\popupwithcast\\septpop06apsept.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\TkBellExe]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="realsched"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\Update Manager]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdateManager"
"hkey"="HKCU"
"command"="\"C:\\Program Files\\Rogers\\Update Manager\\UpdateManager.exe\" /background"
"inimapping"="0"


HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders
securityproviders REG_SZ msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll


Completion time: 2006-09-28 19:52:21.43
ComboFix.txt
ComboFix2.txt

Here's the HijackThis log:

Logfile of HijackThis v1.99.1
Scan saved at 7:54:06 PM, on 2006-09-28
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Quick Lookup\QuickLookup.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Microsoft Office\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickLookup] C:\Program Files\Quick Lookup\QuickLookup.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jonin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) - http://us.dl1.yimg.com/download.yahoo.com/…ntr_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1140390121453
O16 - DPF: {754693AA-011F-40DD-B075-DD4644A47F54} (Importer.Imp) - http://www.imvu.com/catalog/invite/Importer.CAB
O16 - DPF: {958FCAB0-616B-11D3-A63F-00001B322780} (TimetickerLittleHelpers.usfServer) - http://www.timeticker.com/Timeset/TcpServer.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Patiently awaiting your reply…
Please follow my instructions exactly and in the order given.

• If you have an earlier version of eMule than version 0.47, you need to uninstall the program because it probably came bundled with spyware. If you do have an earlier version, then:
- Go to Start > Control Panel > Add/Remove Programs
- Select eMule
- Click Remove
- Select popupwithcast (if listed)
- Click Remove
- Exit

• Open Notepad and copy and paste the text inside the quotebox in it:

REGEDIT4

[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
"{B84CCA60-06C2-4105-0329-040307230001}"=-

[HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\Run]
"{B84CCA60-06C2-4105-0329-040307230001}"=-

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\newname]

[-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Shared Tools\MSCONFIG\Startupreg\septpop06apsept]


- Save this as fix.reg -> choose to save as *all files -> and place it on your desktop.
- It should look like this: [external image: Posted Image]
- Double-click on it and, when you are asked if you want to merge the contents to the registry, click YES/OK.

• Please set your system to show all files.
- Click Start.
- Open My Computer.
- Select the Tools menu and click Folder Options.
- Select the View Tab. Under the Hidden files and folders heading, select Show hidden files
and folders.
- Uncheck: Hide file extensions for known file types
- Uncheck the Hide protected operating system files (recommended) option.
- Click Yes to confirm.
- Click OK.

• Reboot into SAFE MODE.
To get into the Windows XP Safe Mode, restart your computer and, just before Windows starts to load, tap the F8 key a few times. Choose Safe Mode from the menu that will appear and press Enter.

• Start HijackThis, click System Scan Only and place a checkmark next to the following items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R3 - URLSearchHook: (no name) - _{A8BD6820-6ED7-423E-9558-2D1486B0FEEA} - (no file)
O16 - DPF: {754693AA-011F-40DD-B075-DD4644A47F54} (Importer.Imp) - http://www.imvu.com/catalog/invite/Importer.CAB


Close ALL browsers and open windows/programs except HijackThis and click 'Fix Checked'. Then exit HijackThis.

• Navigate to and delete the following folders if present:
C:\Program Files\Common Files\{B84CCA60-06C2-4105-0329-040307230001}
C:\Program Files\popupwithcast

• Navigate to and delete the following files if present:
C:\WINDOWS\popupwithcast.exe
C:\Program Files\swxf.exe
C:\Program Files\secure32.html
C:\Documents and Settings\Jonin\Application Data\WavCodec.wff
C:\nwnmff_e11.exe

• Navigate to and delete the following folder if present:
C:\Program Files\Common Files\{B84CCA60-06C2-4105-0329-040307230001}

• Reboot into Normal Mode.

• Now go to the following site: http://virusscan.jotti.org/
and scan the following files:
C:\WINDOWS\system32\nsw20.dll
C:\WINDOWS\system32\lfoc9b2b.sys
C:\aumco.exe

When you go to the site, you will see "File to upload & scan" at the top of the page. Click "Browse" and a "File Upload" window will open.
Navigate to the first file:
C:\WINDOWS\system32\nsw20.dll
Click onto the file, click "Open" and then click "Submit"
Wait for the scan to finish. Copy the results because you will paste them in your next reply.
Repeat the steps for the next two files.

• Post back with the results from Jotti's on the three files and a new HijackThis log.
Hey there Waterfalls: I didn't continue with the rest of the instructions as I got an error when I tried to add the information to the registry. It gave me the following error: "Cannot import C:\Documents and Settings\Jonin\Desktop\fix.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor." I didn't have a version of eMule below 0.47 nor did I have popupwithcast in the Add/Remove Programs. Please advise. Jonin6
Hi,

I want you to delete the fix.reg file that you created.

Go back and read the instructions carefully. Create the file again following the directions exactly as I posted them. The wording inside the quotebox beginnning with REGEDIT4 is to be copied and pasted to Notepad. Then follow the rest of the steps exactly.

As far as popwithcast not being in Add/Remove Programs, I didn't think it would be. That's why I put next to it "(if listed)" so that's okay.
Done… some files weren't there.

Here's the scans:

File: nsw20.dll
Status:
INFECTED/MALWARE (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 a538563fb256a8d79d32e25830721ff0
Packers detected:
PE_PATCH.UPX, UPX
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found not-a-virus:AdWare.Win32.EZula.cc
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

File: lfoc9b2b.sys
Status:
OK (Note: this file has been scanned before. Therefore, this file's scan results will not be stored in the database)
MD5 8f8a9b19cb0d2f3e8db43397d922bca6
Packers detected:
-
Scanner results
AntiVir
Found nothing
ArcaVir
Found nothing
Avast
Found nothing
AVG Antivirus
Found nothing
BitDefender
Found nothing
ClamAV
Found nothing
Dr.Web
Found nothing
F-Prot Antivirus
Found nothing
Fortinet
Found nothing
Kaspersky Anti-Virus
Found nothing
NOD32
Found nothing
Norman Virus Control
Found nothing
UNA
Found nothing
VirusBuster
Found nothing
VBA32
Found nothing

Scan of C:\aumco.exe brought the following message from the website:

The file you uploaded is 0 bytes. It is very likely a firewall or a piece of malware is prohibiting you from uploading this file

Logfile of HijackThis v1.99.1
Scan saved at 5:26:36 PM, on 2006-10-01
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Quick Lookup\QuickLookup.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\ewido anti-spyware 4.0\ewido.exe
C:\WINDOWS\system32\sstray.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\MagicDisc\MagicDisc.exe
C:\PROGRA~1\Webshots\webshots.scr
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\WgaTray.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickLookup] C:\Program Files\Quick Lookup\QuickLookup.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Jonin\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {31E68DE2-5548-4B23-88F0-C51E6A0F695E} (Microsoft PID Sniffer) - https://support.microsoft.com/OAS/ActiveX/odc.cab
O16 - DPF: {4EC8E993-32C1-47F5-A07A-5B0574655AD4} (WXcom Class) - http://us.dl1.yimg.com/download.yahoo.com/…ntr_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1140390121453
O16 - DPF: {958FCAB0-616B-11D3-A63F-00001B322780} (TimetickerLittleHelpers.usfServer) - http://www.timeticker.com/Timeset/TcpServer.CAB
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI