This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Klone virus and winantivirus

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ive been getting the popup from AVG that there is a Klone virus, also been getting popups from winantivirus pro, I'm a complete novice at this and have no clue what to do to remove them. please help!
thanks

ceara

I took this HijackThis log a few minutes ago

Logfile of HijackThis v1.99.1
Scan saved at 3:07:50 PM, on 10/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.amaena.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O15 - Trusted IP range: http://85.12.25.95
O15 - Trusted IP range: http://202.67.220.227
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - http://www.lotrdvd.com/dvdkey/extended_dvd…ds/iaieplay.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {262F1E21-510D-4FB3-9F40-F6C505CB2A59} (VacPro.canada_ver3_son) - http://www.advnt01.com/dialer/canada_ver3_son.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24bdea51b4f0fe…ip/RdxIE601.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - http://infoship/Printing/setup.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {683DFF0F-331F-44D2-B69B-46D7BFB58F32} (VacPro.canada_ver3) - http://www.advnt01.com/dialer/canada_ver3.CAB
O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) - http://data6.archives.ca/mrsidi_cab/MrSIDI.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsanik1/msrdp.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…inematycoon.cab
O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
Rename your copy of hijackthis.exe to findstuff.exe and post a fresh log run in Normal Mode. It's possible that this nasty is interfering with the normal working of HJT in order to hide itself and renaming the .exe will get around this.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Download Combofix by sUBs from here and save it to your Desktop.
  • Double click combo.exe to run it and follow the prompts.
  • When the tool has finished, it will produce a log C:\ComboFix.txt - copy and paste it into your next reply.
Please Note:
  • Do not mouse click in the combofix window while it is running - this may cause your system to hang/crash.
  • Disable Script Blocking if you have NAV installed as it will interfere with the normal working of this tool.
  • Trojan Hunter has been reported to detect this tool as Worm.Qiv.100 - please ignore this, it's a false-positive.
- 06-10-16 22:46:11.26 Service Pack 2 ComboFix 06.10.16 - ((((((((((((((((((((((((((((((( Files Created from 2006-09-16 to 2006-10-16 )))))))))))))))))))))))))))))))))) 2006-10-16 12:34 76,560 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys 2006-09-30 21:01 143,380 –a—— C:\WINDOWS\SYSTEM32\yivvsqpj.exe 2006-09-25 15:15 143,380 –a—— C:\WINDOWS\SYSTEM32\ljlrmfmm.exe 2006-09-24 21:31 114,688 –a—— C:\WINDOWS\SYSTEM32\rkinstaller.exe (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-16 22:40 ——– d——– C:\Program Files\Hijackthis 2006-10-16 16:02 ——– d——– C:\Program Files\Jewel Quest 2006-10-16 15:25 ——– d——– C:\Program Files\Mystery Case Files - Huntsville 2006-10-09 22:02 ——– d——– C:\Program Files\Mystery Case Files - Prime Suspects 2006-10-09 18:40 ——– d——– C:\Program Files\Hidden Expedition Titanic 2006-10-08 19:42 ——– d——– C:\Program Files\Fiber Twig 2 2006-09-26 16:23 ——– d——– C:\Program Files\Yahoo! Games 2006-09-26 16:21 ——– d–h—– C:\Program Files\InstallShield Installation Information 2006-09-26 16:21 ——– d——– C:\Program Files\Infogrames Interactive 2006-09-26 16:06 ——– d——– C:\Program Files\Setup 2006-09-26 16:06 ——– d——– C:\Program Files\filesubmit 2006-09-26 15:56 778656 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\avg7core.sys 2006-09-24 21:59 ——– d——– C:\Documents and Settings\Kelly 2\Application Data\EA 2006-09-24 21:36 8464 –a—— C:\WINDOWS\SYSTEM32\sporder.dll 2006-09-24 11:07 ——– d-a—— C:\Program Files\Common Files 2006-09-24 11:07 ——– d——– C:\Program Files\Common Files\Companion Wizard 2006-09-13 01:01 1084416 –a—— C:\WINDOWS\SYSTEM32\msxml3.dll 2006-09-07 07:55 ——– d——– C:\Program Files\SysProtect Free 2006-09-04 16:55 131604 –a—— C:\WINDOWS\SYSTEM32\hntutrnq.dll 2006-09-04 16:37 131604 –a—— C:\WINDOWS\SYSTEM32\tymmwfgr.dll 2006-08-31 21:34 131604 –a—— C:\WINDOWS\SYSTEM32\ftppxpen.dll 2006-08-31 20:33 131604 –a—— C:\WINDOWS\SYSTEM32\qsvxxwvb.dll 2006-08-31 19:26 421908 ——— C:\WINDOWS\SYSTEM32\psavryln.exe 2006-08-31 19:11 421908 ——— C:\WINDOWS\SYSTEM32\gdtvifsa.exe 2006-08-31 18:30 421908 ——— C:\WINDOWS\SYSTEM32\kjjlxqbm.exe 2006-08-31 18:11 421908 ——— C:\WINDOWS\SYSTEM32\pddpfyft.exe 2006-08-31 17:30 421908 ——— C:\WINDOWS\SYSTEM32\daarubhk.exe 2006-08-31 17:22 421908 ——— C:\WINDOWS\SYSTEM32\vlndnita.exe 2006-08-31 16:29 421908 ——— C:\WINDOWS\SYSTEM32\yfhrjkmn.exe 2006-08-31 15:29 421908 ——— C:\WINDOWS\SYSTEM32\unnnxqta.exe 2006-08-31 14:37 421908 ——— C:\WINDOWS\SYSTEM32\hhjmuiba.exe 2006-08-31 14:36 421908 ——— C:\WINDOWS\SYSTEM32\uhdhdcnh.exe 2006-08-31 13:36 421908 ——— C:\WINDOWS\SYSTEM32\gujjnqrm.exe 2006-08-31 12:35 565268 ——— C:\WINDOWS\nifoloe.dll 2006-08-31 12:35 421908 ——— C:\WINDOWS\SYSTEM32\xhvabrks.exe 2006-08-31 11:34 421908 ——— C:\WINDOWS\SYSTEM32\nluftnye.exe 2006-08-31 07:51 421908 ——— C:\WINDOWS\SYSTEM32\vsbiexkw.exe 2006-08-31 07:51 421908 ——— C:\WINDOWS\SYSTEM32\ueelapci.exe 2006-08-31 07:50 565268 ——— C:\WINDOWS\untocm.dll 2006-08-31 07:50 421908 ——— C:\WINDOWS\SYSTEM32\yiijwpeu.exe 2006-08-31 07:50 421908 ——— C:\WINDOWS\SYSTEM32\wcsntdjm.exe 2006-08-31 07:50 421908 ——— C:\WINDOWS\SYSTEM32\habcvlpx.exe 2006-08-31 07:49 421908 ——— C:\WINDOWS\SYSTEM32\uhqlmxhg.exe 2006-08-31 07:49 421908 ——— C:\WINDOWS\SYSTEM32\saotvopk.exe 2006-08-31 07:49 421908 ——— C:\WINDOWS\SYSTEM32\dkudipxa.exe 2006-08-31 07:48 421908 ——— C:\WINDOWS\SYSTEM32\unclbihp.exe 2006-08-31 07:48 421908 ——— C:\WINDOWS\SYSTEM32\qnlitaug.exe 2006-08-31 07:48 421908 ——— C:\WINDOWS\SYSTEM32\oicllqrg.exe 2006-08-31 07:48 421908 ——— C:\WINDOWS\SYSTEM32\kqfrumbh.exe 2006-08-31 07:47 421908 ——— C:\WINDOWS\SYSTEM32\opklftir.exe 2006-08-31 07:47 421908 ——— C:\WINDOWS\SYSTEM32\onslsobf.exe 2006-08-31 07:47 421908 ——— C:\WINDOWS\SYSTEM32\iqsqgaev.exe 2006-08-31 07:47 421908 ——— C:\WINDOWS\SYSTEM32\frpirlac.exe 2006-08-31 07:46 421908 ——— C:\WINDOWS\SYSTEM32\ugrbedhi.exe 2006-08-31 07:46 421908 ——— C:\WINDOWS\SYSTEM32\gytjxqul.exe 2006-08-31 07:46 421908 ——— C:\WINDOWS\SYSTEM32\gppyfkuo.exe 2006-08-31 07:45 565268 ——— C:\WINDOWS\odssmvc.dll 2006-08-31 07:45 421908 ——— C:\WINDOWS\SYSTEM32\xqycpmkf.exe 2006-08-31 07:45 421908 ——— C:\WINDOWS\SYSTEM32\upvnajot.exe 2006-08-31 07:45 421908 ——— C:\WINDOWS\SYSTEM32\qsjkuxkj.exe 2006-08-31 07:45 421908 ——— C:\WINDOWS\SYSTEM32\fgrtvtcp.exe 2006-08-31 07:44 421908 ——— C:\WINDOWS\SYSTEM32\jxglwioo.exe 2006-08-31 07:44 421908 ——— C:\WINDOWS\SYSTEM32\ejkybqty.exe 2006-08-30 19:21 421908 ——— C:\WINDOWS\SYSTEM32\gujskwdf.exe 2006-08-30 18:55 421908 ——— C:\WINDOWS\SYSTEM32\jvmuvakk.exe 2006-08-30 18:55 421908 ——— C:\WINDOWS\SYSTEM32\btasjxvx.exe 2006-08-30 18:55 421908 ——— C:\WINDOWS\SYSTEM32\ajorsmte.exe 2006-08-30 18:54 421908 ——— C:\WINDOWS\SYSTEM32\hgmuorsm.exe 2006-08-30 18:54 421908 ——— C:\WINDOWS\SYSTEM32\fvolbmua.exe 2006-08-30 18:53 421908 ——— C:\WINDOWS\SYSTEM32\rnuovkbp.exe 2006-08-30 18:53 421908 ——— C:\WINDOWS\SYSTEM32\mfnyhkkq.exe 2006-08-30 18:52 421908 ——— C:\WINDOWS\SYSTEM32\wlokfona.exe 2006-08-30 18:52 421908 ——— C:\WINDOWS\SYSTEM32\lltohcjv.exe 2006-08-30 18:52 421908 ——— C:\WINDOWS\SYSTEM32\ahyjjpud.exe 2006-08-30 18:51 421908 ——— C:\WINDOWS\SYSTEM32\upvshuav.exe 2006-08-30 18:51 421908 ——— C:\WINDOWS\SYSTEM32\ipcwdbds.exe 2006-08-30 18:51 421908 ——— C:\WINDOWS\SYSTEM32\hpqnfhfy.exe 2006-08-30 18:50 421908 ——— C:\WINDOWS\SYSTEM32\swkqktkd.exe 2006-08-30 18:50 421908 ——— C:\WINDOWS\SYSTEM32\kjffwgqu.exe 2006-08-30 18:50 421908 ——— C:\WINDOWS\SYSTEM32\bqokxgep.exe 2006-08-30 18:49 421908 ——— C:\WINDOWS\SYSTEM32\dmhoymvs.exe 2006-08-30 18:04 421908 ——— C:\WINDOWS\SYSTEM32\gbgvrbft.exe 2006-08-30 18:04 421908 ——— C:\WINDOWS\SYSTEM32\dopjhlns.exe 2006-08-30 18:04 421908 ——— C:\WINDOWS\SYSTEM32\cwsqtoqb.exe 2006-08-30 18:02 565268 ——— C:\WINDOWS\fmcniet.dll 2006-08-30 18:02 565268 ——— C:\WINDOWS\colg.dll 2006-08-30 18:02 421908 ——— C:\WINDOWS\SYSTEM32\pccdcqou.exe 2006-08-30 18:02 421908 ——— C:\WINDOWS\SYSTEM32\gwkyqxsa.exe 2006-08-30 18:01 421908 ——— C:\WINDOWS\SYSTEM32\wogfodih.exe 2006-08-30 18:01 421908 ——— C:\WINDOWS\SYSTEM32\sskffpjm.exe 2006-08-30 18:01 421908 ——— C:\WINDOWS\SYSTEM32\hooaodut.exe 2006-08-30 18:00 421908 ——— C:\WINDOWS\SYSTEM32\tkvgvtky.exe 2006-08-30 18:00 421908 ——— C:\WINDOWS\SYSTEM32\nxufvbjk.exe 2006-08-30 18:00 421908 ——— C:\WINDOWS\SYSTEM32\exfkvcxf.exe 2006-08-30 17:49 421908 ——— C:\WINDOWS\SYSTEM32\fqlswyya.exe 2006-08-30 17:49 421908 ——— C:\WINDOWS\SYSTEM32\dxaqafch.exe 2006-08-27 22:45 ——– d——– C:\Documents and Settings\Kelly 2\Application Data\Wildfire 2006-08-26 13:13 ——– d——– C:\Program Files\Lavasoft 2006-08-25 11:45 617472 –a—— C:\WINDOWS\SYSTEM32\comctl32.dll 2006-08-21 08:21 16896 –a—— C:\WINDOWS\SYSTEM32\fltlib.dll 2006-08-21 05:14 23040 –a—— C:\WINDOWS\SYSTEM32\fltmc.exe 2006-08-21 05:14 128896 ——— C:\WINDOWS\SYSTEM32\DRIVERS\fltmgr.sys 2006-08-18 20:35 ——– d——– C:\Program Files\Virtual Villagers 2006-08-16 07:58 100352 –a—— C:\WINDOWS\SYSTEM32\6to4svc.dll 2006-08-16 05:37 225664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys 2006-08-06 16:01 122900 –a—— C:\WINDOWS\SYSTEM32\tqghcaws.dll 2006-07-27 09:24 679424 –a—— C:\WINDOWS\SYSTEM32\inetcomm.dll 2006-07-21 04:24 72704 –a—— C:\WINDOWS\SYSTEM32\hlink.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "Sonic RecordNow!"="" "DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup" "RealPlayer"="\"C:\\Program Files\\Real\\RealPlayer\\realplay.exe\" /RunUPGToolCommandReBoot" "SysProtect Free"="\"C:\\Program Files\\SysProtect Free\\USYP.exe\" /min" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\System32\\NvCpl.dll,NvStartup" "BCMSMMSG"="BCMSMMSG.exe" "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "DVDSentry"="C:\\WINDOWS\\System32\\DSentry.exe" "PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\"" "diagent"="\"C:\\Program Files\\Creative\\SBLive\\Diagnostics\\diagent.exe\" startup" "UpdReg"="C:\\WINDOWS\\UpdReg.EXE" "UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" @="" "mmtask"="C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mmtask.exe" "POINTER"="point32.exe" "AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP" "AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgemc.exe" "navapp"="C:\\Program Files\\NavExcel\\NavHelper\\v2.0.4d\\navapp.exe" "AdaptecDirectCD"="\"C:\\Program Files\\Roxio\\Easy CD Creator 5\\DirectCD\\DirectCD.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runonceex] @="" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,de,02,\ 00,00,01,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] "Source"="http://www.bloomsbury.com/harrypotter/countdown.htm" "SubscribedURL"="http://www.bloomsbury.com/harrypotter/countdown.cdf" "FriendlyName"="Bloomsbury.com Harry Potter and the Half-Blood Prince Countdown" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,02,00,00,00,34,01,00,00,cd,00,00,00,8a,00,00,00,ea,\ 03,00,00,00,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,02,00,00,00,51,02,00,00,cd,00,00,00,8a,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,2e,03,00,00,4e,02,00,00,cd,00,00,00,8a,00,\ 00,00,01,00,00,40 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\2] "Source"="http://www.mugglenet.com/includes/hbp-cd.html" "SubscribedURL"="http://www.mugglenet.com/includes/hbp-cd.html" "FriendlyName"="Harry Potter and the Half Blood Prince Countdown" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,00,00,00,01,00,00,00,a0,01,00,00,77,00,00,00,ec,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,01,00,00,00,a0,01,00,00,77,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:80,31,13,00,41,c0,b4,74,f8,bc,1d,00,e0,a2,13,00,8c,31,\ 13,00,b7,57,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\3] "Source"="http://www.mugglenet.com/countdown/gof-countdown.php?o=nov18" "SubscribedURL"="http://www.mugglenet.com/countdown/gof-countdown.php?o=nov18" "FriendlyName"="Harry Potter and the Goblet of Fire Movie Countdown" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,00,00,00,01,00,00,00,a0,01,00,00,77,00,00,00,ee,\ 03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,00,00,00,00,01,00,00,00,a0,01,00,00,77,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:80,31,13,00,41,c0,b4,74,b0,70,84,04,e0,a2,13,00,8c,31,\ 13,00,05,75,00,00 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] @="" "NoDriveTypeAutoRun"=hex:5f,00,00,00 "NoCDBurning"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "CDRAutoRun"=dword:00000000 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "CDRAutoRun"=dword:00000000 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^AOL 8.0 Tray Icon.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\AOL 8.0 Tray Icon.lnk" "backup"="C:\\WINDOWS\\pss\\AOL 8.0 Tray Icon.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\AOL8~1.0\\aoltray.exe -check" "item"="AOL 8.0 Tray Icon" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Kodak EasyShare software.lnk] "path"="C:\\Documents and Settings\\All Users\\Start Menu\\Programs\\Startup\\Kodak EasyShare software.lnk" "backup"="C:\\WINDOWS\\pss\\Kodak EasyShare software.lnkCommon Startup" "location"="Common Startup" "command"="C:\\PROGRA~1\\Kodak\\KODAKE~1\\bin\\EASYSH~1.EXE -h" "item"="Kodak EasyShare software" [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking] "key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run" "item"="P2P Networking" "hkey"="HKLM" "command"="C:\\WINDOWS\\System32\\P2P Networking\\P2P Networking.exe /AUTOSTART" "inimapping"="0" HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rulloe HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\srrcfetx HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wkrrdnfr [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\{D2EBF79F-4EEA-4E57-826F-E54D451C29A3}_MADISON_Kelly 2.job Completion time: 06-10-16 22:48:29.67 C:\ComboFix.txt … 06-10-16 22:48
this is the program list A Series of Unfortunate Events (remove only) Absolute Fit-trix 1.0.2 Ad-Aware SE Personal aditltheme.zip Adobe Acrobat - Reader 6.0.2 Update Adobe Acrobat 4.0, 5.0 Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Download Manager 1.2 (Remove Only) Adobe Photoshop 5.0 Limited Edition Adobe Photoshop 7.0 Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 6.0.1 ahatfullofluckwp.zip ArcSoft PhotoImpression aspi Atlantis (remove only) Autumn Cardinals_SS Autumn Flight Autumn Glory Active autumncardinalsss.exe AVG Free Edition BCM V.92 56K Modem Beautiful Portrait Humming Bird Photography Bejeweled 2 Deluxe 1.0 BestOn Software bookoflife.zip Canon i560 CCHelp CCScore Celestrial Birth Active Christmas Lights Christmas Ornaments Christmas Time ClarisWorks 4.0 Classic PhoneTools Cold as Ice Wallpaper Crime Puzzle 1.0 Da Vinci`s Secret (remove only) Dell Digital Jukebox Driver Dell Media Experience Dell ResourceCD Dell Solution Center Dell Support 5.0.0 (766) Desktop Angel DVDSentry earthandskyscr.zip Easy CD Creator 5 Platinum EKS Sherlock 5.0 eMazing Mazes Emerald Skies End Of A Long Journey 1024x768 EPSON Copy Utility EPSON PERF 1670 Guide EPSON Photo Print EPSON Scan EPSON Smart Panel ESSAdpt ESSANUP ESSBrwr ESSCAM ESSCDBK ESScore ESSgui ESShelp ESSini ESSPCD ESSstore ESSTUTOR ESSvpaht ESSvpot Eye Candy 4000 eZshopper Family Feud Hollywood Edition (remove only) Family Tree Maker 9.0 Google Talk (remove only) Google Toolbar for Internet Explorer Happy Holiday Harry Potter Harry Potter and the Prisoner of Azkaban™ Harry Potter II Harry Potter Lumos Screen Saver Hidden Expedition - Titanic (remove only) Hidden Expedition Titanic (remove only) HighMAT Extension to Microsoft Windows XP CD Writing Wizard Hijackthis 1.99.1 HijackThis 1.99.1 Hogwarts4 Active HummingbirdHaven2WP ICQ Images of Spring Incrediball Level Pack 1 1.0 Intel® PRO Network Adapters and Drivers Intel® PROSet InterActual Player Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2 Jewel Quest Kodak EasyShare software KSU Lighthouse Active LimeWire LimeWire 4.10.3 Lizardtech DjVu Control Lizardtech Express View Browser Plug-in Logitech Gaming Software Looking For Santa LOTR The Return of the King tm Macromedia Flash Player 8 Macromedia Shockwave Player Magic Ball 2 New Worlds Magic Vines (remove only) magical4 Screen Saver Mahjong Quest Mahjongg XP Championship 2006 Platinum Edition Merry Christmas Darling Screen Saver Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Data Access Components KB870669 Microsoft Encarta Encyclopedia Standard 2004 Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office 97, Professional Edition Microsoft Windows Media Video 9 VCM Microsoft Word 2000 Modem Helper Moraff's Maximum MahJongg 1.0 MrSID Browser Plug-in 1.3 MSN MuggleNet.com's Harry Potter and the Prisoner of Azkaban Screensaver Music Visualizer Library 1.4.00 MUSICMATCH® Jukebox Mystery Case Files - Huntsville (remove only) Mystery Case Files - Prime Suspects (remove only) Net MD Simple Burner Night Before Christmas Saver Notifier NVIDIA Windows 2000/XP Display Drivers OpenMG Limited Patch 3.2-03-02-21-08 OpenMG Limited Patch 3.2-03-04-14-02 OpenMG Limited Patch 3.2-03-04-17-02 OpenMG Secure Module 3.2 OTtBP Paint Shop Pro 7 PC CameraQ PCDLNCH PICVideo Codecs Pix-Fit 1.0 PowerDVD Pretty Good MahJongg version 1.11 Pretty Good Solitaire - Additional Card Sets 1.0 Pretty Good Solitaire - Christmas Card Set 1.0.2 Pretty Good Solitaire - Elegant Card Set 1.1 Pretty Good Solitaire - Halloween Card Set 1.0 Pretty Good Solitaire version 9.1.0 Princess Diaries SE Screen Saver Pumpkin Patch Babies Pumpkin Pines Quick! Toolbar QuickTax 2003 Standard QuickTax 2004 QuickTax 2005 RealArcade RealPlayer Red Hawk RollerCoaster Tycoon Deluxe Ruby Throated Hummingbird 1024x768 Sandlot Games Client Services Santa Balls ScanToWeb Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925486) SFR SFR2 Shockwave Snow Bench Sonic DLA Sonic RecordNow! Sonic Update Manager SonicStage 1.5.53 Sound Blaster Live! Spybot - Search & Destroy 1.4 Sunset River with Birds Super Slyder 1.09 SysProtect [removed] The Da Vinci Code (remove only) The Hobbit™ The Muse Wallpaper The Polar Express Screen Saver The Sims 2 The Sims 2 Family Fun Stuff The Sims 2 HomeCrafter Plus The Sims 2 Nightlife The Sims 2 University thunderonthef.zip tranquilty.exe Tumblebugs (remove only) Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) USB MassStorage CardReader Viewpoint Manager (Remove Only) Viewpoint Toolbar (Remove Only) Virtual Villagers (remove only) VPN Client VSToolbar for Internet Explorer waithalow1024wp.zip Web Savings from Ebates WebSearch Tools Weeping Willow Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Format Runtime Windows Media Player 10 Windows SR 5.0 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 Winnie the Pooh 010 Witches Home 1024x768 WordPerfect Office 11 Yahoo! Messenger Zoo Tycoon: Complete Collection

ok…im not sure exactly how to rename hijackthis, i dont want to screw up the program, sorry

Navigate to C:\Program Files\Hijackthis\HijackThis.exe, right click HijackThis.exe and select Rename from the menu.
Change the name to findstuff.exe and then post a fresh HJT log run in Normal Mode.
Logfile of HijackThis v1.99.1
Scan saved at 7:46:48 PM, on 10/17/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Winamp\winamp.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\findstuff.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1109F444-EFA0-446F-BFB0-F755B1278153} - (no file)
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\mcxwlgsd.dll (file missing)
O2 - BHO: ohb Class - {285B5CCD-C3F0-4EB6-9632-7D0A3C3AF824} - C:\WINDOWS\system32\hsrb.dll (file missing)
O2 - BHO: (no name) - {291EBEDD-5645-48B7-B0D1-805582EC3B29} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {2E5C7C61-C031-4CC9-8A4D-AAA00C57F635} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {4A22E1FE-5793-490D-8259-9F4F0CABF117} - (no file)
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {54AAEFC7-9717-4A6C-A676-A1E04DC1D34D} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7AE965D0-E0D3-4C94-8E1A-2ABCD63905EC} - (no file)
O2 - BHO: (no name) - {7C1ADA1D-3AA1-4ACF-AE4B-F80B30EDEDC2} - (no file)
O2 - BHO: (no name) - {80A6BD25-4DC6-4549-AD72-A2E39D69D7B7} - (no file)
O2 - BHO: (no name) - {8CB61A5E-B014-49A8-8CDA-651EAC1030C6} - C:\WINDOWS\ServicePackFiles\rulloe.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AF01BD28-6E72-4D9E-A333-8E8C0B245236} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {B7A016B6-127C-4C94-A53A-AF9082D4FB2c} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.amaena.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O15 - Trusted IP range: http://85.12.25.95
O15 - Trusted IP range: http://202.67.220.227
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - http://www.lotrdvd.com/dvdkey/extended_dvd…ds/iaieplay.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {262F1E21-510D-4FB3-9F40-F6C505CB2A59} (VacPro.canada_ver3_son) - http://www.advnt01.com/dialer/canada_ver3_son.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24bdea51b4f0fe…ip/RdxIE601.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - http://infoship/Printing/setup.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {683DFF0F-331F-44D2-B69B-46D7BFB58F32} (VacPro.canada_ver3) - http://www.advnt01.com/dialer/canada_ver3.CAB
O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) - http://data6.archives.ca/mrsidi_cab/MrSIDI.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsanik1/msrdp.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…inematycoon.cab
O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: rulloe - C:\WINDOWS\ServicePackFiles\rulloe.dll
O20 - Winlogon Notify: srrcfetx - srrcfetx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wkrrdnfr - wkrrdnfr.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
Download VundoFix.exe by Atribune from here and save it to your desktop.to your desktop.
  • Close all open programs and windows as this may require a reboot.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will shutdown your computer, click OK.
  • Turn your computer back on.
  • Post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.
the vonduFix report VundoFix V6.2.6 Checking Java version… Scan started at 1:35:18 PM 10/20/2006 Listing files found while scanning…. C:\WINDOWS\colg.dll C:\WINDOWS\fmcniet.dll C:\WINDOWS\nifoloe.dll C:\WINDOWS\odssmvc.dll C:\WINDOWS\untocm.dll C:\WINDOWS\ADDINS\smpi.dll C:\WINDOWS\ADDINS\tuilbv.dll C:\WINDOWS\AppPatch\atpiibn.dll C:\WINDOWS\AppPatch\bvtfp.dll C:\WINDOWS\AppPatch\smvcodc.dll C:\WINDOWS\assembly\GAC\Accessibility\nietvdd.dll C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\ualasis.dll C:\WINDOWS\assembly\temp\ajvanati.dll C:\WINDOWS\assembly\temp\ibnmws.dll C:\WINDOWS\Config\idskrdv.dll C:\WINDOWS\Config\ofntcm.dll C:\WINDOWS\Cursors\arsva.dll C:\WINDOWS\Cursors\awvemcd.dll C:\WINDOWS\Cursors\dobccp.dll C:\WINDOWS\Fonts\cpocm.dll C:\WINDOWS\Fonts\ewbatpi.dll C:\WINDOWS\Fonts\ilbodc.dll C:\WINDOWS\Fonts\cdobli.tmp C:\WINDOWS\Fonts\olgw.dll C:\WINDOWS\Fonts\pas.dll C:\WINDOWS\Help\ibnlpay.dll C:\WINDOWS\Help\ibnsis.dll C:\WINDOWS\Help\SBSI\sprul.dll C:\WINDOWS\INF\acbibn.dll C:\WINDOWS\INF\actidsk.dll C:\WINDOWS\INF\ergajva.dll C:\WINDOWS\INF\smamin.dll C:\WINDOWS\Microsoft.NET\abkctp.dll C:\WINDOWS\Microsoft.NET\arsent.dll C:\WINDOWS\Microsoft.NET\miggva.dll C:\WINDOWS\Microsoft.NET\avggim.bak1 C:\WINDOWS\Microsoft.NET\avggim.tmp C:\WINDOWS\Microsoft.NET\ndsact.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ekys.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ibnent.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\odsw.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ruls.dll C:\WINDOWS\MSAGENT\nifoiwn.dll C:\WINDOWS\MSAGENT\odcabs.dll C:\WINDOWS\MSAGENT\odcloe.dll C:\WINDOWS\MSAGENT\tuilewb.dll C:\WINDOWS\MSAGENT\urnnati.dll C:\WINDOWS\REPAIR\abkocm.dll C:\WINDOWS\REPAIR\ajvaca.dll C:\WINDOWS\REPAIR\acavja.ini C:\WINDOWS\SECURITY\cacnds.dll C:\WINDOWS\SECURITY\LOGS\entfmc.dll C:\WINDOWS\SECURITY\LOGS\smca.dll C:\WINDOWS\ServicePackFiles\arsocm.dll C:\WINDOWS\ServicePackFiles\cmc.dll C:\WINDOWS\ServicePackFiles\dadobc.dll C:\WINDOWS\ServicePackFiles\dobcc.dll C:\WINDOWS\ServicePackFiles\mxlxep.dll C:\WINDOWS\ServicePackFiles\rulloe.dll C:\WINDOWS\ServicePackFiles\eollur.ini C:\WINDOWS\ServicePackFiles\eollur.bak1 C:\WINDOWS\ServicePackFiles\eollur.bak2 C:\WINDOWS\ServicePackFiles\eollur.ini2 C:\WINDOWS\ServicePackFiles\eollur.tmp C:\WINDOWS\ServicePackFiles\vddpm3.dll C:\WINDOWS\SYSTEM\cpunt.dll C:\WINDOWS\SYSTEM\ilbibn.dll C:\WINDOWS\SYSTEM\ilblpay.dll C:\WINDOWS\SYSTEM\loeidsk.dll C:\WINDOWS\SYSTEM32\3COM_DMI\capm3.dll C:\WINDOWS\SYSTEM32\Com\daafx.dll C:\WINDOWS\SYSTEM32\DRVSTORE\entolg.dll C:\WINDOWS\SYSTEM32\MsDtc\lpayolg.dll C:\WINDOWS\Web\atskabk.dll C:\WINDOWS\Web\iwncm.dll C:\WINDOWS\Web\smw.dll C:\WINDOWS\Web\PRINTERS\loemig.dll C:\WINDOWS\SYSTEM32\brxxjsfe.exe C:\WINDOWS\SYSTEM32\ghgyckjt.exe C:\WINDOWS\SYSTEM32\ljlrmfmm.exe C:\WINDOWS\SYSTEM32\xfeurorp.exe C:\WINDOWS\SYSTEM32\yivvsqpj.exe C:\WINDOWS\ServicePackFiles\rulloe.dll C:\WINDOWS\Fonts\cdobli.tmp C:\WINDOWS\Microsoft.NET\avggim.bak1 C:\WINDOWS\Microsoft.NET\avggim.tmp C:\WINDOWS\REPAIR\acavja.ini C:\WINDOWS\ServicePackFiles\eollur.ini C:\WINDOWS\ServicePackFiles\eollur.bak1 C:\WINDOWS\ServicePackFiles\eollur.bak2 C:\WINDOWS\ServicePackFiles\eollur.ini2 C:\WINDOWS\ServicePackFiles\eollur.tmp C:\WINDOWS\ServicePackFiles\eollur.ini C:\WINDOWS\ServicePackFiles\eollur.bak1 C:\WINDOWS\ServicePackFiles\eollur.bak2 C:\WINDOWS\ServicePackFiles\eollur.ini2 C:\WINDOWS\ServicePackFiles\eollur.tmp Beginning removal… Attempting to delete C:\WINDOWS\colg.dll C:\WINDOWS\colg.dll Has been deleted! Attempting to delete C:\WINDOWS\fmcniet.dll C:\WINDOWS\fmcniet.dll Has been deleted! Attempting to delete C:\WINDOWS\nifoloe.dll C:\WINDOWS\nifoloe.dll Has been deleted! Attempting to delete C:\WINDOWS\odssmvc.dll C:\WINDOWS\odssmvc.dll Has been deleted! Attempting to delete C:\WINDOWS\untocm.dll C:\WINDOWS\untocm.dll Has been deleted! Attempting to delete C:\WINDOWS\ADDINS\smpi.dll C:\WINDOWS\ADDINS\smpi.dll Has been deleted! Attempting to delete C:\WINDOWS\ADDINS\tuilbv.dll C:\WINDOWS\ADDINS\tuilbv.dll Has been deleted! Attempting to delete C:\WINDOWS\AppPatch\atpiibn.dll C:\WINDOWS\AppPatch\atpiibn.dll Has been deleted! Attempting to delete C:\WINDOWS\AppPatch\bvtfp.dll C:\WINDOWS\AppPatch\bvtfp.dll Has been deleted! Attempting to delete C:\WINDOWS\AppPatch\smvcodc.dll C:\WINDOWS\AppPatch\smvcodc.dll Has been deleted! Attempting to delete C:\WINDOWS\assembly\GAC\Accessibility\nietvdd.dll C:\WINDOWS\assembly\GAC\Accessibility\nietvdd.dll Has been deleted! Attempting to delete C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\ualasis.dll C:\WINDOWS\assembly\NativeImages1_v1.1.4322\System.Drawing\ualasis.dll Has been deleted! Attempting to delete C:\WINDOWS\assembly\temp\ajvanati.dll C:\WINDOWS\assembly\temp\ajvanati.dll Has been deleted! Attempting to delete C:\WINDOWS\assembly\temp\ibnmws.dll C:\WINDOWS\assembly\temp\ibnmws.dll Has been deleted! Attempting to delete C:\WINDOWS\Config\idskrdv.dll C:\WINDOWS\Config\idskrdv.dll Has been deleted! Attempting to delete C:\WINDOWS\Config\ofntcm.dll C:\WINDOWS\Config\ofntcm.dll Has been deleted! Attempting to delete C:\WINDOWS\Cursors\arsva.dll C:\WINDOWS\Cursors\arsva.dll Has been deleted! Attempting to delete C:\WINDOWS\Cursors\awvemcd.dll C:\WINDOWS\Cursors\awvemcd.dll Has been deleted! Attempting to delete C:\WINDOWS\Cursors\dobccp.dll C:\WINDOWS\Cursors\dobccp.dll Has been deleted! Attempting to delete C:\WINDOWS\Fonts\cpocm.dll C:\WINDOWS\Fonts\cpocm.dll Has been deleted! Attempting to delete C:\WINDOWS\Fonts\ewbatpi.dll C:\WINDOWS\Fonts\ewbatpi.dll Has been deleted! Attempting to delete C:\WINDOWS\Fonts\ilbodc.dll C:\WINDOWS\Fonts\ilbodc.dll Has been deleted! Attempting to delete C:\WINDOWS\Fonts\cdobli.tmp C:\WINDOWS\Fonts\cdobli.tmp Has been deleted! Attempting to delete C:\WINDOWS\Fonts\olgw.dll C:\WINDOWS\Fonts\olgw.dll Has been deleted! Attempting to delete C:\WINDOWS\Fonts\pas.dll C:\WINDOWS\Fonts\pas.dll Has been deleted! Attempting to delete C:\WINDOWS\Help\ibnlpay.dll C:\WINDOWS\Help\ibnlpay.dll Has been deleted! Attempting to delete C:\WINDOWS\Help\ibnsis.dll C:\WINDOWS\Help\ibnsis.dll Has been deleted! Attempting to delete C:\WINDOWS\Help\SBSI\sprul.dll C:\WINDOWS\Help\SBSI\sprul.dll Has been deleted! Attempting to delete C:\WINDOWS\INF\acbibn.dll C:\WINDOWS\INF\acbibn.dll Has been deleted! Attempting to delete C:\WINDOWS\INF\actidsk.dll C:\WINDOWS\INF\actidsk.dll Has been deleted! Attempting to delete C:\WINDOWS\INF\ergajva.dll C:\WINDOWS\INF\ergajva.dll Has been deleted! Attempting to delete C:\WINDOWS\INF\smamin.dll C:\WINDOWS\INF\smamin.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\abkctp.dll C:\WINDOWS\Microsoft.NET\abkctp.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\arsent.dll C:\WINDOWS\Microsoft.NET\arsent.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\miggva.dll C:\WINDOWS\Microsoft.NET\miggva.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\avggim.bak1 C:\WINDOWS\Microsoft.NET\avggim.bak1 Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\avggim.tmp C:\WINDOWS\Microsoft.NET\avggim.tmp Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\ndsact.dll C:\WINDOWS\Microsoft.NET\ndsact.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ekys.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ekys.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ibnent.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ibnent.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\odsw.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\odsw.dll Has been deleted! Attempting to delete C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ruls.dll C:\WINDOWS\Microsoft.NET\Framework\v1.0.3705\ruls.dll Has been deleted! Attempting to delete C:\WINDOWS\MSAGENT\nifoiwn.dll C:\WINDOWS\MSAGENT\nifoiwn.dll Has been deleted! Attempting to delete C:\WINDOWS\MSAGENT\odcabs.dll C:\WINDOWS\MSAGENT\odcabs.dll Has been deleted! Attempting to delete C:\WINDOWS\MSAGENT\odcloe.dll C:\WINDOWS\MSAGENT\odcloe.dll Has been deleted! Attempting to delete C:\WINDOWS\MSAGENT\tuilewb.dll C:\WINDOWS\MSAGENT\tuilewb.dll Has been deleted! Attempting to delete C:\WINDOWS\MSAGENT\urnnati.dll C:\WINDOWS\MSAGENT\urnnati.dll Has been deleted! Attempting to delete C:\WINDOWS\REPAIR\abkocm.dll C:\WINDOWS\REPAIR\abkocm.dll Has been deleted! Attempting to delete C:\WINDOWS\REPAIR\ajvaca.dll C:\WINDOWS\REPAIR\ajvaca.dll Has been deleted! Attempting to delete C:\WINDOWS\REPAIR\acavja.ini C:\WINDOWS\REPAIR\acavja.ini Has been deleted! Attempting to delete C:\WINDOWS\SECURITY\cacnds.dll C:\WINDOWS\SECURITY\cacnds.dll Has been deleted! Attempting to delete C:\WINDOWS\SECURITY\LOGS\entfmc.dll C:\WINDOWS\SECURITY\LOGS\entfmc.dll Has been deleted! Attempting to delete C:\WINDOWS\SECURITY\LOGS\smca.dll C:\WINDOWS\SECURITY\LOGS\smca.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\arsocm.dll C:\WINDOWS\ServicePackFiles\arsocm.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\cmc.dll C:\WINDOWS\ServicePackFiles\cmc.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\dadobc.dll C:\WINDOWS\ServicePackFiles\dadobc.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\dobcc.dll C:\WINDOWS\ServicePackFiles\dobcc.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\mxlxep.dll C:\WINDOWS\ServicePackFiles\mxlxep.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\rulloe.dll C:\WINDOWS\ServicePackFiles\rulloe.dll Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\eollur.ini C:\WINDOWS\ServicePackFiles\eollur.ini Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\eollur.bak1 C:\WINDOWS\ServicePackFiles\eollur.bak1 Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\eollur.bak2 C:\WINDOWS\ServicePackFiles\eollur.bak2 Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\eollur.ini2 C:\WINDOWS\ServicePackFiles\eollur.ini2 Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\eollur.tmp C:\WINDOWS\ServicePackFiles\eollur.tmp Has been deleted! Attempting to delete C:\WINDOWS\ServicePackFiles\vddpm3.dll C:\WINDOWS\ServicePackFiles\vddpm3.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM\cpunt.dll C:\WINDOWS\SYSTEM\cpunt.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM\ilbibn.dll C:\WINDOWS\SYSTEM\ilbibn.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM\ilblpay.dll C:\WINDOWS\SYSTEM\ilblpay.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM\loeidsk.dll C:\WINDOWS\SYSTEM\loeidsk.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\3COM_DMI\capm3.dll C:\WINDOWS\SYSTEM32\3COM_DMI\capm3.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\Com\daafx.dll C:\WINDOWS\SYSTEM32\Com\daafx.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\DRVSTORE\entolg.dll C:\WINDOWS\SYSTEM32\DRVSTORE\entolg.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\MsDtc\lpayolg.dll C:\WINDOWS\SYSTEM32\MsDtc\lpayolg.dll Has been deleted! Attempting to delete C:\WINDOWS\Web\atskabk.dll C:\WINDOWS\Web\atskabk.dll Has been deleted! Attempting to delete C:\WINDOWS\Web\iwncm.dll C:\WINDOWS\Web\iwncm.dll Has been deleted! Attempting to delete C:\WINDOWS\Web\smw.dll C:\WINDOWS\Web\smw.dll Has been deleted! Attempting to delete C:\WINDOWS\Web\PRINTERS\loemig.dll C:\WINDOWS\Web\PRINTERS\loemig.dll Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\brxxjsfe.exe C:\WINDOWS\SYSTEM32\brxxjsfe.exe Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\ghgyckjt.exe C:\WINDOWS\SYSTEM32\ghgyckjt.exe Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\ljlrmfmm.exe C:\WINDOWS\SYSTEM32\ljlrmfmm.exe Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\xfeurorp.exe C:\WINDOWS\SYSTEM32\xfeurorp.exe Has been deleted! Attempting to delete C:\WINDOWS\SYSTEM32\yivvsqpj.exe C:\WINDOWS\SYSTEM32\yivvsqpj.exe Has been deleted! Performing Repairs to the registry. Done!
hijackthis report

Logfile of HijackThis v1.99.1
Scan saved at 1:49:21 PM, on 10/20/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\Hijackthis\findstuff.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1109F444-EFA0-446F-BFB0-F755B1278153} - (no file)
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\mcxwlgsd.dll (file missing)
O2 - BHO: ohb Class - {285B5CCD-C3F0-4EB6-9632-7D0A3C3AF824} - C:\WINDOWS\system32\hsrb.dll (file missing)
O2 - BHO: (no name) - {291EBEDD-5645-48B7-B0D1-805582EC3B29} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {2E5C7C61-C031-4CC9-8A4D-AAA00C57F635} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {4A22E1FE-5793-490D-8259-9F4F0CABF117} - (no file)
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {54AAEFC7-9717-4A6C-A676-A1E04DC1D34D} - (no file)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {7AE965D0-E0D3-4C94-8E1A-2ABCD63905EC} - (no file)
O2 - BHO: (no name) - {7C1ADA1D-3AA1-4ACF-AE4B-F80B30EDEDC2} - (no file)
O2 - BHO: (no name) - {80A6BD25-4DC6-4549-AD72-A2E39D69D7B7} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: (no name) - {AF01BD28-6E72-4D9E-A333-8E8C0B245236} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {B04AEE3A-FADF-47A8-97D0-E68FE029E8C1} - C:\WINDOWS\ServicePackFiles\rulloe.dll (file missing)
O2 - BHO: (no name) - {B7A016B6-127C-4C94-A53A-AF9082D4FB2c} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O15 - Trusted Zone: http://www.amaena.com
O15 - Trusted Zone: http://locator.cdn.imageservr.com
O15 - Trusted Zone: http://locator1.cdn.imagesrvr.com
O15 - Trusted Zone: http://scanner.sysprotect.com
O15 - Trusted Zone: http://*.systemdoctor.com
O15 - Trusted Zone: http://www.winantivirus.com
O15 - Trusted Zone: http://www.winantiviruspro.com
O15 - Trusted Zone: http://download.cdn.winsoftware.com
O15 - Trusted IP range: http://202.67.220.225
O15 - Trusted IP range: http://59.148.220.121
O15 - Trusted IP range: http://62.4.84.53
O15 - Trusted IP range: http://82.98.235.58
O15 - Trusted IP range: http://85.12.25.90
O15 - Trusted IP range: http://85.12.25.95
O15 - Trusted IP range: http://202.67.220.227
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - http://www.lotrdvd.com/dvdkey/extended_dvd…ds/iaieplay.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {262F1E21-510D-4FB3-9F40-F6C505CB2A59} (VacPro.canada_ver3_son) - http://www.advnt01.com/dialer/canada_ver3_son.CAB
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24bdea51b4f0fe…ip/RdxIE601.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - http://infoship/Printing/setup.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {683DFF0F-331F-44D2-B69B-46D7BFB58F32} (VacPro.canada_ver3) - http://www.advnt01.com/dialer/canada_ver3.CAB
O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) - http://data6.archives.ca/mrsidi_cab/MrSIDI.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsanik1/msrdp.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…inematycoon.cab
O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: srrcfetx - srrcfetx.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: wkrrdnfr - wkrrdnfr.dll (file missing)
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe

also since this started a trojen has started popping up called generic or something like that

It's going to be very difficult to identify the infection if you don't give me the information that AVG is giving you.
If AVG tells you what the infection is and the file names and paths, make a note of them and include them in your next reply.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware 7.5 from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click ewido-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to know how to boot into Safe Mode.
Instructions can be found here.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Go to Start > Control Panel > Add/Remove Programs and remove the following, and then reboot your PC:

VSToolBar

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R3 - URLSearchHook: (no name) - - (no file)

O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: (no name) - {1109F444-EFA0-446F-BFB0-F755B1278153} - (no file)
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\mcxwlgsd.dll (file missing)
O2 - BHO: ohb Class - {285B5CCD-C3F0-4EB6-9632-7D0A3C3AF824} - C:\WINDOWS\system32\hsrb.dll (file missing)
O2 - BHO: (no name) - {291EBEDD-5645-48B7-B0D1-805582EC3B29} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {2E5C7C61-C031-4CC9-8A4D-AAA00C57F635} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {4A22E1FE-5793-490D-8259-9F4F0CABF117} - (no file)
O2 - BHO: Quick! - {4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} - C:\PROGRA~1\quickbar\quickbar.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {54AAEFC7-9717-4A6C-A676-A1E04DC1D34D} - (no file)
O2 - BHO: (no name) - {7AE965D0-E0D3-4C94-8E1A-2ABCD63905EC} - (no file)
O2 - BHO: (no name) - {7C1ADA1D-3AA1-4ACF-AE4B-F80B30EDEDC2} - (no file)
O2 - BHO: (no name) - {80A6BD25-4DC6-4549-AD72-A2E39D69D7B7} - (no file)
O2 - BHO: (no name) - {AF01BD28-6E72-4D9E-A333-8E8C0B245236} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {B04AEE3A-FADF-47A8-97D0-E68FE029E8C1} - C:\WINDOWS\ServicePackFiles\rulloe.dll (file missing)
O2 - BHO: (no name) - {B7A016B6-127C-4C94-A53A-AF9082D4FB2c} - C:\WINDOWS\system32\hntutrnq.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll

O4 - HKCU\..\Run: [SysProtect Free] "C:\Program Files\SysProtect Free\USYP.exe" /min

O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} -
O16 - DPF: {262F1E21-510D-4FB3-9F40-F6C505CB2A59} (VacPro.canada_ver3_son) - http://www.advnt01.com/dialer/canada_ver3_son.CAB
O16 - DPF: {683DFF0F-331F-44D2-B69B-46D7BFB58F32} (VacPro.canada_ver3) - http://www.advnt01.com/dialer/canada_ver3.CAB
O16 - DPF: {DE910060-8EFB-44B9-B492-75180696643F} (iiittt Class) - http://www.hotsearchbar.com/toolbar30/hsrb.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://download.games.yahoo.com/games/web_…aploader_v6.cab

O20 - Winlogon Notify: srrcfetx - srrcfetx.dll (file missing)
O20 - Winlogon Notify: wkrrdnfr - wkrrdnfr.dll (file missing)


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Boot into Safe Mode.

3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

6) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG Anti-Spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG Anti-Spyware.

7) Remove any/all of the following files/folders that you can find:

Folders

C:\Program Files\VSToolbar
C:\Program Files\SysProtect Free


As an example:
To delete C:\WINDOWS\system32\foldertogo
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on foldertogo and from the menu that appears, click on 'Delete'


8) Boot into Normal Mode.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

EDIT: Do this as well before you run HJT and create the logs:

Download DelDomains.inf from here and save it to your Desktop.
* If you use Firefox, right click the link and from the menu that appears, click on Save Link As… *

Right click on DelDomains.inf and from the menu that appears, click on Install.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Post a new HJT log, the AVG log AND a description of how your PC is running.
Also, run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
here is the AVG log ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 1:27:00 PM 10/21/2006 + Scan result: C:\WINDOWS\azesearch.bmp -> Adware.Azesearch : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\ftppxpen.dll -> Adware.BHO : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\qsvxxwvb.dll -> Adware.BHO : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP935\A0177014.dll/bi.dll -> Adware.BiSpy : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP935\A0177014.dll/preInsBI.exe -> Adware.BiSpy : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\ClrSch\FNuninstaller.EXE -> Adware.ClearSearch : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\_hsrb -> Adware.HotBar : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\_hsrb\kkws -> Adware.HotBar : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\_hsrb\ppops -> Adware.HotBar : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\_hsrb\ssites -> Adware.HotBar : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{285B5CCD-C3F0-4EB6-9632-7D0A3C3AF824} -> Adware.iLookup : Cleaned with backup (quarantined). C:\Documents and Settings\Bob\Local Settings\Temp\temp.frEC58\NavHelper\v2.0.4d\NHUpdater.exe -> Adware.NavExcel : Cleaned with backup (quarantined). C:\Documents and Settings\Bob\Local Settings\Temp\temp.frEC58\NavHelper\v2.0.4d\NHelper.dll -> Adware.NavExcel : Cleaned with backup (quarantined). C:\Documents and Settings\Bob\Local Settings\Temp\temp.frEC58\NavHelper\v2.0.4d\navapp.exe -> Adware.NavExcel : Cleaned with backup (quarantined). C:\Documents and Settings\Bob\My Documents\Downloads\uninstall3_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\Desktop Angel\NNEZTX638.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\Hogwarts4 Active\NNEZTA388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\Images of Spring\NNEZTA388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\aditltheme.zip\NNEZTA388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\ahatfullofluck.zip\nnez_388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\canadadaywp.zip\NNWDAC638.EXE -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\earthandskyscr.zip\nnez_388.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP933\A0176865.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP933\A0176866.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP933\A0176871.dll -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall5_48.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_10.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_22-1.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall6_98.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\WINDOWS\NDNuninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). F:\Bob's Folder\Downloads\uninstall3_88.exe -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\.DEFAULT\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-18\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4A2AACF3-ADF6-11D5-98A9-00E018981B9E} -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{4E7BD74F-2B8D-469E-C0FF-FD67B79CAF2C} -> Adware.NewDotNet : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\New.net -> Adware.NewDotNet : Cleaned with backup (quarantined). C:\Program Files\filesubmit\Hogwarts4 Active\TBEZA127Q.exe -> Adware.Quick : Cleaned with backup (quarantined). C:\Program Files\filesubmit\Images of Spring\TBEZA127Q.exe -> Adware.Quick : Cleaned with backup (quarantined). C:\Program Files\filesubmit\aditltheme.zip\TBEZA127Q.exe -> Adware.Quick : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\rkinstaller.exe -> Adware.Relevant : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP929\A0173402.dll -> Adware.RK : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP929\A0173403.exe -> Adware.RK : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP934\A0176952.exe -> Adware.RK : Cleaned with backup (quarantined). C:\RECYCLER\S-1-5-21-3557724101-2737143765-978404184-1007\Dc576.exe -> Adware.Sahat : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP931\A0176521.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP931\A0176522.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP931\A0176523.exe -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP931\A0176524.exe -> Adware.SaveNow : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\WUSN.1 -> Adware.SaveNow : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP921\A0168794.dll -> Adware.Searchcolours : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP938\A0179199.dll -> Adware.Searchcolours : Cleaned with backup (quarantined). HKLM\SOFTWARE\SearchRelevancy -> Adware.SearchRelevancy : Cleaned with backup (quarantined). HKLM\SOFTWARE\SearchRelevancy\Update -> Adware.SearchRelevancy : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SWRT01.RT -> Adware.SecondThought : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\SWRT01.RT\Clsid -> Adware.SecondThought : Cleaned with backup (quarantined). C:\Program Files\Common Files\Sandlot Shared\slghex.dll -> Adware.SpywareStorm : Cleaned with backup (quarantined). C:\Program Files\Super Slyder\slghex.dll -> Adware.SpywareStorm : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\AppID\{4F5E5D72-C915-4f3b-908B-527D064B0FAA} -> Adware.SysProtect : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\CLSID\{EF130E77-0A34-4365-BFB7-218FD3DDCD5F} -> Adware.SysProtect : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9} -> Adware.SysProtect : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\TypeLib\{7EACF70B-302F-4049-AC68-2D62EB43E473} -> Adware.SysProtect : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\BO2802040113.dll -> Adware.VirtualBouncer : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\BO2802040128.exe -> Adware.VirtualBouncer : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\BO2803040128.dll -> Adware.VirtualBouncer : Cleaned with backup (quarantined). C:\WINDOWS\SYSTEM32\BO2803040128.exe -> Adware.VirtualBouncer : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{827DC836-DD9F-4A68-A602-5812EB50A834} -> Adware.Virtumonde : Cleaned with backup (quarantined). HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\Common.Buttons -> Adware.WebSearch : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.1\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.2\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.3\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.4\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.5\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.6\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\WinServAdX.dll -> Adware.WinAD : Cleaned with backup (quarantined). C:\temp\WinCtlAdInstPack.exe -> Adware.WinAD : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP885\A0148871.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP885\A0148882.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP885\A0148885.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP912\A0163022.dll -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP912\A0163028.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP912\A0163033.exe -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf\Enum -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf\Security -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Enum -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SYSTEM\CurrentControlSet\Services\vspf_hk\Security -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKU\S-1-5-21-3557724101-2737143765-978404184-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2178F3FB-2560-458F-BDEE-631E2FE0DFE4} -> Adware.WinAntiVirus : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\VacPro.canada_ver3 -> Dialer.Generic : Cleaned with backup (quarantined). HKLM\SOFTWARE\Classes\VacPro.canada_ver3\Clsid -> Dialer.Generic : Cleaned with backup (quarantined). C:\Documents and Settings\Kelly 2\Local Settings\Temporary Internet Files\Content.IE5\O1QZWH67\popup[1].htm -> Hijacker.Agent.a : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\cxuerwxq.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\jgjoqxok.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\luddxkwl.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\qdxyciyf.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\renmotgb.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\skkuevdh.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temp\vjtsshrh.dll -> Logger.VBStat.e : Cleaned with backup (quarantined). C:\Documents and Settings\Bob\Local Settings\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\Cache\ACD008F5d01 -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup (quarantined). C:\Documents and Settings\Kelly 2\Local Settings\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\Cache\ACD008F5d01 -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup (quarantined). C:\Documents and Settings\Lynn\Local Settings\Temporary Internet Files\Content.IE5\C7QFM1CX\SysProtectScannerInstall[1].cab/USYP_0002_N91M1708NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\CONFLICT.1\USYP_0002_N91M1708NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\USYP_0002_N91M0908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). C:\WINDOWS\Downloaded Program Files\USYP_0002_N91M1708NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined). :mozilla.30:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.31:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.144:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.153:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.156:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.467:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.46:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.47:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.48:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.49:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.50:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.51:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.52:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.53:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.544:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.545:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.54:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.55:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.56:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.57:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.58:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.59:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.60:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.61:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.627:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.62:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.64:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@chumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@chumtv.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@cratebarrel.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@powellsbooks.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@serif.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@snagajob.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@taconycorporation.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. :mozilla.382:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.383:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned. :mozilla.289:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.290:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Adserver : Cleaned. :mozilla.39:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.40:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.41:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.42:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Advertising : Cleaned. :mozilla.27:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. :mozilla.65:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Bestoffersnetworks : Cleaned. :mozilla.75:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Bfast : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Bpath : Cleaned. :mozilla.125:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.72:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.75:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned. :mozilla.126:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.69:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.70:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.71:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly [removed][2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.158:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.535:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.536:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.537:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.538:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.539:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.344:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.345:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned. :mozilla.160:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.161:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.87:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@com[2].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@com[2].txt -> TrackingCookie.Com : Cleaned. :mozilla.420:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.421:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned. :mozilla.33:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned. :mozilla.446:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.447:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.448:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.119:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.120:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.76:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.77:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned. :mozilla.68:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.74:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.76:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned. :mozilla.133:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.134:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.135:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.39:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.42:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned. :mozilla.168:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.169:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.170:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.171:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.172:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.213:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.214:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.215:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.297:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.255:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.256:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.257:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.258:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.259:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.260:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.261:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.262:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.263:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.264:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.265:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.266:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.105:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.106:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.111:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.112:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.113:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Overture : Cleaned. :mozilla.626:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@overture[1].txt -> TrackingCookie.Overture : Cleaned. :mozilla.239:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.240:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.241:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.242:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.243:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.86:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.87:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.88:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.36:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.84:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.88:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned. :mozilla.38:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.424:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Realtracker : Cleaned. :mozilla.10:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.10:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.11:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.11:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.12:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.12:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.12:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.13:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.13:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.13:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.14:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.14:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.14:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.15:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.15:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.15:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.16:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.16:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.17:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.17:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.18:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.18:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.19:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.20:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.21:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.23:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.24:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.26:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.27:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.28:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.29:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.30:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.6:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.6:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.7:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.8:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.8:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.9:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.9:C:\Documents and Settings\Lynn\Application Data\Mozilla\Firefox\Profiles\ttc8uos2.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly [removed][2].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned. :mozilla.28:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.29:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.61:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.62:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.63:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.64:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.66:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.452:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.453:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned. :mozilla.135:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Bob\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.313:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Starware : Cleaned. :mozilla.314:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Starware : Cleaned. :mozilla.353:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Starware : Cleaned. :mozilla.364:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@starware[1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned. :mozilla.226:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.227:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.227:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.228:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.229:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.230:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.231:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.232:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.132:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.136:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.73:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.74:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Lynn\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned. :mozilla.117:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.79:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Trafic : Cleaned. :mozilla.127:C:\Documents and Settings\Bob\Application Data\Mozilla\Firefox\Profiles\8qks7m3k.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.68:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Kelly 2\Cookies\kelly 2@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. :mozilla.101:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.102:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.103:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.104:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.105:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.106:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Valuead : Cleaned. :mozilla.334:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.335:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.336:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.540:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.541:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Profiles\qz4nyc4v.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned. C:\Documents and Settings\Bob\Cookies\bob@yadro[1].txt -> TrackingCookie.Yadro : Cleaned. C:\Documents and Settings\Lynn\Cookies\lynn@yadro[2].txt -> TrackingCookie.Yadro : Cleaned. :mozilla.357:C:\Documents and Settings\Kelly 2\Application Data\Mozilla\Firefox\Prof
HijackThis log

Logfile of HijackThis v1.99.1
Scan saved at 1:34:28 PM, on 10/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\drivers\KodakCCS.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\ScsiAccess.EXE
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\BCMSMMSG.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\findstuff.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.seekerbar.com/ie.aspx?tb_id=50154
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [POINTER] point32.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [navapp] C:\Program Files\NavExcel\NavHelper\v2.0.4d\navapp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealPlayer\realplay.exe" /RunUPGToolCommandReBoot
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 4.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\vpngui.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) - https://www.epost.ca/printing/smsx.cab
O16 - DPF: {2042B57E-6336-459E-B7CE-2A0F6C9E6AF8} (IEPlayInterface Class) - http://www.lotrdvd.com/dvdkey/extended_dvd…ds/iaieplay.dll
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/housecal…ivex/hcImpl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/24bdea51b4f0fe…ip/RdxIE601.cab
O16 - DPF: {62BC5DB2-0044-4040-B366-D628F3CFD551} (PowerTeam HTML Printing Behavior) - http://infoship/Printing/setup.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) - http://data6.archives.ca/mrsidi_cab/MrSIDI.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsanik1/msrdp.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://download.games.yahoo.com/games/web_…outLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://download.games.yahoo.com/games/web_…inematycoon.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: ScsiAccess - Unknown owner - C:\WINDOWS\System32\ScsiAccess.EXE
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
program list file A Series of Unfortunate Events (remove only) Absolute Fit-trix 1.0.2 Ad-Aware SE Personal aditltheme.zip Adobe Acrobat - Reader 6.0.2 Update Adobe Acrobat 4.0, 5.0 Adobe Atmosphere Player for Acrobat and Adobe Reader Adobe Download Manager 1.2 (Remove Only) Adobe Photoshop 5.0 Limited Edition Adobe Photoshop 7.0 Adobe Photoshop Album 2.0 Starter Edition Adobe Reader 6.0.1 ahatfullofluckwp.zip ArcSoft PhotoImpression aspi Atlantis (remove only) Autumn Cardinals_SS Autumn Flight Autumn Glory Active autumncardinalsss.exe AVG Anti-Spyware 7.5 AVG Free Edition BCM V.92 56K Modem Beautiful Portrait Humming Bird Photography Bejeweled 2 Deluxe 1.0 BestOn Software bookoflife.zip Canon i560 CCHelp CCScore Celestrial Birth Active Christmas Lights Christmas Ornaments Christmas Time ClarisWorks 4.0 Classic PhoneTools Cold as Ice Wallpaper Crime Puzzle 1.0 Da Vinci`s Secret (remove only) Dell Digital Jukebox Driver Dell Media Experience Dell ResourceCD Dell Solution Center Dell Support 5.0.0 (766) Desktop Angel DVDSentry earthandskyscr.zip Easy CD Creator 5 Platinum EKS Sherlock 5.0 eMazing Mazes Emerald Skies End Of A Long Journey 1024x768 EPSON Copy Utility EPSON PERF 1670 Guide EPSON Photo Print EPSON Scan EPSON Smart Panel ESSAdpt ESSANUP ESSBrwr ESSCAM ESSCDBK ESScore ESSgui ESShelp ESSini ESSPCD ESSstore ESSTUTOR ESSvpaht ESSvpot Eye Candy 4000 eZshopper Family Feud Hollywood Edition (remove only) Family Tree Maker 9.0 Google Talk (remove only) Google Toolbar for Internet Explorer Happy Holiday Harry Potter Harry Potter and the Prisoner of Azkaban™ Harry Potter II Harry Potter Lumos Screen Saver Hidden Expedition - Titanic (remove only) Hidden Expedition Titanic (remove only) HighMAT Extension to Microsoft Windows XP CD Writing Wizard Hijackthis 1.99.1 HijackThis 1.99.1 Hogwarts4 Active HummingbirdHaven2WP ICQ Images of Spring Incrediball Level Pack 1 1.0 Intel® PRO Network Adapters and Drivers Intel® PROSet InterActual Player Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Java 2 Runtime Environment, SE v1.4.2 Jewel Quest Kodak EasyShare software KSU Lighthouse Active LimeWire LimeWire 4.10.3 Lizardtech DjVu Control Lizardtech Express View Browser Plug-in Logitech Gaming Software Looking For Santa LOTR The Return of the King tm Macromedia Flash Player 8 Macromedia Shockwave Player Magic Ball 2 New Worlds Magic Vines (remove only) magical4 Screen Saver Mahjong Quest Mahjongg Artifacts Mahjongg XP Championship 2006 Platinum Edition Merry Christmas Darling Screen Saver Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB886903) Microsoft Data Access Components KB870669 Microsoft Encarta Encyclopedia Standard 2004 Microsoft Money 2004 Microsoft Money 2004 System Pack Microsoft Office 97, Professional Edition Microsoft Windows Media Video 9 VCM Microsoft Word 2000 Modem Helper Moraff's Maximum MahJongg 1.0 MrSID Browser Plug-in 1.3 MSN MuggleNet.com's Harry Potter and the Prisoner of Azkaban Screensaver Music Visualizer Library 1.4.00 MUSICMATCH® Jukebox Mystery Case Files - Huntsville (remove only) Mystery Case Files - Prime Suspects (remove only) Net MD Simple Burner Night Before Christmas Saver Notifier NVIDIA Windows 2000/XP Display Drivers OpenMG Limited Patch 3.2-03-02-21-08 OpenMG Limited Patch 3.2-03-04-14-02 OpenMG Limited Patch 3.2-03-04-17-02 OpenMG Secure Module 3.2 OTtBP Paint Shop Pro 7 PC CameraQ PCDLNCH PICVideo Codecs Pix-Fit 1.0 PowerDVD Pretty Good MahJongg version 1.11 Pretty Good Solitaire - Additional Card Sets 1.0 Pretty Good Solitaire - Christmas Card Set 1.0.2 Pretty Good Solitaire - Elegant Card Set 1.1 Pretty Good Solitaire - Halloween Card Set 1.0 Pretty Good Solitaire version 9.1.0 Princess Diaries SE Screen Saver Pumpkin Patch Babies Pumpkin Pines Quick! Toolbar QuickTax 2003 Standard QuickTax 2004 QuickTax 2005 RealArcade RealPlayer Red Hawk RollerCoaster Tycoon Deluxe Ruby Throated Hummingbird 1024x768 Sandlot Games Client Services Santa Balls ScanToWeb Security Update for Step By Step Interactive Training (KB898458) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB925486) SFR SFR2 Shockwave Snow Bench Sonic DLA Sonic RecordNow! Sonic Update Manager SonicStage 1.5.53 Sound Blaster Live! Spybot - Search & Destroy 1.4 Sunset River with Birds Super Slyder 1.09 SysProtect [removed] The Da Vinci Code (remove only) The Hobbit™ The Muse Wallpaper The Polar Express Screen Saver The Sims 2 The Sims 2 Family Fun Stuff The Sims 2 HomeCrafter Plus The Sims 2 Nightlife The Sims 2 University thunderonthef.zip tranquilty.exe Tumblebugs (remove only) Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) USB MassStorage CardReader Viewpoint Manager (Remove Only) Viewpoint Toolbar (Remove Only) Virtual Villagers (remove only) VPN Client waithalow1024wp.zip Web Savings from Ebates WebSearch Tools Weeping Willow Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Live Messenger Windows Media Format Runtime Windows Media Player 10 Windows SR 5.0 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 Winnie the Pooh 010 Witches Home 1024x768 WordPerfect Office 11 Yahoo! Messenger Zoo Tycoon: Complete Collection

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI