This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

system integrity scan wizard popup & spyware removal wizard popup

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

good afternoon all. hoping someone can help me with this. i am trying to follow all the instructions given here on what to do before i post. my computer is killing me. my girlfriend was surfing and got an email from someone that has caused some major problems. any help would be greatly appreciated. here is my hijackthis log. thanks in advance!

pete

Logfile of HijackThis v1.99.1
Scan saved at 3:03:06 PM, on 10/21/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\Program Files\Microsoft ActiveSync\WCESMgr.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\WINDOWS\System32\HPZipm12.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\WINDOWS\system32\svchost.exe
F:\Documents and Settings\Peter\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - F:\WINDOWS\system32\jfrnxmmh.dll (file missing)
O2 - BHO: (no name) - {3E19C055-8B4A-82DE-1B14-0311D0EC8104} - F:\WINDOWS\system32\ixrivkf.dll
O2 - BHO: (no name) - {4D2BA316-62E7-63A1-9506-00FCACD969A6} - F:\WINDOWS\system32\igmeocj.dll (file missing)
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - F:\WINDOWS\system32\nsk5A.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - F:\WINDOWS\system32\ixt0.dll (file missing)
O2 - BHO: (no name) - {E0914383-B390-42DC-88D9-5063B9D08223} - F:\WINDOWS\system32\vtutu.dll (file missing)
O2 - BHO: AD Rotator - {EEC590D8-0A3C-4464-BB20-25A4747992F9} - F:\WINDOWS\system32\adrotate.dll (file missing)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [ixrivkf.dll] F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ixrivkf.dll,egemvob
O4 - HKLM\..\Run: [wrzd06fd] RUNDLL32.EXE w064435b.dll,n 005d06f800000002064435b
O4 - HKLM\..\Run: [IpWins] F:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "F:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
here is a new scan when i renamed hijackthis.exe. please help someone!

Logfile of HijackThis v1.99.1
Scan saved at 7:38:04 PM, on 10/23/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Internet Explorer\iexplore.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\WINDOWS\System32\HPZipm12.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Documents and Settings\Peter\Desktop\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - F:\WINDOWS\system32\jfrnxmmh.dll (file missing)
O2 - BHO: (no name) - {3E19C055-8B4A-82DE-1B14-0311D0EC8104} - F:\WINDOWS\system32\ixrivkf.dll
O2 - BHO: (no name) - {4D2BA316-62E7-63A1-9506-00FCACD969A6} - F:\WINDOWS\system32\igmeocj.dll (file missing)
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - F:\WINDOWS\system32\nsl6.dll
O2 - BHO: (no name) - {a43385f0-7113-496d-96d7-b9b550e3fcca} - F:\WINDOWS\system32\ixt0.dll (file missing)
O2 - BHO: (no name) - {E0914383-B390-42DC-88D9-5063B9D08223} - F:\WINDOWS\system32\vtutu.dll (file missing)
O2 - BHO: AD Rotator - {EEC590D8-0A3C-4464-BB20-25A4747992F9} - F:\WINDOWS\system32\adrotate.dll (file missing)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [ixrivkf.dll] F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ixrivkf.dll,egemvob
O4 - HKLM\..\Run: [wrzd06fd] RUNDLL32.EXE w064435b.dll,n 005d06f800000002064435b
O4 - HKLM\..\Run: [IpWins] F:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "F:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Hello and Welcome to the forum.

This is what I suggest you do.

Please do not delete anything unless instructed to.

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
This program is for XP and Windows 2000 only
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

Note:
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time.

Even if you've already run these, make SURE they're up-to-date and run per instructions.

Make sure you have the up-to-date versions of Spybot V 1.4 and Ad-aware SE Build 1.06 . All are free and available below.

Download Spybot, install and update. Then download Ad-aware, install, and update.

Spybot:

Install the program and launch it.

Go to Start > Programs >Spybot > Search & Destroy and choose Spybot S&D

Close ALL windows except Spybot S&D
Click the button to "Search for Updates" and download and install the Updates.
Next click the button "Check for Problems"
When Spybot is complete, it will be showing "RED" (RED) entries "BLACK" entries and "GREEN" (GREEN) entries in the window
Put a check mark beside the RED (RED) entries ONLY.
Choose "Fix Selected Problems" and allow Spybot to fix the RED (RED) entries.

Ad-Aware FULL SCAN:

Install the program and launch it.

1. Launch Ad-Aware SE and run the WebUpdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)
2. Set up the Configurations as follows:
– Click the Gear wheel at the top of the Ad-Aware window
– Click General > Safety & Settings: Check (Green) all three.
– Click Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion".
3. Click "Proceed"
4. Click "Scan Now"
5. Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
6. Select "Search for low-risk threats"
7. Run the scanner using the Full Scan (Perform full system scan) mode.
8. When the scan has completed, select Next.
9. In the Scanning Results window, select the "Scan Summary" tab.
10. Check the box next to each "target family" you wish to remove.
11. Click next > Click OK.



Next:

Download AVG Anti-Spyware from HERE and save that file to your
desktop.
This is a 30 day trial of the program
  • Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
    and double-click it to launch the set up program.
  • Once the setup is complete you will need run ewido and update the definition
    files.
  • On the main screen select the icon "Update" then select the "
    Update now
    " link.
    • Next select the "Start Update" button, the update will start and a
      progress bar will show the updates being installed.
  • Once the update has completed select the "Scanner" icon at the top of
    the screen, then select the "Settings" tab.
  • Once in the Settings screen click on "Recommended actions" and then
    select ""Quarantine".".
  • Under "Reports"
    • Select "Automatically generate report after every scan"
    • Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
  • Reboot your computer into SafeMode. You can do this by restarting
    your computer and continually tapping the F8 key until a menu appears.

    Use your up arrow key to highlight SafeMode then hit enter.
    IMPORTANT: Do not open any other windows or
    programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
  • Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
  • Select the "Scanner" icon at the top and then the "Scan" tab
    then click on "Complete System Scan".
  • ewido will now begin the scanning process, be patient this may take a little
    time.
    Once the scan is complete do the following:
  • If you have any infections you will prompted, then select "Apply all
    actions
    "
  • Next select the "Reports" icon at the top.
  • Select the "Save report as" button in the lower left hand of the
    screen and save it to a text file on your system (make sure to remember where
    you saved that file, this is important).
  • Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
    results of the AVG Anti-Spyware report scan along with a new HijackThis log.
here you go. please help!

Logfile of HijackThis v1.99.1
Scan saved at 6:48:25 PM, on 10/26/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\WINDOWS\system32\rundll32.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\WINDOWS\System32\HPZipm12.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
F:\Program Files\Mozilla Firefox\firefox.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\Documents and Settings\Peter\Desktop\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - F:\WINDOWS\system32\jfrnxmmh.dll (file missing)
O2 - BHO: (no name) - {3E19C055-8B4A-82DE-1B14-0311D0EC8104} - F:\WINDOWS\system32\ixrivkf.dll
O2 - BHO: (no name) - {4D2BA316-62E7-63A1-9506-00FCACD969A6} - F:\WINDOWS\system32\igmeocj.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - F:\WINDOWS\system32\nsn6.dll
O2 - BHO: (no name) - {E0914383-B390-42DC-88D9-5063B9D08223} - F:\WINDOWS\system32\vtutu.dll (file missing)
O2 - BHO: AD Rotator - {EEC590D8-0A3C-4464-BB20-25A4747992F9} - F:\WINDOWS\system32\adrotate.dll (file missing)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [ixrivkf.dll] F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ixrivkf.dll,egemvob
O4 - HKLM\..\Run: [wrzd06fd] RUNDLL32.EXE w064435b.dll,n 005d06f800000002064435b
O4 - HKLM\..\Run: [IpWins] F:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "F:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.elitemediagroup.net
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:24:02 PM 10/26/2006

+ Scan result:



F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175565.dll -> Adware.CommAd : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175566.exe -> Adware.CommAd : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP710\A0154791.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154826.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154936.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP719\A0161316.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP720\A0163490.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP723\A0167504.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP724\A0168504.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP725\A0170504.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP726\A0170523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP726\A0171523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP727\A0173523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP728\A0174523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP730\A0176523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP730\A0177523.dll -> Adware.EZula : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP730\A0177536.dll -> Adware.EZula : Ignored.
F:\WINDOWS\system32\nsa59.dll -> Adware.EZula : Ignored.
F:\WINDOWS\system32\nsoFC.dll -> Adware.EZula : Ignored.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A43385F0-7113-496D-96D7-B9B550E3FCCA} -> Adware.Isearch : Ignored.
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A43385F0-7113-496D-96D7-B9B550E3FCCA} -> Adware.Isearch : Ignored.
HKU\S-1-5-21-1993962763-1085031214-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A43385F0-7113-496D-96D7-B9B550E3FCCA} -> Adware.Isearch : Ignored.
F:\RECYCLER\NPROTECT\00008504.ocx -> Adware.MediaMotor : Ignored.
F:\RECYCLER\NPROTECT\00008505.exe -> Adware.MediaMotor : Ignored.
F:\RECYCLER\NPROTECT\00008508.DLL -> Adware.Minibug : Ignored.
F:\RECYCLER\NPROTECT\00008506.EXE -> Adware.SaveNow : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154871.dll -> Adware.Searchcolours : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154980.dll -> Adware.Searchcolours : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP715\A0157250.dll -> Adware.Searchcolours : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175557.dll -> Adware.Softomate : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175558.dll -> Adware.Softomate : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175572.exe -> Adware.Softomate : Ignored.
HKLM\SOFTWARE\Classes\AppID\{4F5E5D72-C915-4f3b-908B-527D064B0FAA} -> Adware.SysProtect : Ignored.
HKLM\SOFTWARE\Classes\CLSID\{EF130E77-0A34-4365-BFB7-218FD3DDCD5F} -> Adware.SysProtect : Ignored.
HKLM\SOFTWARE\Classes\Interface\{02946FD1-2D99-46E6-A790-3A089714EDD9} -> Adware.SysProtect : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175563.dll -> Adware.TargetServer : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175567.dll -> Adware.Virtumonde : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154833.exe -> Adware.Webhancer.a : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154942.exe -> Adware.Webhancer.a : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0156057.exe -> Adware.Webhancer.a : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154841.dll -> Downloader.Bomka.r : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154950.dll -> Downloader.Bomka.r : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0156053.dll -> Downloader.Bomka.r : Ignored.
F:\RECYCLER\NPROTECT\00008500.exe -> Downloader.Small.buy : Ignored.
F:\RECYCLER\NPROTECT\00008503.exe -> Downloader.Small.cyh : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175559.exe -> Downloader.TSUpdate.f : Ignored.
F:\Program Files\Common Files\mkrf\mkrfd\vocabulary -> Downloader.TSUpdate.j : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175560.exe -> Downloader.TSUpdate.l : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175573.exe -> Downloader.TSUpdate.n : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175556.exe -> Downloader.TSUpdate.r : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175561.EXE -> Downloader.VB.anl : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP710\A0154796.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154818.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154890.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP711\A0154907.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154928.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0154999.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0155018.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0156015.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP712\A0156065.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP715\A0157267.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP718\A0158433.EXE -> Downloader.Zlob.apx : Ignored.
F:\WINDOWS\system32\ismini.exe -> Downloader.Zlob.apx : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP721\A0164930.exe -> Hijacker.Small : Ignored.
F:\Documents and Settings\Peter\Application Data\sysprotectscannerinstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175569.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175570.dll -> Not-A-Virus.Hoax.Win32.Renos.ds : Ignored.
F:\System Volume Information\_restore{2B89C928-BC91-4C4B-A7E1-AABC458BB0E1}\RP729\A0175571.DLL -> Not-A-Virus.Hoax.Win32.Renos.ds : Ignored.
:mozilla.180:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.247realmedia : Ignored.
:mozilla.184:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.185:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.186:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.187:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.188:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
:mozilla.364:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.2o7 : Ignored.
F:\RECYCLER\NPROTECT\00008269.TXT -> TrackingCookie.2o7 : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00007997.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00007997.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00007997.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.17:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.18:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.18:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.19:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.19:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.19:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.22:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.22:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.25:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.25:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.26:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.26:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.26:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.27:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adbrite : Ignored.
:mozilla.27:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.27:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.28:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.28:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.29:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.34:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.35:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.35:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.36:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.36:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.37:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.37:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.38:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.41:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.42:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.43:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.44:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.48:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.49:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.49:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.49:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.49:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.51:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.51:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.51:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.51:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.9:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Adbrite : Ignored.
:mozilla.227:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.230:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Adrevolver : Ignored.
:mozilla.322:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.323:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.324:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.325:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Advertising : Ignored.
:mozilla.66:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Atdmt : Ignored.
F:\Documents and Settings\Peter\Cookies\peter@atdmt[2].txt -> TrackingCookie.Atdmt : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.409:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Bfast : Ignored.
:mozilla.8:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Bfast : Ignored.
:mozilla.174:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.175:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.179:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Burstnet : Ignored.
:mozilla.289:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.290:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Casalemedia : Ignored.
:mozilla.404:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.405:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Clickhype : Ignored.
:mozilla.81:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Com : Ignored.
:mozilla.144:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.210:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Cqcounter : Ignored.
:mozilla.73:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Doubleclick : Ignored.
F:\Documents and Settings\Peter\Cookies\peter@doubleclick[1].txt -> TrackingCookie.Doubleclick : Ignored.
F:\RECYCLER\NPROTECT\00008270.TXT -> TrackingCookie.Enhance : Ignored.
:mozilla.349:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Esomniture : Ignored.
:mozilla.10:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.11:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.12:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.13:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.198:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.199:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.200:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.201:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.8:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.9:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Falkag : Ignored.
:mozilla.202:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.203:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
:mozilla.204:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Fastclick : Ignored.
F:\RECYCLER\NPROTECT\00008272.TXT -> TrackingCookie.Findwhat : Ignored.
:mozilla.221:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.224:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Googleadservices : Ignored.
:mozilla.18:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.412:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Hotlog : Ignored.
:mozilla.9:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Hotlog : Ignored.
:mozilla.239:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Masterstats : Ignored.
:mozilla.6:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.7:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Mediaplex : Ignored.
F:\Documents and Settings\Peter\Cookies\peter@mediaplex[1].txt -> TrackingCookie.Mediaplex : Ignored.
:mozilla.355:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Onestat : Ignored.
:mozilla.357:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Onestat : Ignored.
:mozilla.104:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Paycounter : Ignored.
:mozilla.169:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.170:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Questionmarket : Ignored.
:mozilla.406:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Revenue : Ignored.
:mozilla.51:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.52:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.53:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.54:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
:mozilla.55:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Ru4 : Ignored.
F:\RECYCLER\NPROTECT\00008271.TXT -> TrackingCookie.Ru4 : Ignored.
:mozilla.373:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Sexcounter : Ignored.
:mozilla.374:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Sexcounter : Ignored.
:mozilla.98:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Sexlist : Ignored.
:mozilla.400:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Starware : Ignored.
:mozilla.401:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Starware : Ignored.
:mozilla.402:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Starware : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.13:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.253:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.254:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.255:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.256:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.257:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.261:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.262:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Statcounter : Ignored.
:mozilla.32:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.33:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.39:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.45:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.48:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.48:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.48:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.48:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.8:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.8:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Statcounter : Ignored.
:mozilla.176:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.177:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.178:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.365:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tacoda : Ignored.
:mozilla.293:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Trafic : Ignored.
:mozilla.127:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.128:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.129:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.149:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Tribalfusion : Ignored.
:mozilla.287:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.288:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.295:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.296:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.297:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.298:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.299:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Valuead : Ignored.
:mozilla.162:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Webtrendslive : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.20:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.21:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.22:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.22:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.22:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.22:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008385.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008391.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008398.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008404.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008445.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008467.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008482.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008485.MOZ -> TrackingCookie.Yadro : Ignored.
:mozilla.414:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.415:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Yadro : Ignored.
:mozilla.108:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.109:F:\Documents and Settings\Peter\Application Data\Mozilla\Firefox\Profiles\kbim5iuy.default\cookies.txt -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.10:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.11:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008007.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.12:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.14:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.15:F:\RECYCLER\NPROTECT\00008021.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.15:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.16:F:\RECYCLER\NPROTECT\00008067.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.23:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.24:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.25:F:\RECYCLER\NPROTECT\00008071.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.25:F:\RECYCLER\NPROTECT\00008129.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.34:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.35:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.35:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.36:F:\RECYCLER\NPROTECT\00008149.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.36:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.37:F:\RECYCLER\NPROTECT\00008165.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.43:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.44:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.45:F:\RECYCLER\NPROTECT\00008171.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.45:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.46:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.47:F:\RECYCLER\NPROTECT\00008299.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.50:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.51:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.52:F:\RECYCLER\NPROTECT\00008359.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.54:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.55:F:\RECYCLER\NPROTECT\00008379.MOZ -> TrackingCookie.Yieldmanager : Ignored.
:mozilla.56:F:\RECYCLER\N
I'm not sure why you chose to ignore to the bad ones found by AVG Anti-Spyware.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Clear "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Clear "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Download DelDomains.inf
http://www.mvps.org/winhelp2002/DelDomains.inf
Right-click and select….. Save Target As….Save

To use: Right-click and select……. Install (no need to restart)




Run HiJackThis then:

1. Click "Config…"
2. Click "Misc Tools"
3. Click "Open Process manager"
-

Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

F:\Program Files\ipwins\ipwins.exe
F:\WINDOWS\system32\ixrivkf.dll
F:\WINDOWS\system32\nsn6.dll
F:\WINDOWS\system32\jfrnxmmh.dll
F:\WINDOWS\system32\igmeocj.dll
F:\WINDOWS\system32\vtutu.dll
F:\WINDOWS\system32\adrotate.dll
F:\PROGRAm files\COMMON files\mkrf\mkrfm.exe
<–Unless you know what this is


Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - F:\WINDOWS\system32\jfrnxmmh.dll (file missing)
O2 - BHO: (no name) - {3E19C055-8B4A-82DE-1B14-0311D0EC8104} - F:\WINDOWS\system32\ixrivkf.dll
O2 - BHO: (no name) - {4D2BA316-62E7-63A1-9506-00FCACD969A6} - F:\WINDOWS\system32\igmeocj.dll (file missing)
O2 - BHO: SSL encrypt - {746455FE-D059-47e7-AF0E-140E03F5A447} - F:\WINDOWS\system32\nsn6.dll
O2 - BHO: (no name) - {E0914383-B390-42DC-88D9-5063B9D08223} - F:\WINDOWS\system32\vtutu.dll (file missing)
O2 - BHO: AD Rotator - {EEC590D8-0A3C-4464-BB20-25A4747992F9} - F:\WINDOWS\system32\adrotate.dll (file missing)
O4 - HKLM\..\Run: [ixrivkf.dll] F:\WINDOWS\system32\rundll32.exe F:\WINDOWS\system32\ixrivkf.dll,egemvob
O4 - HKLM\..\Run: [wrzd06fd] RUNDLL32.EXE w064435b.dll,n 005d06f800000002064435b
O4 - HKLM\..\Run: [IpWins] F:\Program Files\ipwins\ipwins.exe
O4 - HKLM\..\Run: [adstart] "iexplore.exe" "http://iesettingsupdate"
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O15 - Trusted Zone: *.elitemediagroup.net
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)

Close ALL windows and browsers except HijackThis and click "Fix checked"



Delete these Files if listed:
F:\Program Files\ipwins\ipwins.exe
F:\WINDOWS\system32\ixrivkf.dll
F:\WINDOWS\system32\nsn6.dll
F:\WINDOWS\system32\jfrnxmmh.dll
F:\WINDOWS\system32\igmeocj.dll
F:\WINDOWS\system32\vtutu.dll
F:\WINDOWS\system32\adrotate.dll



Delete these Folders if listed:
F:\Program Files\ipwins



Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.
hey there. it is running better but there are still some popups. anything else you might see here? i have done everything you told me to. thanks again!

pete

Logfile of HijackThis v1.99.1
Scan saved at 10:28:23 AM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\WINDOWS\system32\wuauclt.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\WINDOWS\System32\HPZipm12.exe
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\Documents and Settings\Peter\Desktop\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "F:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Give me another combo scan please.

Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
not exactly sure what you were referring to when you said combo.exe. i dont have that. so i am doing an avg scan and a hijackthis as well. is this what you meant? i will post results
* Download Combofix to your desktop.
Doubleclick combo.exe
Follow the prompts.
Don't click on the window while the fix is running, because that will cause your system to hang.

When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
ok got it now. sorry for the confusion. here it is:

Peter - 06-10-28 11:36:37.90 Service Pack 2
ComboFix 06.10.19 - Running from: "F:\Documents and Settings\Peter\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


F:\WINDOWS\system32\issearch.exe
F:\Program Files\outlook
F:\Program Files\winupdates
F:\WINDOWS\system32\components
F:\Program Files\Common Files\{30B4C3C0-0897-1033-0323-040509030001}
F:\Program Files\Common Files\{D0B4C3C0-0897-1033-0323-040509030001}

~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ Purity ~ ~ ~ ~ ~ ~ ~ ~~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~ ~

Folders Quarantined:

F:\QooBox\Purity\Documents and Settings\Peter\Application Data\FNTS~1
F:\QooBox\Purity\Documents and Settings\Peter\Application Data\SSEMBL~1


((((((((((((((((((((((((((((((( Files Created from 2006-09-28 to 2006-10-28 ))))))))))))))))))))))))))))))))))


2006-10-18 17:31 86,016 ——— F:\WINDOWS\unvise32.exe
2006-10-16 21:06 231,936 –a—— F:\WINDOWS\epsuninst.exe
2006-10-15 18:36 48,816 –a—— F:\WINDOWS\system32\S32EVNT1.DLL
2006-10-15 18:36 109,744 –a—— F:\WINDOWS\system32\drivers\SYMEVENT.SYS
2006-10-15 15:45 3,968 –a—— F:\WINDOWS\system32\drivers\AvgAsCln.sys
2006-10-15 15:34 463 –a—— F:\Documents and Settings\Peter\fixme.reg
2006-10-14 17:06 433,632 –a—— F:\WINDOWS\hancerdoem.exe
2006-10-14 17:06 221,523 –a—— F:\WINDOWS\1011_justin.exe
2006-10-14 17:06 217,346 –a—— F:\WINDOWS\Setup90.exe
2006-10-14 17:06 1,259 –a—— F:\WINDOWS\system32\wrzd06fd.sys
2006-10-14 16:51 2 –a—— F:\WINDOWS\system32\wnsapisv.exe
2006-10-11 13:56 115,134 –a—— F:\WINDOWS\system32\justin.exe
2006-10-11 12:37 96,911 –a—— F:\WINDOWS\system32\ts_www.exe


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-10-28 11:37 ——– d——– F:\Program Files\Common Files
2006-10-28 11:21 54 —hs—- F:\Documents and Settings\Peter\Application Data\.zreglib
2006-10-26 19:28 ——– d——– F:\Program Files\Mozilla Firefox
2006-10-26 19:28 ——– d——– F:\Program Files\Microsoft ActiveSync
2006-10-26 18:35 ——– d——– F:\Program Files\Common Files\Symantec Shared
2006-10-24 19:28 ——– d——– F:\Program Files\Common Files\mkrf
2006-10-24 19:17 ——– d——– F:\Program Files\Lavasoft
2006-10-24 19:17 ——– d——– F:\Documents and Settings\Peter\Application Data\Lavasoft
2006-10-20 09:00 ——– d——– F:\Program Files\QuickTime
2006-10-20 08:59 ——– d——– F:\Program Files\Apple Software Update
2006-10-15 18:53 ——– d——– F:\Program Files\Symantec
2006-10-15 18:43 ——– d——– F:\Program Files\Norton AntiVirus
2006-10-15 16:04 ——– d——– F:\Documents and Settings\Peter\Application Data\Mozilla
2006-10-15 15:45 ——– d——– F:\Program Files\Grisoft
2006-10-14 17:13 ——– d——– F:\Program Files\Folder Lock
2006-09-30 20:52 ——– d——– F:\Program Files\dvdSanta
2006-09-24 08:42 ——– d——– F:\Program Files\Common Files\AOL
2006-09-13 01:01 1084416 –a—— F:\WINDOWS\system32\msxml3.dll
2006-09-11 16:30 275112 –a—— F:\WINDOWS\system32\drivers\srtspl.sys
2006-09-11 16:30 243368 –a—— F:\WINDOWS\system32\drivers\srtsp.sys
2006-09-11 16:30 24232 –a—— F:\WINDOWS\system32\drivers\srtspx.sys
2006-09-10 19:12 ——– d——– F:\Documents and Settings\Peter\Application Data\1ClickDVDCopy
2006-09-10 15:11 81920 –a—— F:\Documents and Settings\Peter\Application Data\ezpinst.exe
2006-09-10 15:11 7176 –a—— F:\Documents and Settings\Peter\Application Data\pcouffin.cat
2006-09-10 15:11 47360 –a—— F:\WINDOWS\system32\drivers\pcouffin.sys
2006-09-10 15:11 47360 –a—— F:\Documents and Settings\Peter\Application Data\pcouffin.sys
2006-09-10 15:11 34 –a—— F:\Documents and Settings\Peter\Application Data\pcouffin.log
2006-09-10 15:11 1144 –a—— F:\Documents and Settings\Peter\Application Data\pcouffin.inf
2006-09-10 15:11 ——– d——– F:\Program Files\LG Software Innovations
2006-09-10 15:11 ——– d——– F:\Documents and Settings\Peter\Application Data\Vso
2006-09-10 15:04 ——– d——– F:\Program Files\SlySoft
2006-09-07 20:29 ——– d——– F:\Program Files\Diskeeper Corporation
2006-09-04 21:10 ——– d——– F:\Program Files\AVI to DVD Converter
2006-09-04 17:27 ——– d——– F:\Program Files\LimeWire
2006-09-02 13:35 613056 –a—— F:\WINDOWS\system32\SymNeti.dll
2006-09-02 13:35 36032 –a—— F:\WINDOWS\system32\drivers\symndisv.sys
2006-09-02 13:35 239808 –a—— F:\WINDOWS\system32\SymRedir.dll
2006-09-02 13:35 186048 –a—— F:\WINDOWS\system32\drivers\symtdi.sys
2006-09-02 13:34 39104 –a—— F:\WINDOWS\system32\drivers\symids.sys
2006-09-02 13:34 33216 –a—— F:\WINDOWS\system32\drivers\symndis.sys
2006-09-02 13:34 26432 –a—— F:\WINDOWS\system32\drivers\symredrv.sys
2006-09-02 13:34 144832 –a—— F:\WINDOWS\system32\drivers\symfw.sys
2006-09-02 13:34 11968 –a—— F:\WINDOWS\system32\drivers\symdns.sys
2006-08-25 11:45 617472 –a—— F:\WINDOWS\system32\comctl32.dll
2006-08-21 08:21 16896 –a—— F:\WINDOWS\system32\fltlib.dll
2006-08-21 05:14 23040 –a—— F:\WINDOWS\system32\fltmc.exe
2006-08-16 07:58 100352 –a—— F:\WINDOWS\system32\6to4svc.dll
2006-07-29 19:32 48936 –a—— F:\WINDOWS\system32\sirenacm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"H/PC Connection Agent"="\"F:\\Program Files\\Microsoft ActiveSync\\wcescomm.exe\""
"getmail"="\"F:\\Program Files\\PaulB\\GetHotmail\\GetMail\\GetMail.exe\""
"Aim6"=""
"SysProtect Free"="\"F:\\Program Files\\SysProtect Free\\USYP.exe\" /min"
"mkrf"="F:\\PROGRA~1\\COMMON~1\\mkrf\\mkrfm.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"NvCplDaemon"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"RemoteControl"="\"F:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"Ulead Quick-Drop"="\"F:\\Program Files\\Ulead Systems\\Ulead DVD MovieFactory 5\\Ulead DVD MovieFactory 5\\Quick-Drop.exe\" WINDOWCALL"
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE"
@=""
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}"="F:\\Program Files\\Google\\Gmail Notifier\\gnotify.exe"
"HostManager"="F:\\Program Files\\Common Files\\AOL\\1149632726\\ee\\AOLSoftware.exe"
"IPHSend"="F:\\Program Files\\Common Files\\AOL\\IPHSend\\IPHSend.exe"
"iTunesHelper"="\"F:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Logitech BT Wizard"="LBTWiz.exe -silent"
"DiskeeperSystray"="\"F:\\Program Files\\Diskeeper Corporation\\Diskeeper\\DkIcon.exe\""
"AnyDVD"="F:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe"
"!AVG Anti-Spyware"="\"F:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ccApp"="\"F:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"osCheck"="\"F:\\Program Files\\Norton AntiVirus\\osCheck.exe\""
"QuickTime Task"="\"F:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,cc,00,00,00,00,00,00,00,34,03,00,00,e2,02,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"ALUAlert"="F:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"ALUAlert"="F:\\Program Files\\Symantec\\LiveUpdate\\ALUNotify.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"
"incestuously"="{03413bf7-e34c-445b-bfc0-a2b127255871}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccApp"
"hkey"="HKLM"
"command"="\"F:\\Program Files\\Common Files\\Symantec Shared\\ccApp.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccRegVfy]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ccRegVfy"
"hkey"="HKLM"
"command"="\"F:\\Program Files\\Common Files\\Symantec Shared\\ccRegVfy.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="CTHELPER"
"hkey"="HKLM"
"command"="CTHELPER.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DeadAIM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DeadAIM"
"hkey"="HKLM"
"command"="rundll32.exe \"F:\\PROGRA~1\\AIM\\\\DeadAIM.ocm\",ExportedCheckODLs"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DiskeeperSystray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DkIcon"
"hkey"="HKLM"
"command"="\"F:\\Program Files\\Executive Software\\Diskeeper\\DkIcon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="WCESCOMM"
"hkey"="HKCU"
"command"="\"F:\\Program Files\\Microsoft ActiveSync\\WCESCOMM.EXE\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\InCD]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="InCD"
"hkey"="HKLM"
"command"="F:\\Program Files\\Ahead\\InCD\\InCD.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Jet Detection]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ADGJDet"
"hkey"="HKLM"
"command"="\"F:\\Program Files\\Creative\\SBLive\\PROGRAM\\ADGJDet.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="dumprep 0 -k"
"hkey"="HKLM"
"command"="%systemroot%\\system32\\dumprep 0 -k"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LDM]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"=""
"hkey"="HKCU"
"command"="\\Program\\"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Logitech Hardware Abstraction Layer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="KHALMNPR"
"hkey"="HKLM"
"command"="KHALMNPR.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoRepair]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="ISStart"
"hkey"="HKLM"
"command"="F:\\Program Files\\Logitech\\Video\\ISStart.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechVideoTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="LogiTray"
"hkey"="HKLM"
"command"="F:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msxct]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="msxct"
"hkey"="HKLM"
"command"="msxct.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="F:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NvCpl"
"hkey"="HKLM"
"command"="RUNDLL32.EXE F:\\WINDOWS\\system32\\NvCpl.dll,NvStartup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NVMCTRAY"
"hkey"="HKCU"
"command"="RUNDLL32.EXE F:\\WINDOWS\\System32\\NVMCTRAY.DLL,NvTaskbarInit"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nwiz"
"hkey"="HKLM"
"command"="nwiz.exe /install"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RecoverFromReboot]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RecoverFromReboot"
"hkey"="HKLM"
"command"="F:\\WINDOWS\\Temp\\RecoverFromReboot.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SAClient]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RegCon"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Comcast\\BBClient\\Programs\\RegCon.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SiSUSBRG]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SiSUSBrg"
"hkey"="HKLM"
"command"="F:\\WINDOWS\\SiSUSBrg.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpriteService]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SpriteService"
"hkey"="HKCU"
"command"="\"F:\\Program Files\\Sprite Software\\Sprite Backup\\SpriteService.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="F:\\Program Files\\Java\\jre1.5.0_02\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SNDMon"
"hkey"="HKLM"
"command"="F:\\PROGRA~1\\SYMNET~1\\SNDMon.exe /Consumer"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdReg]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="UpdReg"
"hkey"="HKLM"
"command"="F:\\WINDOWS\\UpdReg.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WildTangent CDA]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="cdaEngine0400"
"hkey"="HKLM"
"command"="RUNDLL32.exe \"F:\\Program Files\\WildTangent\\Apps\\CDA\\cdaEngine0400.dll\",cdaEngineMain"
"inimapping"="0"

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn\Event

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
F:\WINDOWS\tasks\AppleSoftwareUpdate.job
F:\WINDOWS\tasks\Norton AntiVirus - Run Full System Scan - Peter.job

Completion time: 06-10-28 11:37:28.89
F:\ComboFix.txt … 06-10-28 11:37


Logfile of HijackThis v1.99.1
Scan saved at 11:37:47 AM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\WINDOWS\Explorer.EXE
F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\Program Files\iPod\bin\iPodService.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\Common Files\Symantec Shared\ccApp.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\WINDOWS\System32\HPZipm12.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\Program Files\MSN Messenger\msnmsgr.exe
F:\Documents and Settings\Peter\Desktop\iexplore.exe
F:\WINDOWS\system32\svchost.exe
F:\Documents and Settings\Peter\Desktop\scanner.exe.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ccApp] "F:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "F:\Program Files\Norton AntiVirus\osCheck.exe"
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Settings Manager (ccSetMgr) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - F:\Program Files\Norton AntiVirus\isPwdSvc.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
O23 - Service: Symantec Core LC - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - F:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe
Run HiJackThis then:

1. Click "Config…"
2. Click "Misc Tools"
3. Click "Open Process manager"

-

Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

F:\WINDOWS\unvise32.exe
F:\WINDOWS\epsuninst.exe
F:\WINDOWS\hancerdoem.exe
F:\WINDOWS\1011_justin.exe
F:\WINDOWS\system32\wrzd06fd.sys
F:\WINDOWS\system32\wnsapisv.exe
F:\WINDOWS\system32\justin.exe
F:\WINDOWS\system32\ts_www.exe

Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.



Download Pocket Killbox
http://www.atribune.org/downloads/KillBox.exe
If you already have Killbox first ensure it is this version !.

Then double-click on the killbox.exe program.


Start Killbox and click on Tools->Delete Temp Files.
Then select the option labeled Delete on reboot.

Do not close killbox, and open notepad, by clicking on Start, then Run, and typing notepad.exe and pressing the OK button.


When notepad is open, copy and paste the following bolded text into the notepad screen. You do this by highlighting each of the below bolded filenames and then pressing Control-C on your keyboard. Then click on the open notepad windows and press Control-V to paste the contents into the notepad.

F:\WINDOWS\unvise32.exe
F:\WINDOWS\epsuninst.exe
F:\WINDOWS\hancerdoem.exe
F:\WINDOWS\1011_justin.exe
F:\WINDOWS\system32\wrzd06fd.sys
F:\WINDOWS\system32\wnsapisv.exe
F:\WINDOWS\system32\justin.exe
F:\WINDOWS\system32\ts_www.exe


Return to Killbox, go to the File menu and select Paste from Clipboard.


Still in Killbox, click the red-and-white Delete File button. Click Yes at the Delete on Reboot prompt. Click No at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually

"copy/paste" a new HJT log file into this thread.
Also please describe how your computer behaves at the moment.
i had one popup when starting internet explorer. definitely better though

Logfile of HijackThis v1.99.1
Scan saved at 12:10:22 PM, on 10/28/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
F:\WINDOWS\system32\spoolsv.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe
F:\Program Files\Google\Gmail Notifier\gnotify.exe
F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
F:\Program Files\iTunes\iTunesHelper.exe
F:\Program Files\Logitech\SetPoint\LBTWiz.exe
F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\Microsoft ActiveSync\wcescomm.exe
F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
F:\PROGRA~1\MICROS~3\rapimgr.exe
F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
F:\WINDOWS\system32\CTsvcCDA.exe
F:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
F:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
F:\WINDOWS\System32\nvsvc32.exe
F:\WINDOWS\System32\svchost.exe
F:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
F:\Program Files\Common Files\Logitech\KhalShared\KHALMNPR.EXE
F:\Program Files\iPod\bin\iPodService.exe
F:\WINDOWS\System32\HPZipm12.exe
F:\WINDOWS\system32\wscntfy.exe
F:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
F:\WINDOWS\system32\rundll32.exe
F:\Documents and Settings\Peter\Desktop\scanner.exe.exe
F:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r6.attbi.com;localhost
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - F:\Program Files\TechSmith\SnagIt 7\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - F:\Program Files\TechSmith\SnagIt 7\SnagItIEAddin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] "F:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [Ulead Quick-Drop] "F:\Program Files\Ulead Systems\Ulead DVD MovieFactory 5\Ulead DVD MovieFactory 5\Quick-Drop.exe" WINDOWCALL
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] F:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [HostManager] F:\Program Files\Common Files\AOL\1149632726\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [IPHSend] F:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [iTunesHelper] "F:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech BT Wizard] LBTWiz.exe -silent
O4 - HKLM\..\Run: [DiskeeperSystray] "F:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"
O4 - HKLM\..\Run: [AnyDVD] F:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [H/PC Connection Agent] "F:\Program Files\Microsoft ActiveSync\wcescomm.exe"
O4 - HKCU\..\Run: [getmail] "F:\Program Files\PaulB\GetHotmail\GetMail\GetMail.exe"
O4 - HKCU\..\Run: [SysProtect Free] "F:\Program Files\SysProtect Free\USYP.exe" /min
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: hp psc 2000 Series.lnk = F:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpobnz08.exe
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech Harmony Remote.lnk = F:\Program Files\Logitech\Harmony Remote\harmonyClient.exe
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Broadband Networking.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - F:\PROGRA~1\MICROS~3\INetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - F:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - F:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - F:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/pote_x.cab
O16 - DPF: {24D1BDCE-D835-11D6-BF84-0050047EA0E7} (BlueStream_Flash Class) - http://www.rovion.com/Controls/Rovion.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://wdownload.weatherbug.com/minibug/tr…Transporter.cab?
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/eB…l_v1-0-3-48.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1111906201125
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1145198272000
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse…pDownloader.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - F:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: LBTWlgn - f:\program files\common files\logitech\bluetooth\LBTWlgn.dll
O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)
O23 - Service: asKernel - Unknown owner - F:\PROGRA~1\ALURIA~2\asKernel.exe (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - F:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - F:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - F:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - F:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe" /h ccCommon (file missing)
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - F:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Diskeeper - Diskeeper Corporation - F:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - F:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech Inc. - F:\Program Files\Common Files\Logitech\Bluetooth\LBTSERV.EXE
O23 - Service: LiveUpdate - Symantec Corporation - F:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - F:\WINDOWS\System32\HPZipm12.exe
Run HiJackThis then:

1. Click "Config…"
2. Click "Misc Tools"
3. Click "Open Process manager"

Next, while holding down the CTRL key, locate (if present) and click on (highlight) each of the following:

F:\PROGRAM Files\COMMON Files\mkrf\mkrfm.exe

Now double-check and make sure that only those item(s) above are highlighted, then click "Kill process". Now, click "Refresh", check again, and repeat this step if any remain.





Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a Check in the box on the left side on these:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O4 - HKCU\..\Run: [mkrf] F:\PROGRA~1\COMMON~1\mkrf\mkrfm.exe
O16 - DPF: {886DDE35-E585-11D0-A707-000000521958} - http://69.56.176.76/webplugin.cab
O21 - SSODL: incestuously - {03413bf7-e34c-445b-bfc0-a2b127255871} - (no file)

Close ALL windows and browsers except HijackThis and click "Fix checked"



Delete this Files if listed:
F:\PROGRAM Files\COMMON Files\mkrf\mkrfm.exe


Delete this Folders if listed:
F:\PROGRAM Files\COMMON Files\mkrf




Reboot and "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI