This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan_Generic.z, How do i get rid of it?

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have tried to use trojan removal programs, but my Pc Chillin keeps picking up a virus "Troj_Generic.Z" and i can not remove it. I tried to track the virus back to the folders that it said it was in but i lose track of them at some point because the folder that it is in is not there..? Please help me thank you.



Logfile of HijackThis v1.99.1
Scan saved at 11:34:30 AM, on 2/6/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Adam Smith\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: XBTP01621 Class - {54B62CEF-8A07-4d3c-A2EF-DDF184264374} - C:\PROGRA~1\BEARSH~2\MediaBar.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: BearShare MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\BearShare MediaBar\MediaBar.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZJxdm086YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Doyles Room Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\DOYLES~1\client.exe
O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Krazie_A :D

Welcome to the forum, you have a few things going on that we need to fix.


DO THIS FIRST
Your Hijackthis program is current, but it is very important that it resides in its own folder.
We will use Hijackthis (HJT) to make changes to your system and HJT will make backups of those changes,
If HJT is not in its own folder, those backups could be lost.

Easy to fix.
  • just go to C:\ Program Files and create a new folder and name it Hijackthis .
  • Now scroll to where you have HJT currently, right click on the HJT icon and select CUT .
  • Now open the new folder you just created and right click within that folder and select PASTE .
  • Now HJT should reside in C:\Program Files\Hijackthis\Hijackthis.exe
Please do not proceed until you have moved HJT




Try this for Pc Chillin run another scan and see if it removes it.
Open Main Console
In 'Antivirus' tab, under 'File Types', make sure 'Search for and clean Trojans' box is ticked.
Also under 'Action', make sure 'Recommended Action' is ticked


These are all bad programs that bring malware with it. I suggest you uninstall them via the Add Remove Programs in the Control Panel

C:\Program Files\BearShare MediaBar

C:\Program Files\MyWebSearch

C:\Program Files\EmpirePokerMaster



Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.


O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: XBTP01621 Class - {54B62CEF-8A07-4d3c-A2EF-DDF184264374} - C:\PROGRA~1\BEARSH~2\MediaBar.dll

O3 - Toolbar: BearShare MediaBar - {B7D3E479-CC68-42B5-A338-938ECE35F419} - C:\Program Files\BearShare MediaBar\MediaBar.dll

O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe

O9 - Extra button: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra 'Tools' menuitem: EmpirePoker - {77E68763-4284-41d6-B7E7-B6E1F053A9E7} - C:\Program Files\EmpirePokerMaster\EmpirePoker\RunEPoker.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe

O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/f…tup1.0.0.15.cab





Run this system cleaner

If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
Download and Install CCleaner
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



Lets check and make sure nothing else is installed and hiding from us.


Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
Since you are on a slow connection it will take about 15 minuites for the scanner to load.
10. Click on "Local Disks" to start the scan
11. Once scan is done, click "see report" then "save report"
Save the log someplace.
12. reboot
13. Post Panda scan results in your next reply


Let me see the Panda Log and a New HJT log please.
Ok heres the new log's, Thank you for your help! =) P.S. It also wouldnt tell me how to fix it on the panda scan even though i clicked on the Button for Disenfection advice it didnt do anything.


Logfile of HijackThis v1.99.1
Scan saved at 3:17:10 AM, on 2/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\WINDOWS\system32\hphmon05.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\HiJackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZJxdm086YYUS
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Doyles Room Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\DOYLES~1\client.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe



Panda File



Incident Status Location

Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.hc2.humanclick.com/hc/18583751]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[hc2.humanclick.com/]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[hc2.humanclick.com/hc/18583751]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.hc2.humanclick.com/hc/18583751]
Spyware:Cookie/Humanclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.hc2.humanclick.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/Mammamediasolutions Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.targetnet.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.dist.belnk.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.citi.bridgetrack.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.stat.onestat.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.statse.webtrendslive.com/S005-01-5-10-193810-74233]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/DomainSponsor Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.landing.domainsponsor.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.revenue.net/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.go.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.www.burstbeacon.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.tradedoubler.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.belnk.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.2o7.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@2o7[1].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][2].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@adrevolver[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@advertising[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@atdmt[1].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@atwola[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@bluestreak[2].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@burstnet[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@casalemedia[1].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@com[1].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@doubleclick[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@drivecleaner[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@fastclick[2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@mediaplex[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@questionmarket[2].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@realmedia[1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][2].txt
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam smith@tribalfusion[1].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][1].txt
Spyware:Cookie/DriveCleaner Not disinfected C:\Documents and Settings\Adam Smith\Cookies\adam [removed][2].txt
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Adam Smith\Local Settings\Temp\!update.exe
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@adrevolver[2].txt
Spyware:Cookie/AdDynamix Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@advertising[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@atwola[2].txt
Spyware:Cookie/Azjmp Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@azjmp[2].txt
Spyware:Cookie/Banner Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@banner[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@belnk[1].txt
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@bluestreak[1].txt
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@burstnet[1].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@casalemedia[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@com[1].txt
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@doubleclick[1].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@fastclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@mediaplex[2].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@overture[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@realmedia[2].txt
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@statcounter[1].txt
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@target[1].txt
Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@tradedoubler[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@tribalfusion[2].txt
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\Kat Smith\Cookies\kat smith@zedo[1].txt
Potentially unwanted tool:Application/FunWeb Not disinfected C:\Program Files\HiJackThis\backups\backup-20070212-015223-763.inf
Potentially unwanted tool:Application/FunWeb Not disinfected C:\Program Files\MSN Messenger\msimg32.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MSN Messenger\riched20.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\MyWebSearch\bar\1.bin\MWSOESTB.DLL
Virus:Eicar.Mod Not disinfected C:\Program Files\Trend Micro\Internet Security 12\tmhelp.chm[/PCC12/Test_virus.htm]
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\Program Files\Uninstall My Web Search.dll
Potentially unwanted tool:Application/RealSpy Not disinfected C:\WINDOWS\system32\actskn45.ocx
Adware:Adware/Puper Not disinfected C:\WINDOWS\system32\ld100.tmp
Good Morning, :D

Fix these with HJT.

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)

O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/…?p=ZJxdm086YYUS


Panda will just remove viruses and no trojans or malware, there is a entry in your Panda log that may be pointing to another infection, lets run this tool to check for it.

Please download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.

Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.
Ok this is what you need i think. I hope i did it right. SmitFraudFix v2.141 Scan done at 1:10:56.52, Tue 02/13/2007 Run from C:\Documents and Settings\Adam Smith\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 C:\WINDOWS\system32\ld???.tmp FOUND ! C:\WINDOWS\system32\ld????.tmp FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Adam Smith »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Adam Smith\Application Data C:\Documents and Settings\Adam Smith\Application Data\Install.dat FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADAMSM~1\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32-huy32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
Krazie_A :D

Yep, you did it right :thumbup: But the log shows files from the Smitfraud trojan
So lets proceed to remove that bad program.


You should print out these instructions, or copy them to a Notepad file for reading while in Safe Mode, because you will not be able to connect to the Internet to read from this site.


Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run Ewido and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


Once in Safe Mode, open the SmitfraudFix folder again and double-click smitfraudfix.cmd
Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.

You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.

The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".

The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart anyway into normal Windows. A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt

Warning : Running option #2 on a non infected computer will remove your Desktop background




Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start, click Control Panel, and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete all offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button. Click Apply then OK.
  • Click OK.



IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • Ewido will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5

Post the log from Smitfraud fix, the AVG Spyware log and a New HJT log please
Ok heres the Avg log.

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:07:22 AM 2/13/2007

+ Scan result:



C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned.
:mozilla.105:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.146:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.194:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.284:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.340:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.341:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.346:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.347:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.348:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.349:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.352:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.353:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.325:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.343:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Addynamix : Cleaned.
:mozilla.312:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.313:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.318:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.322:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.326:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.327:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.328:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.339:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.43:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.50:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Adserver : Cleaned.
:mozilla.307:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.308:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.309:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.310:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.311:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.335:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.148:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.140:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.141:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.235:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.212:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.106:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.107:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.108:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.342:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.147:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.336:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.266:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.267:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.103:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.104:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.109:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.131:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.132:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.133:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.134:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.157:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.213:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Information : Cleaned.
:mozilla.191:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.329:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.330:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.224:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.225:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.149:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.150:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.305:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.306:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.320:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.350:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@pro-market[1].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.70:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.71:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.72:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.139:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.241:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.242:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.243:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.244:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.218:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.263:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.264:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.265:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.237:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.238:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.239:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.240:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.257:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.258:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
:mozilla.259:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Starware : Cleaned.
:mozilla.256:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.262:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.67:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
:mozilla.68:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.260:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.285:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.286:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.287:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.288:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.289:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.290:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.291:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.292:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.186:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.187:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.100:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.101:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.97:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.98:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.99:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.63:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.210:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.211:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.333:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.334:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat [removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.48:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.51:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.52:C:\Documents and Settings\Adam Smith\Application Data\Mozilla\Firefox\Profiles\dtghakpu.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\Kat Smith\Cookies\kat smith@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Here's the HJT log.

Logfile of HijackThis v1.99.1
Scan saved at 10:11:01 AM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe
C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\WINDOWS\SYSTEM32\CTXFISPI.EXE
C:\PROGRA~1\MUSICM~1\MUSICM~3\MMDiag.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\MUSICMATCH\Musicmatch Jukebox\mim.exe
C:\WINDOWS\system32\hphmon05.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\HiJackThis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: CBrowserHelperObject Object - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\GoogleAFE\GoogleAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\Sound Blaster X-Fi\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanel.exe" /r
O4 - HKLM\..\Run: [AudioDrvEmulator] "C:\Program Files\Creative\Shared Files\Module Loader\DLLML.exe" -1 AudioDrvEmulator "C:\Program Files\Creative\Shared Files\Module Loader\Audio Emulator\AudDrvEm.dll"
O4 - HKLM\..\Run: [CTXFIREG] CTxfiReg.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [MimBoot] C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [HPHUPD05] C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\system32\hphmon05.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Elements 5.0\apdproxy.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe
O4 - Global Startup: KTTC Desktop Alert.lnk = C:\Program Files\Common Files\KTTC Desktop Alert\TrueWeather.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Open in new background tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Open in new foreground tab - res://C:\Program Files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?1bfdcfecf20246b7bcf149acef87b20b
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Doyles Room Poker - {40B2063F-DB01-4962-BE63-59435C01283C} - C:\PROGRA~1\DOYLES~1\client.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by105fd.bay105.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.

And heres the smit log/ rapport?

SmitFraudFix v2.141

Scan done at 9:09:19.79, Tue 02/13/2007
Run from C:\Documents and Settings\Adam Smith\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\WINDOWS\system32\ld???.tmp Deleted
C:\Documents and Settings\Adam Smith\Application Data\Install.dat Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End
Krazie_A :D

You did very well :thumbup: Working with some posters is like pulling teeth to get a report :D

Your HJT log looks fine :thumbup:

FYI AVG Anti Spyware will still function after the trial, you can still check for updates, run scans and remove what it finds, you will just lose the Back Ground Guard feature, so its your call to purchase the full version, keep the trial or uninstall it;

You need to update your Java to plug any holes that the bad guys can get in.
  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Java website and download and install the update.
  • Java Runtime Environment (JRE) 5.0 Update 11 <–This is what you need to download and install.
  • If you do an Online installation, it will install automatically.
  • If you do an Offline installation, you will have to save the setup file to your hard disk and run it. Your call.
  • Then after install you can verify your installation here Sun Java Verify
I like to do an Offline Installation and save the setup file in case I need it in the future


All the bad stuff we removed is backed up in the Windows System Restore program and if you ever use it to restore your system to an earlier date you risk reinfecting yourself all over again, so I need you to flush it all out and I can't stress enough how important it is to Create a New Restore point



Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this


How is your system behaving now??? If all is well I have some free programs for you to install to help keep you more secure .

Ken :D
Thank you so much for all your help. I have one more question to ask of you, I still keep getting a pop up about some one trying to acess my computer it comes up saying Unknown source and it gives me an IP adress and i dont know how to stop that. I click on Do not trust but it doesnt seem to do anything, this happens fairly often through out the day and i just keep clicking close. Hope you can help thank you so much.
The program is Trend Micro pc chillin. Heres the diffrent catergories, Status= Unknown IP Address: 192.168.0.1 Computer name=…… Mac address: 00:15:05:4f:97:2f
Look in your Add-Remove Programs in the Control Panel for this program and uninstall it if its present.

C:\Program Files\MyWebSearch



Then go to C:\Program Files\MyWebSearch <–and delete this folder


Lets reset your Hosts files. The name of the program has changed but its the same program.

Download Hoster
  • Unzip Hoster to your desktop
  • Open up the Hoster program.
  • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
  • Click Create Back Up
  • Then click on Restore Microsoft's Host Files
  • Close the Hoster program


Look in your Trend Micro pc chillin. firewall and disable any notifications that alert you. Its normal for your firewall to block all sorts of hits on it, 99.9% are all legit.


Let me know if this helped ??
Sorry for getting back to you so late i have not been around the computer. Um the computer runs very well again but it is still poping up with tht threat warning saying unknown source is trying to acess my computer. Sorry again and thanks for all your help. Adam
Adam, As long as your firewall is blocking it I don't think I would worry about it. Like I said, you will get lots of hits to access your computer and most of them are legit, they have to do with things like some programs you have looking for updates and things of that nature. So at this point I believe your ok. Your firewall should have an option to turn off alerts, most do. Ken :D

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI