This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Think-Adz problem

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

so, i have think-adz on my computer. dont know how it got there or anything. i tried to just remove it from add/remove programmes, but has returned within 24 hours.

i hvae run avg, and spybot, but they havent seemed to help.

problems include, constant pop-ups, even when firefox/internet explorer isn't open, and also sometimes my coputer starts making sounds like a fly buzzing, kisses, or sometimes what sounds like "i love you". and this repeats for about an hour, and then stops. highly frustrating.

any help would be appreciated.

Logfile of HijackThis v1.99.1
Scan saved at 17:18:29, on 31/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\DOCUME~1\HILARY~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\stickies\stickies.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\QuickTime\QuickTimePlayer.exe
C:\WINDOWS\explorer.exe
C:\Program Files\SpywareBot\Scheduler.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\Rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\DOCUME~1\HILARY~1\LOCALS~1\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: mycpmads.com Browser Optimizer - {582FDCF0-A82E-4fc1-A6F6-0D2F36881F63} - C:\WINDOWS\system32\br_rt.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [ExploreUpdSched] C:\WINDOWS\system32\nwintoed.exe CHA001
O4 - HKLM\..\Run: [adstart] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\br_rt.dll" DllVerify
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: Stickies.lnk = C:\Program Files\stickies\stickies.exe
O4 - Startup: Think-Adz.lnk = C:\WINDOWS\system32\nwintoed.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139924424169
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1140524105359
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU…_1/axofupld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
Hi mushroome and welcome to the Forums :)

You're infected.

HijackThis is in an unsafe location. Please download HijackThis to your desktop from here

Create a new folder for HijackThis and move HijackThis.exe into it.


1. Download this file - combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply along with a fresh HIjackThis log

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
"Hilary Milne" - 07-02-01 17:36:15 Service Pack 2
ComboFix 07.01.31 - Running from: "C:\Program Files\Mozilla Firefox"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\WinNB58.dll


((((((((((((((((((((((((((((((( Files Created from 2007-01-01 to 2007-02-01 ))))))))))))))))))))))))))))))))))


2007-02-01 17:28 d——– C:\DOCUME~1\HILARY~1\Application Data\Logitech
2007-02-01 17:26 71,936 –a—— C:\WINDOWS\system32\drivers\LMouKE.Sys
2007-02-01 17:26 55,936 –a—— C:\WINDOWS\system32\drivers\L8042MOU.SYS
2007-02-01 17:26 13,568 –a—— C:\WINDOWS\system32\drivers\L8042Kbd.SYS
2007-02-01 17:25 94,208 –a—— C:\WINDOWS\KHALMNPR.Exe
2007-02-01 17:25 69,632 –a—— C:\WINDOWS\system32\KemXML.dll
2007-02-01 17:25 3,712 –a—— C:\WINDOWS\system32\drivers\LBeepKE.sys
2007-02-01 17:25 27,136 –a—— C:\WINDOWS\system32\drivers\LHidKE.Sys
2007-02-01 17:25 155,648 –a—— C:\WINDOWS\system32\kemutb.dll
2007-02-01 17:25 131,072 –a—— C:\WINDOWS\system32\KemUtil.dll
2007-02-01 17:25 110,592 –a—— C:\WINDOWS\system32\KemWnd.dll
2007-01-31 16:14 d——– C:\Program Files\SpywareBot
2007-01-21 03:10 5,632 –a—— C:\WINDOWS\system32\drivers\StarOpen.sys
2007-01-21 00:24 d——– C:\Program Files\Enigma Software Group
2007-01-08 11:27 61,440 –a—— C:\WINDOWS\system32\br_rt.dll
2007-01-05 23:22 d——– C:\DOCUME~1\HILARY~1\Application Data\TransRender
2007-01-05 23:22 d——– C:\DOCUME~1\HILARY~1\Application Data\Temporary
2007-01-05 23:22 d——– C:\DOCUME~1\HILARY~1\Application Data\Samsung
2007-01-05 23:22 d——– C:\DOCUME~1\HILARY~1\Application Data\ConvertTemp
2007-01-05 21:44 94,000 –a—— C:\WINDOWS\system32\drivers\ssm_mdm.sys
2007-01-05 21:44 8,336 –a—— C:\WINDOWS\system32\drivers\ssm_mdfl.sys
2007-01-05 21:44 77,824 –a—— C:\WINDOWS\system32\fun_mp4_dec.dll
2007-01-05 21:44 684,032 –a—— C:\WINDOWS\system32\fun_mp4_enc.dll
2007-01-05 21:44 6,176 –a—— C:\WINDOWS\system32\drivers\ssm_cmnt.sys
2007-01-05 21:44 6,176 –a—— C:\WINDOWS\system32\drivers\ssm_cm.sys
2007-01-05 21:44 58,320 –a—— C:\WINDOWS\system32\drivers\ssm_bus.sys
2007-01-05 21:44 5,840 –a—— C:\WINDOWS\system32\drivers\ssm_whnt.sys
2007-01-05 21:44 5,840 –a—— C:\WINDOWS\system32\drivers\ssm_wh.sys
2007-01-05 21:44 2,729,472 –a—— C:\WINDOWS\system32\fun_avcodec.dll
2007-01-05 21:44 d——– C:\WINDOWS\system32\Samsung_USB_Drivers
2007-01-05 21:44 d——– C:\WINDOWS\system32\Samsung PC Studio Codecs
2007-01-05 21:44 d——– C:\Program Files\Samsung
2007-01-02 15:25 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Spybot - Search & Destroy
2007-01-01 23:28 d——– C:\DOCUME~1\HILARY~1\Application Data\Lavasoft
2007-01-01 23:27 d——– C:\Program Files\Lavasoft
2007-01-01 22:59 3,968 –a—— C:\WINDOWS\system32\drivers\avgclean.sys
2007-01-01 22:59 18,240 –a—— C:\WINDOWS\system32\drivers\avgmfx86.sys


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-01 17:36 ——– d——– C:\Program Files\mozilla firefox
2007-02-01 17:25 ——– d–h—– C:\Program Files\installshield installation information
2007-02-01 17:25 ——– d——– C:\Program Files\logitech
2007-02-01 08:43 ——– d——– C:\DOCUME~1\HILARY~1\Application Data\avg7
2007-01-31 16:17 ——– d——– C:\Program Files\msn games
2007-01-15 20:26 217329 –a—— C:\DOCUME~1\HILARY~1\Application Data\com.kennettnet.podutil.plist
2007-01-11 16:38 ——– d——– C:\DOCUME~1\HILARY~1\Application Data\adobeum
2007-01-10 14:33 39745 –a—— C:\WINDOWS\system32\br_rt-uninst.exe
2007-01-02 15:47 49 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb41.dat
2007-01-02 15:47 382 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb1942.dat
2007-01-01 23:07 ——– d——– C:\Program Files\e-campaign
2007-01-01 23:05 ——– d——– C:\DOCUME~1\HILARY~1\Application Data\skype
2007-01-01 23:03 ——– d——– C:\Program Files\aim
2007-01-01 22:59 816672 –a—— C:\WINDOWS\system32\drivers\avg7core.sys
2007-01-01 22:59 4224 –a—— C:\WINDOWS\system32\drivers\avg7rsw.sys
2007-01-01 22:59 28416 –a—— C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-28 11:11 930 –a—— C:\WINDOWS\system32\winpfz32.sys
2006-12-28 11:11 9216 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb8467.dat
2006-12-28 11:11 66267 –a—— C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
2006-12-28 11:11 622613 –a—— C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
2006-12-28 11:11 45056 –a—— C:\WINDOWS\19-13830fd1a8a5137f57332f003822f774.exe
2006-12-28 11:11 44888 –a—— C:\WINDOWS\system32\caunst.exe
2006-12-28 11:11 417792 –a—— C:\WINDOWS\system32\tcblnsbl.dll
2006-12-28 11:11 36864 –a—— C:\WINDOWS\system32\slimtypi.exe
2006-12-28 11:11 356663 –a—— C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
2006-12-28 11:11 24576 –a—— C:\WINDOWS\system32\msxml3a.dll
2006-12-28 11:11 23 –a—— C:\DOCUME~1\HILARY~1\Application Data\inifile41.ini
2006-12-28 11:11 20480 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb4827.dat
2006-12-28 11:11 184398 –a—— C:\WINDOWS\system32\nwintoed.exe
2006-12-28 11:11 139264 –a—— C:\WINDOWS\mirar_distro_876088.exe
2006-12-28 11:11 116138 –a—— C:\WINDOWS\18-979cccfcc7622e89302a49c23b6fa37a.exe
2006-12-28 11:11 0 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb6334.dat
2006-12-28 11:11 0 –a—— C:\DOCUME~1\HILARY~1\Application Data\internaldb5436.dat
2006-12-07 04:14 2330624 –a—— C:\WINDOWS\system32\wmvcore.dll
2006-11-08 05:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll
2006-11-04 14:14 1245696 –a—— C:\WINDOWS\system32\msxml4.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"ModemOnHold"="C:\\Program Files\\NetWaiting\\netWaiting.exe"
"SetDefaultMIDI"="MIDIDef.exe"
"Creative Detector"="\"C:\\Program Files\\Creative\\MediaSource\\Detector\\CTDetect.exe\" /R"
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"LogitechSoftwareUpdate"="\"C:\\Program Files\\Logitech\\Video\\ManifestEngine.exe\" boot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ehTray"="C:\\WINDOWS\\ehome\\ehtray.exe"
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"SigmatelSysTrayApp"="stsystra.exe"
"ATIPTA"="\"C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe\""
"CTSysVol"="C:\\Program Files\\Creative\\SBAudigy\\Surround Mixer\\CTSysVol.exe /r"
"MBMon"="Rundll32 CTMBHA.DLL,MBMon"
"UpdReg"="C:\\WINDOWS\\UpdReg.EXE"
"VoiceCenter"="\"C:\\Program Files\\Creative\\VoiceCenter\\AndreaVC.exe\" /tray"
"ISUSPM Startup"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\isuspm.exe\" -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"DLA"="C:\\WINDOWS\\System32\\DLA\\DLACTRLW.EXE"
"MSKDetectorExe"="C:\\Program Files\\McAfee\\SpamKiller\\MSKDetct.exe /uninstall"
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgcc.exe /STARTUP"
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Elements 4.0\\apdproxy.exe\""
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"LVCOMSX"="C:\\WINDOWS\\system32\\LVCOMSX.EXE"
"LogitechVideoRepair"="C:\\Program Files\\Logitech\\Video\\ISStart.exe "
"LogitechVideoTray"="C:\\Program Files\\Logitech\\Video\\LogiTray.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""
"Logitech Hardware Abstraction Layer"="\"C:\\Program Files\\Common Files\\Logitech\\khalshared\\KHALMNPR.EXE\""
@=""
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVGFRE~1\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,\
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,\
6d,73,73,74,79,6c,65,73,00
"InstallTheme"=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,\
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0


[HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
Shell\AutoRun\command E:\setup.exe


Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1139941863.job

Completion time: 07-02-01 17:40:23






–NEW HIJACK THIS LOG:

Logfile of HijackThis v1.99.1
Scan saved at 17:42:49, on 01/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\DOCUME~1\HILARY~1\LOCALS~1\Temp\clclean.0001
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\stickies\stickies.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Documents and Settings\Hilary Milne\Desktop\ijack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: mycpmads.com Browser Optimizer - {582FDCF0-A82E-4fc1-A6F6-0D2F36881F63} - C:\WINDOWS\system32\br_rt.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: Stickies.lnk = C:\Program Files\stickies\stickies.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139924424169
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1140524105359
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU…_1/axofupld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe






another problem is occuring where, my mouse seems to freeze after a series of "clicky" noises from my computer. this may just be a dodgey mouse, although its pretty new, or something to do with the infcection

thank you for your time
Hi again, we'll continue :)


You seem to have this MyWaySA software installed. It has a suspicious reputation and I recommend that you remove it via Control Panel, Add/Remove programs.

These are the lines to fix with HijackThis,
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DK
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll

This is the folder to delete, C:\Program Files\MyWaySA

You should print these instructions or save these to a text file. Follow these instructions carefully.

Please download AVG Anti-Spyware to your Desktop or to your usual Download Folder.
http://www.ewido.net/en/download/
  • Install AVG Anti-Spyware by double clicking the installer.
  • Follow the prompts. Make sure that Launch AVG Anti-Spyware is checked.
  • On the main screen under Your Computer's security.
    • Click on Change state next to Resident shield. It should now change to inactive.
    • Click on Change state next to Automatic updates. It should now change to inactive.
    • Next to Last Update, click on Update now. (You will need an active internet connection to perform this)
    • Wait until you see the Update succesfull message.
  • Right-click the AVG Anti-Spyware Tray Icon and uncheck Start with Windows.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
If you are having problems with the updater, you can use this link to manually update ewido.
AVG Anti-Spyware manual updates.
Download the Full database to your Desktop or to your usual Download Folder and install it by double clicking the file. Make sure that AVG Anti-Spyware is closed before installing the update.

Download ATF Cleaner by Atribune to your desktop.
Do NOT run yet.

Please download the Killbox.
Unzip it to the desktop but do NOT run it yet.

==================

Open Control Panel -> Add/Remove programs -> Remove all the of the following or similar entries if found:
MyCPMads

and any other programs you didn't install or don't recognize - if your not sure please ask first

Run HijackThis, click Do a system scan only, and check the box next to each of these entries if still present. Close all other windows and press Fix checked. If something isn't there, please continue with the next entry in the list.
O2 - BHO: mycpmads.com Browser Optimizer - {582FDCF0-A82E-4fc1-A6F6-0D2F36881F63} - C:\WINDOWS\system32\br_rt.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

Please run Killbox.

Select "Delete on Reboot".

Copy the file names below to the clipboard by highlighting them and pressing Control-C:

C:\WINDOWS\system32\br_rt-uninst.exe
C:\Documents and Settings\Hilary Milne\Application Data\internaldb41.dat
C:\Documents and Settings\Hilary Milne\Application Data\internaldb1942.dat
C:\WINDOWS\system32\winpfz32.sys
C:\WINDOWS\system32\br_rt.dll
C:\Documents and Settings\Hilary Milne\Application Data\internaldb8467.dat
C:\WINDOWS\10-47488c40c3cddfee98fc3b173f6d7beb.exe
C:\WINDOWS\4-efb7bab6499fc415ee93f4097033deae.exe
C:\WINDOWS\19-13830fd1a8a5137f57332f003822f774.exe
C:\WINDOWS\system32\caunst.exe
C:\WINDOWS\system32\tcblnsbl.dll
C:\WINDOWS\system32\slimtypi.exe
C:\WINDOWS\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe
C:\Documents and Settings\Hilary Milne\Application Data\internaldb4827.dat
C:\WINDOWS\system32\nwintoed.exe
C:\WINDOWS\mirar_distro_876088.exe
C:\WINDOWS\18-979cccfcc7622e89302a49c23b6fa37a.exe
C:\Documents and Settings\Hilary Milne\Application Data\internaldb6334.dat
C:\Documents and Settings\Hilary Milne\Application Data\internaldb5436.dat

Return to Killbox, go to the File menu, and choose "Paste from Clipboard".

Select "All Files".

Click the red-and-white "Delete File" button. Click "Yes" at the Delete on Reboot prompt. Click "No" at the Pending Operations prompt.

If your computer does not restart automatically, please restart it manually.

Restart your computer to the safe mode:
  • Restart your computer
  • Start tapping the F8 key when the computer restarts.
  • When the start menu opens, choose Safe mode
  • Press Enter. The computer then begins to start in Safe mode.
Run ATF Cleaner Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.

Close ALL open Windows / Programs / Folders. Please start AVG Anti-Spyware and run a full scan.
  • Click on Scanner on the toolbar.
  • Click on the Settings tab.
    • Under How to act?
      • Click on Recommended Action and choose Quarantine from the popup menu.
    • Under How to scan?
      • All checkboxes should be ticked.
    • Under Possibly unwanted software:
      • All checkboxes should be ticked.
    • Under Reports:
      • Select Automatically generate report after every scan and uncheck Only if threats were found.
    • Under What to scan?
      • Select Scan every file.
  • Click on the Scan tab.
  • Click on Complete System Scan to start the scan process.
  • Let the program scan the machine.
  • When the scan has finished, follow the instructions below.
    IMPORTANT : Don't click on the "Save Scan Report" button before you did hit the "Apply all Actions" button.
    • Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2)
    • At the bottom of the window click on the Apply all Actions button. (3)
      [external image: Posted Image]
  • When done, click the Save Scan Report button. (4)
    • Click the Save Report as button.
    • Save the report to your Desktop.
  • Right-click the AVG Anti-Spyware Tray Icon and select Exit. Confirm by clicking Yes.
Reboot in Normal Mode.

================

When you're ready, please post the following logs to here:
- AVG's report
- a fresh HijackThis log
hijack this report:

Logfile of HijackThis v1.99.1
Scan saved at 21:06:13, on 01/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\PRISMSVR.EXE
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Creative\VoiceCenter\AndreaVC.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\DOCUME~1\HILARY~1\LOCALS~1\Temp\clclean.0001
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\NetWaiting\netWaiting.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
C:\Program Files\AVerTV 6.0\AVerQT.exe
C:\Program Files\Dell Wireless\PRISMCFG.exe
C:\Program Files\stickies\stickies.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Documents and Settings\Hilary Milne\Desktop\andrews\HijackThis.exe
C:\Documents and Settings\Hilary Milne\Desktop\andrews\HijackThis.exe
C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Logitech\SetPoint\LULnchr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Logitech\SetPoint\LogitechUpdate.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\iTunes\iTunes.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [MBMon] Rundll32 CTMBHA.DLL,MBMon
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VoiceCenter] "C:\Program Files\Creative\VoiceCenter\AndreaVC.exe" /tray
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 4.0\apdproxy.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] "C:\Program Files\Common Files\Logitech\khalshared\KHALMNPR.EXE"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [SetDefaultMIDI] MIDIDef.exe
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - Startup: Stickies.lnk = C:\Program Files\stickies\stickies.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: Logitech SetPoint.lnk = ?
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: QuickTV6.lnk = C:\Program Files\AVerTV 6.0\AVerQT.exe
O4 - Global Startup: Wireless USB 2.0 WLAN Card Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab46479.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {339234B4-4E14-4280-B8B4-8BAE5AF99063} (Chess Object) - http://zone.msn.com/bingame/zpagames/zpa_kqrp.cab48295.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab32846.cab
O16 - DPF: {4E62C4DE-627D-4604-B157-4B7D6B09F02E} (AccountTracking Profile Manager Class) - https://moneymanager.egg.com/Pinsafe/accounttracking.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by106fd.bay106.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab32846.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1139924424169
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1140524105359
O16 - DPF: {6F750200-1362-4815-A476-88533DE61D0C} (Ofoto Upload Manager Class) - http://adobe.kodakgallery.com/downloads/BU…_1/axofupld.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www3.ca.com/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {AE9DCB17-F804-11D2-A44A-0020182C1446} (IntraLaunch.MainControl) - file://D:\SuperCD\IntraLaunch.CAB
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab47946.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab41227.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 4.0\PhotoshopElementsFileAgent.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Creative Labs Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe




AVG report:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 21:00:57 01/02/2007

+ Scan result:



C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP353\snapshot\MFEX-1.DAT -> Adware.Beginto : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SearchTool\nsg11.dll -> Adware.Beginto : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP387\A0047750.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\!KillBox\mirar_distro_876088.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047799.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP353\A0044795.dll -> Adware.SearchEnh : Cleaned with backup (quarantined).
C:\!KillBox\12-b101c483c2fe3ac4a2bd5fae3377ef4f.exe -> Adware.SearchTool : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047797.exe -> Adware.SearchTool : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SearchTool\SearchTool.dll -> Adware.SearchTool : Cleaned with backup (quarantined).
C:\!KillBox\4-efb7bab6499fc415ee93f4097033deae.exe -> Adware.SmartShoppe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047792.exe -> Adware.SmartShoppe : Cleaned with backup (quarantined).
C:\WINDOWS\system32\SmartShopper\SmartShopper0.dll -> Adware.SmartShoppe : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP353\A0044796.dll -> Adware.SmartShopper : Cleaned with backup (quarantined).
C:\!KillBox\19-13830fd1a8a5137f57332f003822f774.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\!KillBox\nwintoed.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP357\A0045176.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP357\A0045177.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047793.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047798.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\!KillBox\tcblnsbl.dll -> Downloader.Age : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047795.dll -> Downloader.Age : Cleaned with backup (quarantined).
C:\!KillBox\10-47488c40c3cddfee98fc3b173f6d7beb.exe -> Downloader.Age.c : Cleaned with backup (quarantined).
C:\!KillBox\CAUnst.exe -> Downloader.Age.c : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047791.exe -> Downloader.Age.c : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{129201FA-B0AC-49B3-96B2-DEB8B91E727B}\RP388\A0047794.exe -> Downloader.Age.c : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
:mozilla.224:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.225:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.136:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.137:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.139:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.140:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.141:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.142:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.143:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.144:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.145:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.146:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.147:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.148:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.149:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.150:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.151:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.152:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.153:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.154:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.155:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.156:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.157:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.158:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.159:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.221:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.298:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.392:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.629:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.696:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.723:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.250:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.251:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.271:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.272:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.53:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.54:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.79:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.855:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.856:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.857:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.359:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.902:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.34:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.35:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.36:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.37:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.38:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.40:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.41:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.42:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.395:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Com : Cleaned.
:mozilla.83:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.430:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.431:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.432:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.433:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.434:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.435:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.436:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.437:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.438:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.439:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.440:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.441:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.442:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.443:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.444:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.445:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.446:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.447:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.448:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.449:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.450:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.451:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.254:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.255:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.256:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.257:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.258:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.319:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.101:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.102:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.103:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.914:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.915:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.916:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.549:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.871:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.872:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.873:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.876:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.877:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.878:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.116:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.831:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.933:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
:mozilla.711:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.712:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.713:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.728:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.267:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.268:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.269:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.270:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.750:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.751:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.753:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.754:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.755:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.756:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.84:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.85:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.86:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.87:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.770:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.473:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.474:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.475:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.476:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.477:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.118:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.119:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.120:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.121:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.122:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.123:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.887:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.888:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Sitestat : Cleaned.
:mozilla.261:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.172:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.173:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.808:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.809:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.810:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.219:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.814:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.815:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.816:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.817:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.818:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.819:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.820:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.117:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.125:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.10:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.11:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.12:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.13:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.14:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.15:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.30:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.9:C:\Documents and Settings\Hilary Milne\Application Data\Mozilla\Firefox\Profiles\21zhzplr.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end



thanks for your help so far!
Hi again, it is looking good now :)
How is the computer running ?

Fix this leftover with HijackThis:
O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - (no file)

Make your hidden files visible:
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Uncheck "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
Go to the My Computer and delete the following folder (if present):
C:\WINDOWS\system32\SearchTool
C:\WINDOWS\system32\SmartShopper

Now you can clean AVG's Quarantine:
  • Open AVG Anti-Spyware
  • Click Infections
  • Click Quarantine tab
  • Click Select all
  • Click Remove finally
  • Close the program
You can remove the tools we used.

Then you should update your Java to the latest version (6.0)
  • Start
  • Control Panel
  • Add/Remove Programs
  • Delete the old Java, J2SE Runtime Environment 5.0 Update 6
  • Download the latest version of Java Runtime Environment (JRE) 6.0.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications."
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement."
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Install it
Now you can make your hidden files hidden again.
  • Go to My Computer
  • Select the Tools menu and click Folder Options
  • Click the View tab.
  • Checkmark the "Display the contents of system folders"
  • Under the Hidden files and folders select "Show hidden files and folders"
  • Check "Hide protected operating system files"
  • Click Apply and then the OK and close My Computer.
=============

Now that you seem to be clean, please follow these simple steps in order to keep your computer clean and secure:
  • Clear your system restore
    This will clear the system restore folders from possible malware that was left behind during the cleaning process.
  • Use ATF Cleaner
    Download and install ATF Cleaner. Clean your temporary files & folders with it regularly.
  • Use Ad-Aware
    Download and install Ad-Aware. Update it and scan your computer regularly with it.
  • Use AVG Anti-Spyware
    Update it and scan your computer regularly with it.
  • Use Spybot S&D
    Download and install Spybot S&D. Update it and scan your computer regularly with it.
  • Install SpywareBlaster
    SpywareBlaster will prevent spyware from being installed.
  • Install MVPS Hosts file
    This prevents your computer from connecting to harmful sites.
  • Use Firefox browser
    Firefox is faster, safer and better browser than Internet Explorer.
  • Keep your systen up-to-date
    Visit Windows Update regularly.
  • Keep your antivirus and firewall up-to-date
    Scan your computer regularly with your antivirus.
  • Read this article by TonyKlein
    So how did I get infected in the first place?
  • Stand Up and Be Counted !
    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.
Stay clean and be safe ;)
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI