This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help with scans requested (please!)

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi everyone,

I've posted my logs from hijackthis, AVG virus scan, and spySweep below. I still have some annoying pop-ups and malware, and want to make my computer 100% clean. Any help any of you can give me would be very much appreciated!!!

Thanks! :)
Abby

Logfile of HijackThis v1.99.1
Scan saved at 9:33:10 PM, on 10/16/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5346.0005)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\PROGRA~1\SPSS\spsswin.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\hijack this\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ucsbuxa.ucsb.edu:9000/ucsblibrary
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NI.USYP_0001_N85M2606] "C:\WINDOWS\Downloaded Program Files\USYP_0001_N85M2606NetInstaller.exe" -nag
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL; Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\VIRUSfighter\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 9:13:45 PM 10/15/2006

+ Scan result:



C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP208\A0047913.dll -> Adware.Virtumonde : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP252\A0055505.dll -> Adware.Virtumonde : No action taken.
C:\WINDOWS\system32\fmfhfiot.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\WINDOWS\system32\nafxeoju.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\WINDOWS\system32\oonboahb.exe -> Not-A-Virus.Downloader.Win32.WinFixer.i : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP240\snapshot\MFEX-1.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP240\snapshot\MFEX-5.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP241\snapshot\MFEX-1.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP241\snapshot\MFEX-5.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP242\snapshot\MFEX-1.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP242\snapshot\MFEX-5.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP243\snapshot\MFEX-1.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP243\snapshot\MFEX-5.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP244\snapshot\MFEX-1.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP244\snapshot\MFEX-5.DAT/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\system32\aatayaip.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\baosbwyh.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\fagbwvle.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\mwjljiuh.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\odvwvjvt.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\qnoejjcl.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\sraxqeyx.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\wbkjohjx.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
C:\WINDOWS\system32\wgylsjmy.exe -> Not-A-Virus.Downloader.Win32.WinFixer.r : No action taken.
:mozilla.15:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.16:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.17:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.18:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.20:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.21:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.22:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.23:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.24:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.25:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.26:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.370:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.382:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.425:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.596:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.2o7 : No action taken.
:mozilla.292:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.295:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adbrite : No action taken.
:mozilla.375:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Addynamix : No action taken.
:mozilla.626:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.627:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adjuggler : No action taken.
:mozilla.308:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.309:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.310:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.311:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.312:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.313:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adrevolver : No action taken.
:mozilla.159:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Adserver : No action taken.
:mozilla.222:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.223:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.224:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.225:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.226:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.227:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Advertising : No action taken.
:mozilla.53:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Atdmt : No action taken.
:mozilla.589:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Bfast : No action taken.
:mozilla.246:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Bluestreak : No action taken.
:mozilla.439:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Bridgetrack : No action taken.
:mozilla.334:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Burstbeacon : No action taken.
:mozilla.315:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.316:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.317:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Burstnet : No action taken.
:mozilla.105:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.106:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.107:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.108:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.109:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.110:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.111:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Casalemedia : No action taken.
:mozilla.293:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Com : No action taken.
:mozilla.294:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Abby Prestin\Cookies\abby_prestin@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
:mozilla.54:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.479:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.480:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.481:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Falkag : No action taken.
:mozilla.198:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.199:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.200:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.201:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.202:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Fastclick : No action taken.
:mozilla.274:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Googleadservices : No action taken.
:mozilla.376:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.433:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.617:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.622:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Hitbox : No action taken.
:mozilla.55:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Mediaplex : No action taken.
:mozilla.318:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.505:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Overture : No action taken.
:mozilla.228:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.229:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.230:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.231:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Pointroll : No action taken.
:mozilla.149:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.150:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.151:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.152:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.153:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.154:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.155:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.156:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Reliablestats : No action taken.
:mozilla.377:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.378:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.379:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.380:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.381:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Serving-sys : No action taken.
:mozilla.350:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Sexcounter : No action taken.
:mozilla.351:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Sexcounter : No action taken.
:mozilla.549:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Smartadserver : No action taken.
:mozilla.542:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.543:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.544:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Specificclick : No action taken.
:mozilla.402:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.403:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.404:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Starware : No action taken.
:mozilla.485:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.486:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.487:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Statcounter : No action taken.
:mozilla.145:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.336:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.35:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.36:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.37:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.38:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.44:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tacoda : No action taken.
:mozilla.203:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.204:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.205:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.206:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.207:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.208:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.209:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.210:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Trafficmp : No action taken.
:mozilla.161:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.165:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.
:mozilla.602:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.603:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.604:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Valuead : No action taken.
:mozilla.187:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.188:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.189:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.190:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Yieldmanager : No action taken.
:mozilla.100:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.96:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.97:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.98:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Zedo : No action taken.
:mozilla.99:C:\Documents and Settings\Abby Prestin\Application Data\Mozilla\Firefox\Profiles\kekuqtr2.a\cookies.txt -> TrackingCookie.Zedo : No action taken.


::Report end

10:22 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
10:21 PM: Your definitions are up to date.
10:21 PM: Automated check for program update in progress.
9:36 PM: None
9:36 PM: Traces Found: 0
9:36 PM: Full Sweep has completed. Elapsed time 00:17:51
9:36 PM: File Sweep Complete, Elapsed Time: 00:15:03
9:36 PM: Warning: Failed to access drive D:
9:35 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\application data\mozilla\firefox\profiles\kekuqtr2.a\parent.lock". The operation completed successfully
9:22 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
9:21 PM: Starting File Sweep
9:21 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
9:21 PM: Starting Cookie Sweep
9:21 PM: Registry Sweep Complete, Elapsed Time:00:00:13
9:21 PM: Starting Registry Sweep
9:21 PM: Memory Sweep Complete, Elapsed Time: 00:02:28
9:18 PM: Starting Memory Sweep
9:18 PM: Sweep initiated using definitions version 782
9:18 PM: Spy Sweeper 5.0.5.1286 started
9:18 PM: | Start of Session, Sunday, October 15, 2006 |
********
9:18 PM: | End of Session, Sunday, October 15, 2006 |
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
9:17 PM: Shield States
9:17 PM: Spyware Definitions: 782
9:16 PM: Spy Sweeper 5.0.5.1286 started
7:30 PM: Deletion from quarantine completed. Elapsed time 00:00:00
7:30 PM: Processing: zedo cookie
7:30 PM: Processing: specificclick.com cookie
7:30 PM: Processing: mygeek cookie
7:30 PM: Processing: trafficmp cookie
7:30 PM: Processing: falkag cookie
7:30 PM: Processing: qksrv cookie
7:30 PM: Processing: apmebf cookie
7:30 PM: Deletion from quarantine initiated
7:30 PM: Removal process completed. Elapsed time 00:00:10
7:30 PM: Quarantining All Traces: zedo cookie
7:30 PM: Quarantining All Traces: trafficmp cookie
7:30 PM: Quarantining All Traces: qksrv cookie
7:30 PM: Quarantining All Traces: mygeek cookie
7:30 PM: Quarantining All Traces: falkag cookie
7:30 PM: Quarantining All Traces: apmebf cookie
7:30 PM: Quarantining All Traces: specificclick.com cookie
7:30 PM: Removal process initiated
7:30 PM: Traces Found: 7
7:30 PM: Full Sweep has completed. Elapsed time 00:20:51
7:30 PM: File Sweep Complete, Elapsed Time: 00:15:05
7:30 PM: Warning: Failed to access drive D:
7:29 PM: Warning: Failed to read file "c:\documents and settings\abby prestin\local settings\temp\~df307a.tmp". "c:\documents and settings\abby prestin\local settings\temp\~df307a.tmp": File not found
7:29 PM: Warning: Failed to read file "c:\documents and settings\abby prestin\local settings\temp\~dfdffc.tmp". "c:\documents and settings\abby prestin\local settings\temp\~dfdffc.tmp": File not found
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dff239.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfdb15.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfdae6.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df8c4d.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df8c56.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df8c34.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfc5d.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df307a.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df88c.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\my documents\research\my stuff\thesis\~$esis outline.doc". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfdffc.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfb2a1.tmp". The operation completed successfully
7:29 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\acr198.tmp". The operation completed successfully
7:28 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfe302.tmp". The operation completed successfully
7:28 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\acr196.tmp". The operation completed successfully
7:28 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dfcf4b.tmp". The operation completed successfully
7:15 PM: Starting File Sweep
7:15 PM: Cookie Sweep Complete, Elapsed Time: 00:00:01
7:14 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@zedo[1].txt (ID = 3762)
7:14 PM: Found Spy Cookie: zedo cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@trafficmp[1].txt (ID = 3581)
7:14 PM: Found Spy Cookie: trafficmp cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@qksrv[2].txt (ID = 3213)
7:14 PM: Found Spy Cookie: qksrv cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@mygeek[1].txt (ID = 3041)
7:14 PM: Found Spy Cookie: mygeek cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\[removed][2].txt (ID = 2650)
7:14 PM: Found Spy Cookie: falkag cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@apmebf[2].txt (ID = 2229)
7:14 PM: Found Spy Cookie: apmebf cookie
7:14 PM: c:\documents and settings\abby prestin\cookies\[removed][2].txt (ID = 3400)
7:14 PM: Found Spy Cookie: specificclick.com cookie
7:14 PM: Starting Cookie Sweep
7:14 PM: Registry Sweep Complete, Elapsed Time:00:00:24
7:14 PM: Starting Registry Sweep
7:14 PM: Memory Sweep Complete, Elapsed Time: 00:04:59
7:09 PM: Starting Memory Sweep
7:09 PM: Sweep initiated using definitions version 782
7:09 PM: Spy Sweeper 5.0.5.1286 started
7:09 PM: | Start of Session, Sunday, October 15, 2006 |
********
9:12 PM: | End of Session, Saturday, October 14, 2006 |
9:05 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
8:05 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:07 PM: BHO Shield: found: nixkvyel.dll– BHO installation denied at user request
7:07 PM: BHO Shield: found: nixkvyel.dll– BHO installation denied at user request
7:07 PM: BHO Shield: found: nixkvyel.dll– BHO installation denied at user request
7:07 PM: BHO Shield: found: nixkvyel.dll– BHO installation denied at user request
7:05 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
2:32 PM: BHO Shield: found: – BHO installation denied at user request
2:31 PM: BHO Shield: found: – BHO installation denied at user request
1:48 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
1:05 PM: Deletion from quarantine completed. Elapsed time 00:00:00
1:05 PM: Processing: atwola cookie
1:05 PM: Processing: linkmedia
1:05 PM: Processing: linkmedia
1:05 PM: Deletion from quarantine initiated
1:05 PM: Removal process completed. Elapsed time 00:00:01
1:05 PM: Quarantining All Traces: atwola cookie
1:05 PM: Quarantining All Traces: linkmedia
1:05 PM: Removal process initiated
1:05 PM: Traces Found: 4
1:05 PM: Full Sweep has completed. Elapsed time 00:16:43
1:05 PM: File Sweep Complete, Elapsed Time: 00:14:16
1:05 PM: Warning: Failed to access drive D:
1:03 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\application data\mozilla\firefox\profiles\kekuqtr2.a\parent.lock". The operation completed successfully
12:51 PM: Starting File Sweep
12:51 PM: Cookie Sweep Complete, Elapsed Time: 00:00:00
12:51 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@atwola[1].txt (ID = 2255)
12:51 PM: Found Spy Cookie: atwola cookie
12:51 PM: Starting Cookie Sweep
12:51 PM: Registry Sweep Complete, Elapsed Time:00:00:12
12:51 PM: HKLM\system\currentcontrolset\services\nwsapagent\ (ID = 1729831)
12:51 PM: HKLM\system\controlset001\services\nwsapagent\ (ID = 1729695)
12:51 PM: HKLM\system\controlset001\enum\root\legacy_nwsapagent\ (ID = 1729645)
12:51 PM: Found Adware: linkmedia
12:50 PM: Starting Registry Sweep
12:50 PM: Memory Sweep Complete, Elapsed Time: 00:02:09
12:48 PM: Starting Memory Sweep
12:48 PM: Sweep initiated using definitions version 782
12:48 PM: Spy Sweeper 5.0.5.1286 started
12:48 PM: | Start of Session, Saturday, October 14, 2006 |
********
7:09 PM: | End of Session, Sunday, October 15, 2006 |
7:09 PM: BHO Shield: found: pxjqrrpn.dll– BHO installation denied at user request
6:53 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Operation: File Access
Target:
Source: C:\WINDOWS\SYSTEM32\IMAPI.EXE
5:54 PM: Tamper Detection
5:54 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
1:11 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
12:11 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
2:40 AM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
1:05 AM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Operation: Terminate
Target: C:\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPERUI.EXE
Source: C:\WINDOWS\SYSTEM32\CSRSS.EXE
12:27 AM: Tamper Detection
12:06 AM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Operation: File Access
Target:
Source: C:\WINDOWS\SYSTEM32\IMAPI.EXE
11:14 PM: Tamper Detection
11:05 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Operation: File Access
Target:
Source: C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
10:43 PM: Tamper Detection
10:21 PM: Your definitions are up to date.
10:21 PM: Automated check for program update in progress.
10:05 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
10:00 PM: None
10:00 PM: Traces Found: 0
10:00 PM: Full Sweep has completed. Elapsed time 00:47:50
10:00 PM: File Sweep Complete, Elapsed Time: 00:40:35
10:00 PM: Warning: Failed to access drive D:
9:59 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~dff9a2.tmp". The operation completed successfully
9:59 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df6317.tmp". The operation completed successfully
9:59 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df37af.tmp". The operation completed successfully
9:59 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\~df1cd0.tmp". The operation completed successfully
9:59 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\acr33b.tmp". The operation completed successfully
9:58 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\application data\mozilla\firefox\profiles\kekuqtr2.a\parent.lock". The operation completed successfully
9:58 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\acr339.tmp". The operation completed successfully
9:58 PM: Warning: Failed to open file "c:\documents and settings\abby prestin\local settings\temp\acr4c7.tmp". The operation completed successfully
9:19 PM: Starting File Sweep
9:19 PM: Cookie Sweep Complete, Elapsed Time: 00:00:03
9:19 PM: Starting Cookie Sweep
9:19 PM: Registry Sweep Complete, Elapsed Time:00:01:11
9:18 PM: Starting Registry Sweep
9:18 PM: Memory Sweep Complete, Elapsed Time: 00:05:44
9:12 PM: Starting Memory Sweep
9:12 PM: Sweep initiated using definitions version 782
9:12 PM: Spy Sweeper 5.0.5.1286 started
9:12 PM: | Start of Session, Saturday, October 14, 2006 |
********
12:48 PM: | End of Session, Saturday, October 14, 2006 |
12:48 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Keylogger Shield: On
BHO Shield: On
IE Security Shield: On
Alternate Data Stream (ADS) Execution Shield: On
Startup Shield: On
12:43 PM: Warning: The handle is invalid
Common Ad Sites Shield: Off
Hosts File Shield: On
Spy Communication Shield: On
ActiveX Shield: On
Windows Messenger Service Shield: On
IE Favorites Shield: On
Spy Installation Shield: On
Memory Shield: On
IE Hijack Shield: On
IE Tracking Cookies Shield: Off
12:43 PM: Shield States
12:43 PM: Spyware Definitions: 782
12:42 PM: Spy Sweeper 5.0.5.1286 started
10:20 PM: Your spyware definitions have been updated.
10:20 PM: Automated check for program update in progress.
10:19 PM: Sweep Status: 3 Items Found
10:19 PM: Traces Found: 3
10:19 PM: File Sweep Complete, Elapsed Time: 02:15:01
10:19 PM: Sweep Canceled
10:13 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
8:04 PM: Starting File Sweep
8:04 PM: Cookie Sweep Complete, Elapsed Time: 00:00:06
8:04 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@atwola[1].txt (ID = 2255)
8:04 PM: Found Spy Cookie: atwola cookie
8:04 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@atdmt[2].txt (ID = 2253)
8:04 PM: Found Spy Cookie: atlas dmt cookie
8:04 PM: c:\documents and settings\abby prestin\cookies\abby_prestin@advertising[2].txt (ID = 2175)
8:04 PM: Found Spy Cookie: advertising cookie
8:03 PM: Starting Cookie Sweep
8:03 PM: Registry Sweep Complete, Elapsed Time:00:01:06
8:02 PM: Starting Registry Sweep
8:02 PM: Memory Sweep Complete, Elapsed Time: 00:11:42
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:56 PM: The Spy Communication shield has blocked access to: WWW.DRIVECLEANER.COM
7:51 PM: Starting Memory Sweep
7:50 PM: Sweep initiated using definitions version 781
7:50 PM: Spy Sweeper 5.0.5.1286 started
7:50 PM: | Start of Session, Friday, October 13, 2006 |
********
7:33 PM: | End of Session, Thursday, October 12, 2006 |
6:58 PM: Your spyware definitions have been updated.
6:57 PM: Automated check for program update in progress.
6:57 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
2:23 AM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
1:23 AM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
Operation: File Access
Target:
Source: C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
1:08 AM: Tamper Detection
1:05 AM: None
1:05 AM: Traces Found: 0
1:05 AM: Full Sweep has completed. Elapsed time 00:41:07
1:05 AM: File Sweep Complete, Elapsed Time: 00:29:53
1:05 AM: Warning: Failed to access drive D:
1:03 AM: Warning: Failed to open file "c:\documents and settings\abby prestin\application data\mozilla\firefox\profiles\kekuqtr2.a\parent.lock". The operation completed successfully
12:35 AM: Starting File Sweep
12:35 AM: Cookie Sweep Complete, Elapsed Time: 00:00:00
12:35 AM: Starting Cookie Sweep
12:35 AM: Registry Sweep Complete, Elapsed Time:00:00:51
12:34 AM: Starting Registry Sweep
12:34 AM: Memory Sweep Complete, Elapsed Time: 00:09:45
12:24 AM: Starting Memory Sweep
12:24 AM: Sweep initiated using definitions version 780
12:24 AM: Spy Sweeper 5.0.5.1286 started
12:24 AM: | Start of Session, Thursday, October 12, 2006 |
********
7:50 PM: | End of Session, Friday, October 13, 2006 |
7:50 PM: BHO Shield: found: – BHO installation denied at user request
7:50 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
7:50 PM: BHO Shield: found: – BHO installation denied at user request
7:50 PM: BHO Shield: found: – BHO installation denied at user request
7:50 PM: BHO Shield: found: – BHO installation denied at user request
10:56 PM: Access to Hosts file blocked for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
9:57 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
8:57 PM: Access to Hosts file allowed for C:\PROGRAM FILES\GRISOFT\AVG ANTI-SPYWARE 7.5\AVGAS.EXE
8:26 PM: Deletion from quarantine completed. Elapsed time 00:00:00
8:26 PM: Processing: atlas dmt cookie
8:26 PM: Processing: specificclick.com cookie
8:26 PM: Processing: mygeek cookie
8:26 PM: Proc
Welcome to the forum :wavey:

Please do this.

Rename:

C:\hijack this\HijackThis.exe

To:

C:\hijack this\scanner.exe

Reboot, run it, and post a new log, into this thread.
:)
Logfile of HijackThis v1.99.1
Scan saved at 1:20:11 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Webroot\Spy Sweeper\SSU.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\hijack this\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ucsbuxa.ucsb.edu:9000/ucsblibrary
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {EFA55A35-7443-48D4-A483-C1F3522CB472} - C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NI.USYP_0001_N85M2606] "C:\WINDOWS\Downloaded Program Files\USYP_0001_N85M2606NetInstaller.exe" -nag
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintray
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O20 - Winlogon Notify: abknifo - C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll
O20 - Winlogon Notify: cbxvtrp - cbxvtrp.dll (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: winqne32 - winqne32.dll (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\VIRUSfighter\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Disable SpySweeper:
You have SpySweeper installed. While this is a great program, we need to temporarily disable (not uninstall) the program because it might stop our fix.
  • Open it click >Options over to the left then >program options>Uncheck "load at windows startup"
  • Over to the left click "shields" and uncheck all there.
  • Uncheck" home page shield".
  • Uncheck ''automatically restore default without notification".
After all of the fixes are complete it is very important that you enable SpySweeper again.

Copy and paste the contents of the quote box below into notepad.

Save it as file name: "fixme.reg" (not including the quotes). Save as file type: *All files* and save it on your Desktop.

REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NI.USYP_0001_N85M2606"=-


Then, locate fixme.reg on your desktop and it.

You will receive a prompt similar to: "Do you wish to merge the information into the registry?".

Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".

Download VundoFix.exe to your desktop from here:

VundoFix.exe

Don't run it yet.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)

O20 - Winlogon Notify: cbxvtrp - cbxvtrp.dll (file missing)

O20 - Winlogon Notify: winqne32 - winqne32.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Reboot.

1. Double-click VundoFix.exe to run it.
2. Click the Scan for Vundo button.
3. Once it's done scanning, click the Remove Vundo button.
4. You will receive a prompt asking if you want to remove the files, click YES.
5. Once you click yes, your desktop will go blank as it starts removing Vundo.
6. When completed, it will prompt that it will shutdown your computer, click OK.
7. Turn your computer back on.

Post a new HijackThis! log, along with the contents of this file:

C:\vundofix.txt


into this thread.
:)
Logfile of HijackThis v1.99.1
Scan saved at 6:03:14 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\BitTorrent\bittorrent.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\UStorSrv.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\hijack this\scanner.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://ucsbuxa.ucsb.edu:9000/ucsblibrary
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {75140CF2-4FF1-4257-A200-707C909F2215} - C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll (file missing)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" –force_start_minimized
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.net - {F4430FE8-2638-42e5-B849-800749B94EED} - C:\Program Files\PartyGaming.net\PartyPokerNet\RunPF.exe (file missing)
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Norman API-hooking helper (NipSvc) - Unknown owner - C:\VIRUSfighter\Nvc\BIN\nipsvc.exe (file missing)
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: UStorage Server Service - OTi - C:\WINDOWS\system32\UStorSrv.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe


VundoFix V6.2.6

Checking Java version…

Java version is 1.4.2.3

Java version is 1.5.0.2

Scan started at 5:56:03 PM 10/23/2006

Listing files found while scanning….

C:\WINDOWS\system32\argokyui.dll
C:\WINDOWS\system32\glhdepaw.dll
C:\WINDOWS\system32\igmrvciv.dll
C:\WINDOWS\system32\nixkvyel.dll
C:\WINDOWS\system32\nrxqynpv.dll
C:\WINDOWS\system32\ocsumxel.dll
C:\WINDOWS\system32\ohjyiuyp.dll
C:\WINDOWS\system32\pxjqrrpn.dll
C:\WINDOWS\system32\vmikypcm.dll
C:\WINDOWS\system32\aatayaip.exe
C:\WINDOWS\system32\baosbwyh.exe
C:\WINDOWS\system32\fagbwvle.exe
C:\WINDOWS\system32\fmfhfiot.exe
C:\WINDOWS\system32\idgogmwg.exe
C:\WINDOWS\system32\mtxqskch.exe
C:\WINDOWS\system32\mwjljiuh.exe
C:\WINDOWS\system32\nafxeoju.exe
C:\WINDOWS\system32\odvwvjvt.exe
C:\WINDOWS\system32\oonboahb.exe
C:\WINDOWS\system32\qnoejjcl.exe
C:\WINDOWS\system32\sraxqeyx.exe
C:\WINDOWS\system32\wbkjohjx.exe
C:\WINDOWS\system32\wgylsjmy.exe
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.ini
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak1
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak2

Beginning removal…

Attempting to delete C:\WINDOWS\system32\argokyui.dll
C:\WINDOWS\system32\argokyui.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\glhdepaw.dll
C:\WINDOWS\system32\glhdepaw.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\igmrvciv.dll
C:\WINDOWS\system32\igmrvciv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nixkvyel.dll
C:\WINDOWS\system32\nixkvyel.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\nrxqynpv.dll
C:\WINDOWS\system32\nrxqynpv.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ocsumxel.dll
C:\WINDOWS\system32\ocsumxel.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\ohjyiuyp.dll
C:\WINDOWS\system32\ohjyiuyp.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\pxjqrrpn.dll
C:\WINDOWS\system32\pxjqrrpn.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\vmikypcm.dll
C:\WINDOWS\system32\vmikypcm.dll Has been deleted!

Attempting to delete C:\WINDOWS\system32\aatayaip.exe
C:\WINDOWS\system32\aatayaip.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\baosbwyh.exe
C:\WINDOWS\system32\baosbwyh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fagbwvle.exe
C:\WINDOWS\system32\fagbwvle.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\fmfhfiot.exe
C:\WINDOWS\system32\fmfhfiot.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\idgogmwg.exe
C:\WINDOWS\system32\idgogmwg.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mtxqskch.exe
C:\WINDOWS\system32\mtxqskch.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\mwjljiuh.exe
C:\WINDOWS\system32\mwjljiuh.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\nafxeoju.exe
C:\WINDOWS\system32\nafxeoju.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\odvwvjvt.exe
C:\WINDOWS\system32\odvwvjvt.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\oonboahb.exe
C:\WINDOWS\system32\oonboahb.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\qnoejjcl.exe
C:\WINDOWS\system32\qnoejjcl.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\sraxqeyx.exe
C:\WINDOWS\system32\sraxqeyx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wbkjohjx.exe
C:\WINDOWS\system32\wbkjohjx.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\wgylsjmy.exe
C:\WINDOWS\system32\wgylsjmy.exe Has been deleted!

Attempting to delete C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll Has been deleted!

Attempting to delete C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.ini
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.ini Has been deleted!

Attempting to delete C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak1
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak2
C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\ofinkba.bak2 Has been deleted!

Performing Repairs to the registry.
Done!
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O2 - BHO: (no name) - {75140CF2-4FF1-4257-A200-707C909F2215} - C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Access\abknifo.dll (file missing)

Then click "Fix checked" and close Hijack This!.

Delete this file (if found):

C:\WINDOWS\Downloaded Program Files\USYP_0001_N85M2606NetInstaller.exe

That should do it. :thumbup:

How is it running?
:unsure:

Securing Your PC After An Attack
Thank you for choosing TomCoyote for your malware removal solutions.

M68 :)

Please read:
Securing Your PC After An Attack

This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI