This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow PC and Popup. Plz Help.

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

Just yesterday my computer started running really slow. I ran spybot and ad-aware, but they didn't help. For a week now, I've been getting an "ad.yeildmanager" pop-up, and now my computer is running slow. Your help is really appreciated. :)

-Jason



Logfile of HijackThis v1.99.1
Scan saved at 2:27:17 AM, on 2/3/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
c:\PROGRA~1\mcafee.com\vso\OasClnt.exe
c:\program files\mcafee.com\vso\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Apoint\Apntex.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Documents and Settings\Jason\My Documents\Downloaded Program Updates\Hi Jack This Program\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
Welcome to the forum - not much showing in the log - Lets do this:

Clean out temp files:

Download and run ATF Cleaner - hit "select all" then click "empty selected" That will clear out all the temp files on the system.

——————
Next…..

1. Download combofix.exe from one of the links below:

http://download.bleepingcomputer.com/sUBs/combofix.exe
http://www.techsupportforum.com/sectools/combofix.exe

2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall

—————–

Next….

Please download and install the 30 day trial version of AVG Anti-Spyware 7.5 here:
http://www.ewido.net/en/download/

After it's installed…Check for updates:
Double click on the AVG-AS icon in the system tray or on the desktop> this will bring up the main program if it's not already up.

On the Main Page click the Update Tab and then Start Update.
Download and install any updates if available.

Select the Scanner icon at the top of the screen, then select the Settings tab.
Once in the Settings screen click on Recommended actions and then select Quarantine.
Under Reports
Select Automatically generate report after every scan
Un-Select Only if threats were found

Close ALL open Windows / Programs / Folders.
Open up AVG-AS
Now click the Scanner Icon on top
Click on Complete System Scan
Be patient - it takes a while to run.

IMPORTANT! Do not save the report before you have clicked the Apply all actions button. If you do, the log that is created will indicate "No action taken", making it more difficult to interpret the report. So be sure you save it only AFTER clicking the "Apply all actions" button?

Once the scan is complete do the following:
If you have any infections you will prompted, then select Apply All Actions

Next select the Reports icon at the top.
Copy and paste the scan report in your next reply.

Close AVG-AS and Reboot in Normal Mode.

—————–

Next:

Please download SUPERAntiSpyware Home Edition (free)

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click "Yes",
Let it through your firewall!
Under "Configuration and Preferences", click the "Preferences" button.
Click the "Scanning Control" tab.
Under "Scanner Options" make sure the following are checked:
1>> Close browsers before scanning
2>> Scan for tracking cookies
3>> Terminate memory threats before quarantining.
4>> Ignore System Restore/Volume Information on ME and XP
5>> Please leave the others unchecked.
6>> Click the Close button to leave the control center screen.

On the main screen, under "Scan for Harmful Software" click "Scan your
computer".
On the left check "C:\Fixed Drive".
On the right, under "Complete Scan", choose "Perform Complete Scan".
Click "Next" to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click "OK".
Make sure everything in the white box has a check next to it, then click "Next".
It will quarantine what it found and if it asks if you want to reboot, click
"Yes".

To retrieve the removal information - please do the following:
1>> After reboot, double-click the "SUPERAntispyware icon" on your desktop.
2>> Click "Preferences". Click the "Statistics/Logs tab".
3>> Under "Scanner Logs", double-click "SUPERAntiSpyware Scan Log".
4>> It will open in your default text editor (such as Notepad/Wordpad).
5>> Please highlight everything , then right-click and choose copy.
6>> Click close and close again to exit the program.

Now please paste the "removal information" along with a fresh "HijackThis log", the log from ComboFix and AVG-AS in your reply. If it's a large log, you may need several replies to post it.

Good Luck, MrC
MrCharlie, I haven't done anything yet because I've been really busy the last 2 days. However, my computer seems to be running better, I was wondering if I should do the things you listed as just a "check up" (just to make sure everything's ok) or should I do something else for a "check up." thanks, Jason
"Jason" - 07-02-08 1:32:49 Service Pack 2
ComboFix 07-02-07 - Running from: "C:\Documents and Settings\Jason\Desktop"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\WINDOWS\system32\bszip.dll


((((((((((((((((((((((((((((((( Files Created from 2007-01-08 to 2007-02-08 ))))))))))))))))))))))))))))))))))


2007-01-31 18:10 765,952 –a—— C:\WINDOWS\system32\xvidcore.dll
2007-01-31 18:10 180,224 –a—— C:\WINDOWS\system32\xvidvfw.dll
2007-01-31 18:10 d——– C:\Program Files\Xvid
2007-01-25 21:23 d——– C:\DOCUME~1\ALLUSE~1\Application Data\Adobe
2007-01-11 11:00 d——– C:\WINDOWS\ie7updates


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-02-07 23:38 ——– d——– C:\Program Files\trillian
2007-02-07 12:22 ——– d——– C:\Program Files\mozilla firefox
2007-02-03 00:29 ——– d——– C:\Program Files\spywareblaster
2007-02-02 02:13 664 –a—— C:\WINDOWS\system32\d3d9caps.dat
2007-01-27 20:11 ——– d——– C:\Program Files\quicktime
2007-01-26 12:18 ——– d——– C:\Program Files\pokerroom.com
2006-12-23 19:36 ——– d——– C:\Program Files\cdknet
2006-12-08 13:56 ——– d——– C:\Program Files\samsung
2006-12-08 13:53 ——– d——– C:\Program Files\java
2006-11-08 00:06 679424 –a—— C:\WINDOWS\system32\inetcomm.dll


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"DellSupport"="\"C:\\Program Files\\Dell Support\\DSAgnt.exe\" /startup"
"MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background"
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"Apoint"="C:\\Program Files\\Apoint\\Apoint.exe"
"IgfxTray"="C:\\WINDOWS\\system32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\system32\\hkcmd.exe"
"SunJavaUpdateSched"="\"C:\\Program Files\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
@=""
"IntelWireless"="C:\\Program Files\\Intel\\Wireless\\Bin\\ifrmewrk.exe /tf Intel PROSet/Wireless"
"PCMService"="\"C:\\Program Files\\Dell\\Media Experience\\PCMService.exe\""
"Dell QuickSet"="C:\\Program Files\\Dell\\QuickSet\\quickset.exe"
"DVDLauncher"="\"C:\\Program Files\\CyberLink\\PowerDVD\\DVDLauncher.exe\""
"MMTray"="\"C:\\Program Files\\Musicmatch\\Musicmatch Jukebox\\mm_tray.exe\""
"ISUSPM Startup"="C:\\PROGRA~1\\COMMON~1\\INSTAL~1\\UPDATE~1\\ISUSPM.exe -startup"
"ISUSScheduler"="\"C:\\Program Files\\Common Files\\InstallShield\\UpdateService\\issch.exe\" -start"
"VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask"
"MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe"
"MCUpdateExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe"
"VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe"
"dla"="C:\\WINDOWS\\system32\\dla\\tfswctrl.exe"
"OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe"
"MPFExe"="C:\\PROGRA~1\\McAfee.com\\PERSON~1\\MpfTray.exe"
"MimBoot"="C:\\PROGRA~1\\MUSICM~1\\MUSICM~2\\mimboot.exe"
"MPSExe"="c:\\PROGRA~1\\mcafee.com\\mps\\mscifapp.exe /embedding"
"MSKAGENTEXE"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MskAgent.exe"
"MSKDetectorExe"="C:\\PROGRA~1\\McAfee\\SPAMKI~1\\MSKDetct.exe /startup"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"iTunesHelper"="\"C:\\Program Files\\iTunes\\iTunesHelper.exe\""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"


[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"WPDShServiceObj"="{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoCDBurning"=dword:00000000

HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0



Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\McAfee.com Scan for Viruses - My Computer (JASON-Jason).job


********************************************************************

catchme 0.1 W2K/XP - userland rootkit detector by Gmer, 17 October 2006
http://www.gmer.net

scanning hidden processes …

scanning hidden services …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0

********************************************************************

Completion time: 07-02-08 1:35:36
——————————————————— AVG Anti-Spyware - Scan Report ——————————————————— + Created at: 2:25:22 AM 2/8/2007 + Scan result: HKU\S-1-5-21-1048751292-3701252890-3758912614-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FC148228-87E1-4D00-AC06-58DCAA52A4D1} -> Adware.Virtumonde : Cleaned with backup (quarantined). HKU\S-1-5-21-1048751292-3701252890-3758912614-1005\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00DBDAC8-4691-4797-8E6A-7C6AB89BC441} -> Downloader.ConHook.l : Cleaned with backup (quarantined). C:\Documents and Settings\Jason \My Documents\The Incredible Machine\TIM 3\EVENMORE (D)\AOLTECH\DTAC.EXE -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined). :mozilla.829:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.247realmedia : Cleaned. :mozilla.830:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.831:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.832:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.833:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.834:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.869:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.954:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.2o7 : Cleaned. :mozilla.107:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.108:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.109:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.110:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.111:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.112:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.179:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.180:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned. :mozilla.873:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Bridgetrack : Cleaned. :mozilla.193:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.194:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.196:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.55:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.59:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned. :mozilla.191:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.192:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Casalemedia : Cleaned. :mozilla.871:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Centrport : Cleaned. :mozilla.872:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Centrport : Cleaned. :mozilla.838:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Clickhype : Cleaned. :mozilla.422:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.423:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.424:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.425:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Com : Cleaned. :mozilla.451:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Com : Cleaned. :mozilla.452:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Com : Cleaned. :mozilla.223:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.295:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.296:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.297:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.371:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.396:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.416:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.469:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.470:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.471:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.487:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.550:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.551:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.552:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.553:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.554:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.555:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.556:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.557:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.558:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.681:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.683:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.705:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.706:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.712:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.713:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.714:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.715:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.716:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.717:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.721:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.722:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.723:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.730:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.732:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.740:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.741:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.742:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.757:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.768:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.773:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.774:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.781:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.812:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.889:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.890:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.891:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.892:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.893:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.894:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.895:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.896:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.897:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.898:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.899:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.900:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.901:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.902:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.903:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.904:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.905:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.906:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.907:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.908:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.909:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.910:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Esomniture : Cleaned. :mozilla.500:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.501:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.502:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.503:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Falkag : Cleaned. :mozilla.656:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Information : Cleaned. :mozilla.616:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Ivwbox : Cleaned. :mozilla.224:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.735:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.834:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.835:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.836:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.843:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.844:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.845:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned. :mozilla.778:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Myaffiliateprogram : Cleaned. :mozilla.854:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.855:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Onestat : Cleaned. :mozilla.843:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.844:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.845:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.846:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.847:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Pointroll : Cleaned. :mozilla.245:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.310:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.311:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.312:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.313:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.314:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned. :mozilla.657:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Revenue : Cleaned. :mozilla.913:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.914:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Ru4 : Cleaned. :mozilla.239:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.240:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.241:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.242:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.243:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Serving-sys : Cleaned. :mozilla.534:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.535:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned. :mozilla.841:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Specificclick : Cleaned. :mozilla.947:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Starware : Cleaned. :mozilla.948:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Starware : Cleaned. :mozilla.326:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.327:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.328:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.329:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.330:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.331:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.332:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.333:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.334:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Statcounter : Cleaned. :mozilla.53:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.57:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.58:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.98:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.99:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Tacoda : Cleaned. :mozilla.765:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned. :mozilla.400:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.401:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.402:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.403:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.91:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.92:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.93:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.94:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned. :mozilla.215:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.216:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.217:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.91:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.92:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.93:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.94:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.95:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. :mozilla.96:C:\Documents and Settings\Jason \Application Data\Mozilla\Firefox\Profiles\8fjpq48g.default\cookies-1.txt -> TrackingCookie.Zedo : Cleaned. ::Report end MrC, I will do the last thing in the morning. Jason
MrC,

SUPERAntiSpyware Scan Log
Generated 02/08/2007 at 01:00 PM

Application Version : 3.5.1016

Core Rules Database Version : 3179
Trace Rules Database Version: 1189

Scan type : Complete Scan
Total Scan Time : 01:11:56

Memory items scanned : 572
Memory threats detected : 0
Registry items scanned : 5912
Registry threats detected : 0
File items scanned : 53838
File threats detected : 0






Logfile of HijackThis v1.99.1
Scan saved at 1:22:17 PM, on 2/8/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\Program Files\Apoint\Apntex.exe
C:\PROGRA~1\MUSICM~1\MUSICM~2\MMDiag.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Digital Line Detect\DLG.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre1.5.0_09\bin\jucheck.exe
C:\Documents and Settings\Jason\My Documents\Downloaded Program Updates\Hi Jack This Program\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~2\mimboot.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\McAfee\SPAMKI~1\MskAgent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: dlbcserv.lnk = C:\Program Files\Dell Photo Printer 720\dlbcserv.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} - http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: IntelWireless - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



–


thanks,

Jason
It seems to be running smoothly. Did any of those programs remove anything significant? and should I uninstall them via ControlPanel>Add/Remove Programs?
Did any of those programs remove anything significant? and should I uninstall them via ControlPanel>Add/Remove Programs?

A lot of cookies and……

C:\WINDOWS\system32\bszip.dll <—this is a worm that was deleted

C:\Documents and Settings\Jason \My Documents\The Incredible Machine\TIM 3\EVENMORE (D)\AOLTECH\DTAC.EXE -> Heuristic.Win32.Dialer : Cleaned with backup (quarantined). <—and a dialer

Yes you can uninstall them via add/remove programs.

—————

If you have any questions - please post back

I'll leave you with……..

Some preventive maintenance:

——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point:
(ME and XP users only)

XP system restore

ME system restore

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File
Direct Download - MVPS HOSTS <==> MVPS HOSTS Tutorial

Need a free anti virus?
AVG*free
Avast free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
ZoneAlarm*free
Comodo Free Firewall
Other free firewalls

Keep those temp files off your system use
CCleaner
Uncheck "Cookies" under "Internet Explorer".
or
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected" That will clear out all the temp files on the system.


IMPORTANT!!
Keep your Sun Java up-to-date JRE 6 <–newest version
Download page JRE 6
Java Tutorial
Delete ALL old versions from add/remove programs if listed first!

Keep the registry backed up - use ERUNT
Print this out and save it
ERUNT Tutorial

———-Free malware removal programs:———-

SpyBot
AD-Aware
CW-Shredder
SUPERAntiSpyware (free edition)

AVG Anti-Spyware<—VERY GOOD! (XP and 2K only)

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable Windows MessengerXP - 2K (stops pop-up ads -etc):
Disabling Messenger Service in Windows XP
How to Remove Windows Messenger on Windows XP
How to Remove Windows Messenger on Windows XP
Shoot The Messenger

Don't open e-mail attachments without first scanning them with an up-to-date
anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
Just to add……

Try this tweak and let me know if it speeds things up and if it runs better, you can always reverse the tweak.

Please go to Start > Settings > Control Panel > Regional and Language Options > Languages > Details > Advanced
Now CHECK the box that says Turn off advanced text services

MrC
MrC, I removed all those programs, downloaded the SpywareGuard, the new Java, and my McAfee released a new update, so I installed that as well. I had to restart a few times and my computer seemed to be slow when starting up, but when I'm running my programs its going faster. I just did that tweak you suggested, I'll try it for a while and let you know how its working. -Jason
OK,
Read through this and also try this tweak - it may improve internet surfing.

1> Go to Start > Run (type) services.msc > OK
2> Scroll down to DNS Client, Right-click and select: Properties
3> Click the drop-down arrow for "Startup type"
4> Select: Manual, click Apply/Ok and restart.
(The default is Auto - you can always change it back)

MrC
Quoting MrC: 1> Go to Start > Run (type) services.msc > OK 2> Scroll down to DNS Client, Right-click and select: Properties 3> Click the drop-down arrow for "Startup type" 4> Select: Manual, click Apply/Ok and restart. (The default is Auto - you can always change it back) ^^ what is it that I'm changing, and what does it do?
Here's a couple of good links:

http://www.theeldergeek.com/dns_client.htm

http://www.simpledns.com/kb.aspx?kbid=1089

I set my XP machine to manual and saw a great improvement in performance while on the web. Before making the change - I would click on a link and there would be a big lag before the page would be displayed. Now after I made the change (set it to manual), as soon as I click on a link the page opens right up, noticeable big difference.
You can always change it back to the default setting, which is "auto".

MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI