This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

ads.k8l.info needs removal

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have read a couple of the threads on this issue and my logs are below. I have had this problem for several days now and did remove the 016 – adwerkz.cab. Please review my logs and confirm additional actions.

Logfile of HijackThis v1.99.1
Scan saved at 11:52:41 AM, on 1/17/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\i2050QosSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\System32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\WINDOWS\$NtUninstallKB902400$\jofocu.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\WISPTIS.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.txstate.edu/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
O1 - Hosts: 147.26.136.43 tsusympsrv011
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0C6936AE-5D20-4B63-E0A4-E78CF3041075} - C:\Program Files\WindowsUpdate\qucawoge.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [ReportListener] "C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nicrlstn.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [jofocu] C:\WINDOWS\$NtUninstallKB902400$\jofocu.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -stcleanup
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: tsusympsrv011.tr.txstate.edu
O15 - Trusted IP range: 147.26.136.43
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\5921\html\awswaxf.cab
O16 - DPF: {1C203F13-95AD-11D0-A84B-00A0247B735B} (Infragistics ActiveTreeView Control) - http://147.26.136.43/Common/controls/ssTree.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://tsusympsrv011.tr.txstate.edu/SWCCom…exviewermod.cab
O16 - DPF: {44BD92DB-D8A8-43A8-8900-DD73310A59EB} (True OLE DBGrid 8 Control) - http://tsusympsrv011/common/controls/todg8.cab
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} (Cadwkzctl Object) - http://apps.deskwizz.com/ax/adwerkz.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136481744696
O16 - DPF: {6ACD018E-1823-4705-83FB-64B6F498038C} (EmHlpControl Class) - http://tsusympsrv011.tr.txstate.edu/Common…rols/EHCtrl.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://147.26.136.43/Common/controls/iemenu.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsusympsrv011/Scripting/msrdp.cab
O16 - DPF: {92D71E93-25A8-11CF-A640-9986B64D9618} (Olectra Chart 2D Control) - http://tsusympsrv011.tr.txstate.edu/Common…ols/olec-2D.cab
O16 - DPF: {977DBE03-F527-11D3-8F03-00C04FA3EB91} (RtdControl Class) - http://tsusympsrv011/Common/Controls/RtdCtrl.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = txstate.edu
O17 - HKLM\Software\..\Telephony: DomainName = txstate.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{748F0FF5-2798-41E0-864F-C6C503F3BDFD}: NameServer = 147.26.8.11,147.26.8.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = txstate.edu
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Nortel Networks i2050 QoS Service (i2050QoSSvc) - Nortel Networks Corp. - C:\WINDOWS\system32\i2050QosSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe

——————————————————————————————————————

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 3:13:30 PM 1/17/2007

+ Scan result:



C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\CONFLICT.2\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP323\A0059830.dll -> Trojan.ZQuest : No action taken.


::Report end
I have now run the combo fix and the log is as follows. In reading some of the other threads on this issue, I have found some suspect files. Please confirm.

C:\WINDOWS\$NtUninstallKB902400$\jofocu.exe
O4 - HKLM\..\Run: [jofocu] C:\WINDOWS\$NtUninstallKB902400$\jofocu.exe
O4 - HKCU\..\Run: [PID41IER.exe ] C:\WINDOWS\system32\PID41IER.exe
O16 - DPF: {4AD73894-A895-4FC2-B233-299867E08753} (Cadwkzctl Object) - http://apps.deskwizz.com/ax/adwerkz.cab
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)


Layne - 07-01-18 10:46:02.01 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Layne\My Documents\1FIXpc"

((((((((((((((((((((((((((((((( Files Created from 2006-12-18 to 2007-01-18 ))))))))))))))))))))))))))))))))))


2007-01-17 16:06 d——– C:\!KillBox
2007-01-12 15:20 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-12 15:20 d——– C:\Program Files\Grisoft
2007-01-11 13:45 d——– C:\WINDOWS\pss
2007-01-11 07:58 d——– C:\Program Files\Hijackthis
2007-01-10 10:01 d——– C:\Documents and Settings\Layne\Application Data\System Restore
2006-12-20 10:41 d——– C:\My Games
2006-12-20 10:40 d——– C:\My Download Files
2006-12-20 10:38 774,144 –a—— C:\Program Files\RngInterstitial.dll
2006-12-20 10:38 d——– C:\Program Files\Real
2006-12-20 10:38 d——– C:\Program Files\Common Files\Real


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-18 10:07 ——– d–h—– C:\Program Files\WindowsUpdate
2007-01-12 15:19 ——– d——– C:\Documents and Settings\Layne\Application Data\U3
2007-01-12 10:17 ——– d——– C:\Program Files\Viewpoint
2007-01-12 09:26 ——– d——– C:\Program Files\Mozilla Firefox
2007-01-10 20:05 ——– d–h—– C:\Program Files\InstallShield Installation Information
2007-01-10 20:05 ——– d——– C:\Program Files\Hewlett-Packard
2007-01-10 20:04 ——– d——– C:\Program Files\Nortel Networks
2007-01-10 09:51 ——– d——– C:\Documents and Settings\Layne\Application Data\AdobeUM
2006-12-20 10:38 ——– d——– C:\Program Files\Common Files
2006-12-18 09:28 ——– d——– C:\Program Files\Internet Explorer
2006-12-18 09:26 ——– d——– C:\Program Files\Outlook Express
2006-12-18 09:26 ——– d——– C:\Program Files\Common Files\System
2006-12-12 14:04 ——– d——– C:\Program Files\Common Files\Viewpoint
2006-12-11 19:53 38512 –a—— C:\Documents and Settings\Layne\Application Data\Comma Separated Values (DOS).ADR
2006-12-06 23:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-12-05 14:32 ——– d——– C:\Program Files\MSXML 4.0
2006-12-04 19:03 ——– d——– C:\Program Files\Common Files\supportsoft
2006-12-04 18:59 ——– d——– C:\Program Files\HERACTSTG
2006-11-27 17:18 1530 –a—— C:\WINDOWS\UnHSDX.bat
2006-11-07 23:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:17 1245696 –a—— C:\WINDOWS\system32\msxml4.dll
2006-10-19 07:56 713216 –a—— C:\WINDOWS\system32\sxs.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
"Gadwin PrintScreen 3.1"="C:\\Program Files\\Gadwin Systems\\PrintScreen\\PrintScreen.exe /nosplash"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"IE Privacy Keeper"="\"C:\\Program Files\\UnH Solutions\\IE Privacy Keeper\\IEPrivacyKeeper.exe\" -stcleanup"
"PID41IER.exe "="C:\\WINDOWS\\system32\\PID41IER.exe "

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"Dell Wireless Manager UI"="C:\\WINDOWS\\System32\\WLTRAY"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE"
"McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey"
"Network Associates Error Reporting Service"="\"C:\\Program Files\\Common Files\\Network Associates\\TalkBack\\tbmon.exe\""
"ReportListener"="\"C:\\Program Files\\Nortel Networks\\Symposium Call Center Server\\client\\en\\bin\\nicrlstn.exe\""
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r"
"AdobeVersionCue"="C:\\Program Files\\Adobe\\Adobe Version Cue\\ControlPanel\\VersionCueTray.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"kugudako"="C:\\WINDOWS\\$NtUninstallKB904706$\\kugudako.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="C:\\Program Files\\WindowsUpdate\\rtelelizu.html"
"SubscribedURL"=""
"FriendlyName"=""
"Flags"=dword:00002000
"Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\
03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00
"CurrentState"=dword:40000001
"OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\
00,00,01,00,00,00
"RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\
00,00,00,00,00,00

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,00,00,ea,\
03,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=dword:40000004
"OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,\
00,00,04,00,00,40
"RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,\
00,00,01,00,00,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job

Completion time: 07-01-18 10:48:26.47
C:\ComboFix.txt … 07-01-18 10:48
C:\ComboFix2.txt … 07-01-11 13:17
Sorry for the delay :oops:
If you still need help and haven't posted at another forum.

Download and install AVG Anti-Spyware (ewido). Then scan and save the log from the scan.
Instructions and download link can be found here.

Then run this online scan. Save the report.

Rescan with HJT and post a new log with the results from AVG .
Also please describe how your computer behaves at the moment.
Thanks for the response. I am still having issues with ads popping up and I hear ads but there is no window or anything on the task bar. I was hit by a "bo:heap" virus while I was running the online scan. McAfee blocked the virus but my pc froze and I had to reboot. The following is the AVG and HJT logs. I am not getting the ads.k8l.info windows anymore but I do still get ads popping up even when I am not connected to the network.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 9:22:56 AM 2/5/2007

+ Scan result:



C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP322\A0056610.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP322\A0056611.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP322\A0057655.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP323\A0058777.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP323\A0059807.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP323\A0059860.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP325\A0059890.exe -> Hijacker.VB.pm : No action taken.
C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP325\A0059909.exe -> Hijacker.VB.pm : No action taken.
C:\WINDOWS\$NtUninstallKB904706$\kugudako.exe -> Hijacker.VB.pm : No action taken.
C:\WINDOWS\Downloaded Program Files\UDC6_0001_D19M1908NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.m : No action taken.
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : No action taken.
C:\WINDOWS\Downloaded Program Files\USDR6_7777_BHLP0611NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.q : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@adrevolver[3].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Falkag : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@findwhat[1].txt -> TrackingCookie.Findwhat : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Information : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
:mozilla.348:C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.349:C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.350:C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
:mozilla.351:C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@realmedia[2].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@targetnet[2].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Layne\Cookies\layne@zedo[1].txt -> TrackingCookie.Zedo : No action taken.


::Report end


HJT LOG
Logfile of HijackThis v1.99.1
Scan saved at 9:50:44 AM, on 2/5/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\WINDOWS\system32\i2050QosSvc.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\System32\WLTRAY.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe
C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nicrlstn.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe
C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nbnmsrvc.exe
C:\Program Files\Hijackthis\HijackThis.exe
\?\C:\WINDOWS\system32\WBEM\WMIADAP.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.txstate.edu/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
O1 - Hosts: 147.26.136.43 tsusympsrv011
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0C6936AE-5D20-4B63-E0A4-E78CF3041075} - C:\Program Files\WindowsUpdate\qucawoge.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Dell Wireless Manager UI] C:\WINDOWS\System32\WLTRAY
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\Network Associates\Common Framework\UpdaterUI.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [Network Associates Error Reporting Service] "C:\Program Files\Common Files\Network Associates\TalkBack\tbmon.exe"
O4 - HKLM\..\Run: [ReportListener] "C:\Program Files\Nortel Networks\Symposium Call Center Server\client\en\bin\nicrlstn.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 3.1] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKCU\..\Run: [IE Privacy Keeper] "C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPrivacyKeeper.exe" -stcleanup
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Adobe Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: VPN Client.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: tsusympsrv011.tr.txstate.edu
O15 - Trusted IP range: 147.26.136.43
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://activation.rr.com/install/downloads/tgctlcm.cab
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {15B782AF-55D8-11D1-B477-006097098764} (Macromedia Authorware Web Player Control) - file://D:\5921\html\awswaxf.cab
O16 - DPF: {1C203F13-95AD-11D0-A84B-00A0247B735B} (Infragistics ActiveTreeView Control) - http://147.26.136.43/Common/controls/ssTree.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/insta…staller_gmn.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installd…leanerstart.cab
O16 - DPF: {2DEF4530-8CE6-41C9-84B6-A54536C90213} (Crystal Report Viewer Control 9) - http://tsusympsrv011.tr.txstate.edu/SWCCom…exviewermod.cab
O16 - DPF: {44BD92DB-D8A8-43A8-8900-DD73310A59EB} (True OLE DBGrid 8 Control) - http://tsusympsrv011/common/controls/todg8.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1136481744696
O16 - DPF: {6ACD018E-1823-4705-83FB-64B6F498038C} (EmHlpControl Class) - http://tsusympsrv011.tr.txstate.edu/Common…rols/EHCtrl.cab
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://www.kodakgallery.com/downloads/BUM/…_1/axofupld.cab
O16 - DPF: {7823A620-9DD9-11CF-A662-00AA00C066D2} (PopupMenu Object) - http://147.26.136.43/Common/controls/iemenu.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://tsusympsrv011/Scripting/msrdp.cab
O16 - DPF: {92D71E93-25A8-11CF-A640-9986B64D9618} (Olectra Chart 2D Control) - http://tsusympsrv011.tr.txstate.edu/Common…ols/olec-2D.cab
O16 - DPF: {977DBE03-F527-11D3-8F03-00C04FA3EB91} (RtdControl Class) - http://tsusympsrv011/Common/Controls/RtdCtrl.cab
O16 - DPF: {9B17FE0E-51F2-4692-8B32-8EFB805FC0E7} (HPObjectInstaller Class) - http://h30155.www3.hp.com/ediags/gs/instal…edsolutions.cab
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://download.cdn.winsoftware.com/files/…FreeInstall.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = txstate.edu
O17 - HKLM\Software\..\Telephony: DomainName = txstate.edu
O17 - HKLM\System\CCS\Services\Tcpip\..\{748F0FF5-2798-41E0-864F-C6C503F3BDFD}: NameServer = 147.26.8.11,147.26.8.12
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = txstate.edu
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Nortel Networks i2050 QoS Service (i2050QoSSvc) - Nortel Networks Corp. - C:\WINDOWS\system32\i2050QosSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Eastman Kodak Company - C:\WINDOWS\system32\drivers\KodakCCS.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
Only for Windows XP and Windows 2000

Download ATF Cleaner instructions here.

Download AVG Anti-Spyware Instructions and download link can be found here.
Update it but DO NOT run a scan just yet, we will run the scan later.

Download SmitfraudFix (by S!Ri) to your Desktop.
http://siri.urz.free.fr/Fix/SmitfraudFix.zip
Extract all the files to your Destop. A folder named SmitfraudFix will be created on your Desktop.

[external image: Posted Image]

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press Enter

[external image: Posted Image]

This program will scan large amounts of files on your computer for known patterns so please be patient while it works.
It will create a file named: c:\rapport.txt
Please post the C:\rapport.txt in your next reply

IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
Here is the Smit log. SmitFraudFix v2.138 Scan done at 13:55:10.12, Mon 02/05/2007 Run from C:\Documents and Settings\Layne\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Layne »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Layne\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\Layne\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="C:\\Program Files\\WindowsUpdate\\rtelelizu.html" "SubscribedURL"="" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
here is the combo log Layne - 07-02-05 15:40:24.60 Service Pack 2 ComboFix 06.11.27 - Running from: "C:\Documents and Settings\Layne\My Documents\1FIXpc" ((((((((((((((((((((((((((((((( Files Created from 2007-01-05 to 2007-02-05 )))))))))))))))))))))))))))))))))) 2007-02-05 13:55 2,972 –a—— C:\WINDOWS\system32\tmp.reg 2007-02-02 09:01 d——– C:\Program Files\Unit Conversion Tool 2007-01-30 15:20 d——– C:\WINDOWS\A4W_DATA 2007-01-23 11:33 55,296 –a—— C:\WINDOWS\system32\HAESvr.dll 2007-01-23 11:33 3,078 –a—— C:\WINDOWS\system32\HAESvr.Reg 2007-01-23 11:33 1,160,304 –a—— C:\WINDOWS\system32\dcom95.exe 2007-01-23 11:33 1,056,768 –a—— C:\WINDOWS\system32\roboex32.dll 2007-01-19 08:52 d——– C:\Program Files\MEDIC 2007-01-18 15:27 d——– C:\WINDOWS\system32\Kaspersky Lab 2007-01-17 16:06 d——– C:\!KillBox 2007-01-12 15:20 3,968 –a—— C:\WINDOWS\system32\drivers\AvgAsCln.sys 2007-01-12 15:20 d——– C:\Program Files\Grisoft 2007-01-11 13:45 d——– C:\WINDOWS\pss 2007-01-11 07:58 d——– C:\Program Files\Hijackthis 2007-01-10 10:01 d——– C:\Documents and Settings\Layne\Application Data\System Restore (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2007-01-30 15:15 ——– d——– C:\Program Files\Nortel 2007-01-29 13:16 ——– d——– C:\Documents and Settings\Layne\Application Data\AdobeUM 2007-01-23 11:33 ——– d——– C:\Program Files\Helmsman 4.4.1 2007-01-18 10:07 ——– d–h—– C:\Program Files\WindowsUpdate 2007-01-12 15:19 ——– d——– C:\Documents and Settings\Layne\Application Data\U3 2007-01-12 10:17 ——– d——– C:\Program Files\Viewpoint 2007-01-12 09:26 ——– d——– C:\Program Files\Mozilla Firefox 2007-01-10 20:05 ——– d–h—– C:\Program Files\InstallShield Installation Information 2007-01-10 20:05 ——– d——– C:\Program Files\Hewlett-Packard 2007-01-10 20:04 ——– d——– C:\Program Files\Nortel Networks 2006-12-20 10:38 774144 –a—— C:\Program Files\RngInterstitial.dll 2006-12-20 10:38 ——– d——– C:\Program Files\Real 2006-12-20 10:38 ——– d——– C:\Program Files\Common Files\Real 2006-12-20 10:38 ——– d——– C:\Program Files\Common Files 2006-12-18 09:28 ——– d——– C:\Program Files\Internet Explorer 2006-12-18 09:26 ——– d——– C:\Program Files\Outlook Express 2006-12-18 09:26 ——– d——– C:\Program Files\Common Files\System 2006-12-12 14:04 ——– d——– C:\Program Files\Common Files\Viewpoint 2006-12-11 19:53 38512 –a—— C:\Documents and Settings\Layne\Application Data\Comma Separated Values (DOS).ADR 2006-12-06 23:29 2374472 –a—— C:\WINDOWS\system32\wmvcore.dll 2006-12-05 14:32 ——– d——– C:\Program Files\MSXML 4.0 2006-11-27 17:18 1530 –a—— C:\WINDOWS\UnHSDX.bat 2006-11-07 23:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe" "Gadwin PrintScreen 3.1"="C:\\Program Files\\Gadwin Systems\\PrintScreen\\PrintScreen.exe /nosplash" "IE Privacy Keeper"="\"C:\\Program Files\\UnH Solutions\\IE Privacy Keeper\\IEPrivacyKeeper.exe\" -stcleanup" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "Apoint"="C:\\Program Files\\Apoint\\Apoint.exe" "ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe" "Dell Wireless Manager UI"="C:\\WINDOWS\\System32\\WLTRAY" "DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\"" "ShStatEXE"="\"C:\\Program Files\\Network Associates\\VirusScan\\SHSTAT.EXE\" /STANDALONE" "McAfeeUpdaterUI"="\"C:\\Program Files\\Network Associates\\Common Framework\\UpdaterUI.exe\" /StartedFromRunKey" "Network Associates Error Reporting Service"="\"C:\\Program Files\\Common Files\\Network Associates\\TalkBack\\tbmon.exe\"" "ReportListener"="\"C:\\Program Files\\Nortel Networks\\Symposium Call Center Server\\client\\en\\bin\\nicrlstn.exe\"" "dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe" "UpdateManager"="\"C:\\Program Files\\Common Files\\Sonic\\Update Manager\\sgtray.exe\" /r" "QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "Installed"="1" "NoChange"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="C:\\Program Files\\WindowsUpdate\\rtelelizu.html" "SubscribedURL"="" "FriendlyName"="" "Flags"=dword:00002000 "Position"=hex:2c,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,00,00,e8,\ 03,00,00,00,00,00,00,00,00,00,00,00,00,00,00,14,00,00,00,14,00,00,00 "CurrentState"=hex:01,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,64,00,00,00,64,00,00,00,58,02,00,00,c8,00,\ 00,00,01,00,00,40 "RestoredStateInfo"=hex:00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,00,\ 00,00,00,00,00,00 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,00,04,\ 00,00,01,00,00,00 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" "{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] "NoCDBurning"=dword:00000000 [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder C:\WINDOWS\tasks\AppleSoftwareUpdate.job Completion time: 07-02-05 15:42:00.10 C:\ComboFix.txt … 07-02-05 15:42 C:\ComboFix2.txt … 07-01-18 10:53 C:\ComboFix3.txt … 07-01-11 13:17
C:\WINDOWS\system32\HAESvr.dll

I would like to see a copy of the file in bold.

Click start / then my computer / local disk then follow the process tree.
Or using Windows Explorer, locate the first file you want to zip.
Right click on the file and select Send To and Compressed (zipped) Folder.
This makes a copy it does not delete it.
Please zip the file and upload it here
Or email it here

Please include a link to this thread.
Here is the active scan report Incident Status Location Potentially unwanted tool:Application/Processor Not disinfected C:\1Layne\Installs\SmitfraudFix\SmitfraudFix\Process.exe Potentially unwanted tool:Application/Processor Not disinfected C:\1Layne\Installs\SmitfraudFix.zip[SmitfraudFix/Process.exe] Spyware:Cookie/Entrepreneur Not disinfected C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt[.entrepreneur.com/] Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt[.fortunecity.com/] Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Layne\Application Data\Mozilla\Firefox\Profiles\twmd9q2k.default\cookies.txt[.go.com/] Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Layne\Application Data\PowerHouse\DeviceSpecific\b936cd57\Synchronize\Cookies\layne@belnk[1].txt Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Layne\Application Data\PowerHouse\DeviceSpecific\b936cd57\Synchronize\Cookies\[removed][2].txt Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Layne\Application Data\PowerHouse\DeviceSpecific\b936cd57\Synchronize\Cookies\layne@drivecleaner[2].txt Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Layne\Cookies\[removed][2].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Layne\Cookies\layne@adrevolver[1].txt Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Layne\Cookies\layne@adrevolver[2].txt Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Layne\Cookies\layne@advertising[2].txt Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Layne\Cookies\[removed][2].txt Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Layne\Cookies\layne@atdmt[2].txt Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Layne\Cookies\layne@bravenet[2].txt Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Layne\Cookies\layne@casalemedia[2].txt Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Layne\Cookies\layne@doubleclick[1].txt Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Layne\Cookies\layne@drivecleaner[2].txt Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Layne\Cookies\[removed][1].txt Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Layne\Cookies\layne@mediaplex[1].txt Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Layne\Cookies\layne@overture[2].txt Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\Layne\Cookies\layne@paycounter[2].txt Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Layne\Cookies\layne@realmedia[1].txt Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Layne\Cookies\layne@serving-sys[2].txt Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Layne\Cookies\layne@trafficmp[1].txt Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Layne\Cookies\layne@tribalfusion[2].txt Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Layne\Cookies\layne@zedo[2].txt Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Layne\Desktop\SmitfraudFix\Process.exe Hacktool:Hacktool/AngryScan Not disinfected C:\Documents and Settings\Layne\Desktop\stfistuff\ipscan.exe Virus:Bck/Haxdoor.NJ Disinfected Personal Folders\Inbox\Order ID : 37679041 Is Being Processed\37679041.zip[37679041.exe]
Can you run AVG anti-spyware delete everything then save the report.

Can I see this file
C:\Documents and Settings\Layne\Desktop\stfistuff\ipscan.exe
Teacher, I e-mailed the file to little_eagle. I use the application to moniter my VOIP sets. I ran AVG, deleted everything it found and the log follows. ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 10:50:55 AM 2/8/2007 + Scan result: C:\System Volume Information\_restore{D07A54C1-A616-4980-8BA8-65482CE0F0FA}\RP336\A0063652.exe -> Hijacker.VB.pm : No action taken. C:\Documents and Settings\Layne\Cookies\layne@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Addynamix : No action taken. C:\Documents and Settings\Layne\Cookies\layne@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken. C:\Documents and Settings\Layne\Cookies\layne@advertising[1].txt -> TrackingCookie.Advertising : No action taken. C:\Documents and Settings\Layne\Cookies\layne@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken. C:\Documents and Settings\Layne\Cookies\layne@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : No action taken. C:\Documents and Settings\Layne\Cookies\layne@burstnet[2].txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : No action taken. C:\Documents and Settings\Layne\Cookies\layne@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken. C:\Documents and Settings\Layne\Cookies\layne@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : No action taken. C:\Documents and Settings\Layne\Cookies\layne@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Falkag : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Falkag : No action taken. C:\Documents and Settings\Layne\Cookies\layne@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Fastclick : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Information : No action taken. C:\Documents and Settings\Layne\Cookies\layne@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken. C:\Documents and Settings\Layne\Cookies\layne@overture[2].txt -> TrackingCookie.Overture : No action taken. C:\Documents and Settings\Layne\Cookies\layne@paycounter[2].txt -> TrackingCookie.Paycounter : No action taken. C:\Documents and Settings\Layne\Cookies\layne@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken. C:\Documents and Settings\Layne\Cookies\layne@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken. C:\Documents and Settings\Layne\Cookies\layne@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken. C:\Documents and Settings\Layne\Cookies\layne@serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : No action taken. C:\Documents and Settings\Layne\Cookies\layne@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Layne\Cookies\layne@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken. C:\Documents and Settings\Layne\Cookies\layne@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken. C:\Documents and Settings\Layne\Cookies\layne@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Valuead : No action taken. C:\Documents and Settings\Layne\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : No action taken. C:\Documents and Settings\Layne\Cookies\layne@zedo[2].txt -> TrackingCookie.Zedo : No action taken. ::Report end
To reset your restore points, please note that you will need to log into your computer with an account which has full administrator access. You will know if the account has administrator access because you will be able to see the System Restore tab. If the tab is missing, you are logged in under a limited account. 1. Turn off System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. Check Turn off System Restore. Click Apply, and then click OK. 2. Reboot. 3. Turn ON System Restore. On the Desktop, right-click My Computer. Click Properties. Click the System Restore tab. UN-Check *Turn off System Restore*. Click Apply, and then click OK.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI