This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Kernel Fault Check

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried to delete a message, "kernelfaultcheck, c:\windows\system32\dumprep0 -k" from start up but unsuccessfully. Here is my log, hope you can help. Thanx.

Logfile of HijackThis v1.99.1
Scan saved at 1:24:10 PM, on 1/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\Hijack This\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164120998312
O16 - DPF: {DABFA9AD-4E31-43F4-9D60-4CDD20F57F28} (PhotomaxUploader.ActiveXControl) - http://www.photomax.com/web/PhotomaxUploader.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Right clicking on My Computer, selecting Properties and then the Advanced tab. Click on the Settings button in 'Startup and Recovery'. In the bottom pane - under 'Write debugging information' - click on the down arrow and then select 'None' -

Sorry for the delay :oops:
If you still need help and haven't posted at another forum.

Download and install AVG Anti-Spyware (ewido). Then scan and save the log from the scan.
Instructions and download link can be found here.

Then run this online scan. Save the report.

Rescan with hijackthis and post a new log with the results from AVG .
Also please describe how your computer behaves at the moment.
Thanks very much for your reply. Here are my logs. The F-Secure scan found 1 virus and 5 malware. I assume it has cleaned them from the PC.

Generally, the PC runs OK but it freezes occasionally and I have had a couple of blue screens which have cleared, thankfully after restarting.

Logfile of HijackThis v1.99.1
Scan saved at 10:59:02 AM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164120998312
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {DABFA9AD-4E31-43F4-9D60-4CDD20F57F28} (PhotomaxUploader.ActiveXControl) - http://www.photomax.com/web/PhotomaxUploader.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:59:15 AM 2/11/2007

+ Scan result:



C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adviva[1].txt -> TrackingCookie.Adviva : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@com[2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Neil\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Maisie\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@zedo[1].txt -> TrackingCookie.Zedo : No action taken.


::Report end

Scanning Report
Monday, February 12, 2007 10:14:28 - 10:49:14
Computer name: NEIL-A672D62AD1
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\


——————————————————————————–

Result: 5 malware found
Tracking Cookie (spyware)
System (Disinfected)
System
System
System
W32/DLoader.AMSO (virus)
C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE (Submitted)

——————————————————————————–

Statistics
Scanned:
Files: 30376
System: 4261
Not scanned: 4
Actions:
Disinfected: 1
Renamed: 0
Deleted: 0
None: 4
Submitted: 1
Files not scanned:
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\DOCUMENTS AND SETTINGS\NEIL\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{847530BA-5C3D-48EA-8C7D-FE862C4F4022}
C:\DOCUMENTS AND SETTINGS\HANNAH\LOCAL SETTINGS\TEMP\HSPERFDATA_HANNAH\2240

——————————————————————————–

Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-02-01
F-Secure AVP: 7.0.171, 2007-02-12
F-Secure Orion: 1.2.37, 2007-02-10
F-Secure Blacklight: 1.0.53, 0000-00-00
F-Secure Draco: 1.0.35, 2007-02-09
F-Secure Pegasus: 1.19.0, 2007-01-07
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
Use Advanced heuristics


I look forward to your reply.
Just one thing - if I did get a virus, did it get through my AVG? I keep it updated daily.

Thanks
Neilski
Thanks very much for your reply. Here are my logs. The F-Secure scan found 1 virus and 5 malware. I assume it has cleaned them from the PC.

Generally, the PC runs OK but it freezes occasionally and I have had a couple of blue screens which have cleared, thankfully after restarting.

Logfile of HijackThis v1.99.1
Scan saved at 10:59:02 AM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164120998312
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {DABFA9AD-4E31-43F4-9D60-4CDD20F57F28} (PhotomaxUploader.ActiveXControl) - http://www.photomax.com/web/PhotomaxUploader.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:59:15 AM 2/11/2007

+ Scan result:



C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adrevolver[2].txt -> TrackingCookie.Adrevolver : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adtech[2].txt -> TrackingCookie.Adtech : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@advertising[2].txt -> TrackingCookie.Advertising : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adviva[1].txt -> TrackingCookie.Adviva : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@atdmt[1].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@casalemedia[1].txt -> TrackingCookie.Casalemedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@com[1].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@com[2].txt -> TrackingCookie.Com : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
C:\Documents and Settings\Neil\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@overture[1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Overture : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Maisie\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@realmedia[1].txt -> TrackingCookie.Realmedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@targetnet[1].txt -> TrackingCookie.Targetnet : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@webstat[1].txt -> TrackingCookie.Web-stat : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : No action taken.
C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Neil\Cookies\neil@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@zedo[1].txt -> TrackingCookie.Zedo : No action taken.


::Report end

Scanning Report
Monday, February 12, 2007 10:14:28 - 10:49:14
Computer name: NEIL-A672D62AD1
Scanning type: Scan system for viruses, rootkits, spyware
Target: C:\ D:\


——————————————————————————–

Result: 5 malware found
Tracking Cookie (spyware)
System (Disinfected)
System
System
System
W32/DLoader.AMSO (virus)
C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE (Submitted)

——————————————————————————–

Statistics
Scanned:
Files: 30376
System: 4261
Not scanned: 4
Actions:
Disinfected: 1
Renamed: 0
Deleted: 0
None: 4
Submitted: 1
Files not scanned:
C:\PAGEFILE.SYS
C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT
C:\DOCUMENTS AND SETTINGS\NEIL\LOCAL SETTINGS\APPLICATION DATA\MICROSOFT\WINDOWS DEFENDER\FILETRACKER\{847530BA-5C3D-48EA-8C7D-FE862C4F4022}
C:\DOCUMENTS AND SETTINGS\HANNAH\LOCAL SETTINGS\TEMP\HSPERFDATA_HANNAH\2240

——————————————————————————–

Options
Scanning engines:
F-Secure Libra: 2.4.2, 2007-02-01
F-Secure AVP: 7.0.171, 2007-02-12
F-Secure Orion: 1.2.37, 2007-02-10
F-Secure Blacklight: 1.0.53, 0000-00-00
F-Secure Draco: 1.0.35, 2007-02-09
F-Secure Pegasus: 1.19.0, 2007-01-07
Scanning options:
Scan defined files: COM EXE SYS OV? BIN SCR DLL SHS HTM HTML HTT VBS JS INF VXD DO? XL? RTF CPL WIZ HTA PP? PWZ P?T MSO PIF . ACM ASP AX CNV CSC DRV INI MDB MPD MPP MPT OBD OBT OCX PCI TLB TSP WBK WBT WPC WSH VWP WML BOO HLP TD0 TT6 MSG ASD JSE VBE WSC CHM EML PRC SHB LNK WSF {* PDF ZL? XML ZIP XXX
Use Advanced heuristics


I look forward to your reply.
Just one thing - if I did get a virus, did it get through my AVG? I keep it updated daily.

Thanks
Neilski
Can you scan with AVG anti-spyware again.
This time delete everything it fins then save the log.

C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@247realmedia[1].txt -> TrackingCookie.247realmedia : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Maisie\Cookies\maisie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
C:\Documents and Settings\Hannah\Cookies\hannah@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.


Just one thing - if I did get a virus, did it get through my AVG? I keep it updated daily.

I really have no idea how it might have gotten there. Drive by hacker, email attachment, or download.
Here's the AVG scan after deletions ——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 1:24:59 PM 2/12/2007 + Scan result: C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Ignored. C:\Documents and Settings\Hannah\Cookies\hannah@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@mediauk.247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Neil\Cookies\neil@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@adtech[2].txt -> TrackingCookie.Adtech : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@advertising[2].txt -> TrackingCookie.Advertising : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@adviva[1].txt -> TrackingCookie.Adviva : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@com[1].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Neil\Cookies\neil@com[2].txt -> TrackingCookie.Com : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Euroclick : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned. C:\Documents and Settings\Neil\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned. C:\Documents and Settings\Neil\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Maisie\Cookies\maisie@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@overture[1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Maisie\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@targetnet[1].txt -> TrackingCookie.Targetnet : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned. C:\Documents and Settings\Neil\Cookies\neil@webstat[1].txt -> TrackingCookie.Web-stat : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned. C:\Documents and Settings\Hannah\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Neil\Cookies\neil@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned. C:\Documents and Settings\Hannah\Cookies\hannah@zedo[1].txt -> TrackingCookie.Zedo : Cleaned. ::Report end

Here's the AVG scan after deletions

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 1:24:59 PM 2/12/2007

+ Scan result:



C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Ignored.
::Report end

Is there some reason these was not deleted??
Here's the log. There are no apparent problems with the running of the computer.
There is a "dumprep 0 -k" item in the start up menu. Should this still be here?

Logfile of HijackThis v1.99.1
Scan saved at 8:13:14 AM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {2AF5BD25-90C5-4EEC-88C5-B44DC2905D8B} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/vers…vex-2.0.6.5.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1164120998312
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O16 - DPF: {DABFA9AD-4E31-43F4-9D60-4CDD20F57F28} (PhotomaxUploader.ActiveXControl) - http://www.photomax.com/web/PhotomaxUploader.CAB
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI