This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Video Codec has taken over my browser

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

A new video codec was installed on my computer by a family member and took over my web browser. I found some of the files and deleted them (they are still in my recylcle bin). The files were isamini, isamntr, pmsnrr and a few others. I am concerned that there may be more problems with my machine, so I have basicaly stopped using it until I can find out if it has other problems. Not sure what to do from here, and would rather have someone guide me instead of just winging it and really messing things up. Thanks, Ed
Erynex :D

Welcome to Tom Coyote Yep, there are a log of bogus codecs going around goading you to install them when in fact there a Trojan.

I can't help you until I see a Hijackthis log, here are the instructions,


Hijackthis 1.99.1
Its important that Hijackthis is installed in its own permanent folder for backup purposes.
  • Use the link above or the links in my signature to download HJT 1.99.1 setup to your desktop
  • Double Click on the Setup icon and by defaut it will unzip to C:\Program Files\Hijackthis
  • Open HJT Scan and Save a Log File, it will open in Notepad
  • Go to Edit> Select All…..Edit > Copy and Paste the new log into this thread.
  • Please use the [external image: Posted Image] Button and not the New Topic Button
DO NOT have HijackThis fix anything yet. Most of what it finds will be harmless or even required.
Thank you so much for your assistance. Here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 9:06:37 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Common Files\AOL\1171131137\ee\AOLSoftware.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isadd.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171131137\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [errorkiller] "C:\Program Files\errorkiller\errorkiller.exe" -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) - http://real.gamehouse.com/games/adventureball/abx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161965638196
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/pla…0/Installer.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
Erynex :D

Good job, HJT is current and right where we want it to be.

You may want to print this out as we will be offline for most of the fix. This is a mouthful but the infection you have is nasty and can't be cleaned by a few mouse clicks. Take your time, read the instructions.


We need to make sure all hidden files are showing :
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Under the Hidden files and folders heading select Show hidden files and folders.
  • Uncheck the Hide file extensions for known types option.
  • Uncheck the Hide protected operating system files (recommended) option.
  • Click Yes to confirm.
  • Click OK.
Once your system is clean, we suggest that you reverse this to keep critical windows files from accidently being deleted.


Look in your Add-Remove Programs in the Control Panel and see if you can uninstall this program
C:\Program Files\Video ActiveX Object


You have AVG Anti Spyware installed, set it up this way but don't run the scan yet.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.






Download SmitfraudFix
Extract the content (a folder named SmitfraudFix) to your Desktop.




Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode

  • Once in Safe Mode, open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #2 - Clean by typing 2 and press "Enter" to delete infected files.
  • You will be prompted : "Registry cleaning - Do you want to clean the registry ?"; answer "Yes" by typing Y and press "Enter" in order to remove the Desktop background and clean registry keys associated with the infection.
  • The tool will now check if wininet.dll is infected. You may be prompted to replace the infected file (if found); answer "Yes" by typing Y and press "Enter".
  • The tool may need to restart your computer to finish the cleaning process; if it doesn't, please restart into normal Windows.
  • A text file will appear onscreen, with results from the cleaning process; please copy/paste the content of that report into your next reply along with a new HijackThis log.
The report can also be found at the root of the system drive, usually at C:\rapport.txt





Clean out your Temporary Internet files. Proceed like this:
  • Quit Internet Explorer and quit any instances of Windows Explorer.
  • Click Start> Control Panel and then double-click Internet Options.
  • On the General tab, click Delete Files under Temporary Internet Files.
  • In the Delete Files dialog box, tick the Delete Offline content check box , and then click OK.
  • On the General tab, click Delete Cookies under Temporary Internet Files, and then click OK.
  • Click on the Programs tab then click the Reset Web Settings button.
  • Click Apply then OK.




Still in Safemode
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system
  • make sure to remember where you saved that file, this is important
  • Close AVG Anti-Spyware 7.5
IMPORTANT: Do not open any other windows or programs while AVG is scanning, it may interfere with the scanning process:


Reboot normally.
  • Open the SmitfraudFix folder and double-click smitfraudfix.cmd
  • Select option #3 - Delete Trusted zone by typing 3 and press Enter
  • Answer Yes to the question "Restore Trusted Zone ?" by typing Y and hit Enter.
Note, if you use SpywareBlaster and/or IE-SPYAD, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE-SPYAD, run the batch file and reinstall the protection.



Still in Safemode, delete these files and folders.


C:\Program Files\Video ActiveX Object
C:\WINDOWS\system32\cwgppb.dll


Reboot normally

Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.


These may be gone so don't be alarmed if there not present
O2 - BHO: (no name) - {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} - C:\Program Files\Video ActiveX Object\isadd.dll (file missing)

O21 - SSODL: exemplars - {2acf3add-34a1-4f2f-99cf-cc69785d1e90} - C:\WINDOWS\system32\cwgppb.dll (file missing)




Let me see the Smitfraud log, the AVG log and a New HJT log please.
I followed everything, so I am attaching the logs. I hope these look better.

Smitfraud log
SmitFraudFix v2.142
Scan done at 22:19:41.82, Tue 02/13/2007
Run from C:\Documents and Settings\Edward Rynex\My Documents\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{2acf3add-34a1-4f2f-99cf-cc69785d1e90}"="exemplars"

[HKEY_CLASSES_ROOT\CLSID\{2acf3add-34a1-4f2f-99cf-cc69785d1e90}\InProcServer32]
@="C:\WINDOWS\system32\cwgppb.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{2acf3add-34a1-4f2f-99cf-cc69785d1e90}\InProcServer32]
@="C:\WINDOWS\system32\cwgppb.dll"


»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts


127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted

»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"System"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End



AVG Log
———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:01:26 PM 2/13/2007

+ Scan result:



HKLM\SOFTWARE\ErrorKiller\BhoManager\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Cleaned with backup (quarantined).
HKU\S-1-5-21-2003296787-2632964813-3829646969-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} -> Adware.Generic : Cleaned with backup (quarantined).
C:\Program Files\MalwareBot\MalwareBot.dll -> Adware.GoodByeSpyware : Cleaned with backup (quarantined).
C:\Documents and Settings\Edward Rynex\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfg.class-593ebb39-2b85a2f9.class -> Downloader.OpenStream.y : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042941.dll -> Downloader.Zlob.bno : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042911.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042912.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042932.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042934.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042949.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042951.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042964.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042967.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043060.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043062.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043070.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043142.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043144.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043229.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043231.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043244.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043246.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043261.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043263.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP528\A0045578.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP528\A0045579.dll -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP528\A0045580.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP528\A0045581.exe -> Downloader.Zlob.bnw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042913.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042933.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042950.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP526\A0042965.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043061.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043143.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043245.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP527\A0043262.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3DBD88D2-9FFC-498B-A689-A4771362F918}\RP528\A0045582.exe -> Downloader.Zlob.bny : Cleaned with backup (quarantined).
C:\Program Files\DIGStream\digstream.exe -> Not-A-Virus.Downloader.Win32.DigStream : Cleaned with backup (quarantined).
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@marketlive.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@robeez.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@volkswagen.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@wpni.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@comcast.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@giftscom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@leeenterprises.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@poweronemedia.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10008.qit -> TrackingCookie.2o7 : Cleaned.
C:\WINDOWS\Temp\Cookies\edward rynex@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy rynex@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10000.qit -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@adviva[1].txt -> TrackingCookie.Adviva : Cleaned.
:mozilla.123:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy rynex@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10001.qit -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10002.qit -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@centrport[2].txt -> TrackingCookie.Centrport : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Co : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@commission-junction[2].txt -> TrackingCookie.Commission-junction : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.42:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy rynex@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10003.qit -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Esomniture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy rynex@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy [removed][2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10004.qit -> TrackingCookie.Goclick : Cleaned.
:mozilla.19:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.20:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.21:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy [removed][2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10005.qit -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.105:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10006.qit -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Program Files\MalwareBot\Quarantine\11-02-2007-08-07-28\10007.qit -> TrackingCookie.Overture : Cleaned.
:mozilla.15:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Paycounter : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.34:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Amy Rynex\Local Settings\Temp\Cookies\amy rynex@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed]-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.54:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Sexlist : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@spylog[1].txt -> TrackingCookie.Spylog : Cleaned.
:mozilla.41:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@trafic[1].txt -> TrackingCookie.Trafic : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed][1].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@valueclick[1].txt -> TrackingCookie.Valueclick : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy rynex@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy [removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.97:C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Amy Rynex\Cookies\amy_rynex@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.


::Report end


HJT Log

Logfile of HijackThis v1.99.1
Scan saved at 11:10:02 PM, on 2/13/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Common Files\AOL\1171131137\ee\aolsoftware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\America Online 9.0\aoltray.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171131137\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [errorkiller] "C:\Program Files\errorkiller\errorkiller.exe" -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - E
Erynex :D

I need to see the entire HJT log, yours was cut off.

A couple of points, AVG quarantined some bad files in your System Restore program, so lets flush it out .

System Restore makes regular backups of all your settings, if you ever had to use this program to restore your system to a previous date, you will be infected all over again so we need to clean out the previous Restore Points. I cant emphasize enough how important it is to create a new restore point.

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Reboot your System

Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • Go to Start/ Control Panel/ Performance and Maintenance/ System Restore/ Create a New Restore Point
    You can name the restore point anything you like, something that you can remember, You will have to be in Catagory View to see this

Please download ATF Cleaner by Atribune.
  • This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up


Then do this. Panda will show if anything is left behind.

Run Panda's ActiveScan from here and perform a full system scan.

1. Once you are on the Panda site click the "Scan your PC" button
2. A new window will open…click the big "Check Now" button
3. Enter your Country
4. Enter your State/Province
5. Enter your e-mail address and click send
6. Select either Home User or Company
7. Click the big Scan Now button
8. If it wants to install an ActiveX component allow it
9. It will start downloading the files it requires for the scan (Note: It will take a couple minutes)
Since you are on a slow connection it will take about 15 minuites for the scanner to load.
10. Click on "Local Disks" to start the scan
11. Once scan is done, click "see report" then "save report"
Save the log someplace.
12. reboot
13. Post Panda scan results in your next reply

So let me see the Panda report and a New COMPLETE HJT log please and let me know how your system is behaving now.
I am so glad I posted for help on this, I would have been in way over my head. My machine appears to be running better now. Panda showed the following items still on my machine:


Incident Status Location

Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Edward Rynex\Application Data\Mozilla\Firefox\Profiles\3ledrlpm.default\cookies.txt[.doubleclick.net/]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Edward Rynex\My Documents\SmitfraudFix\Process.exe

Here is a complete HJT Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:44:59 AM, on 2/14/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
c:\program files\mcafee.com\agent\mcdetect.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\McAfee.com\VSO\mcvsshld.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\PROGRA~1\mcafee.com\mps\mscifapp.exe
C:\PROGRA~1\McAfee\SPAMKI~1\MSKAgent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\McAfee.com\VSO\oasclnt.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
C:\Program Files\Common Files\AOL\1171131137\ee\AOLSoftware.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee PopupKiller - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: McAfee AntiPhishing Filter - {41D68ED8-4CFF-4115-88A6-6EBB8AF19000} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [CTDVDDET] "C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MPSExe] c:\PROGRA~1\mcafee.com\mps\mscifapp.exe /embedding
O4 - HKLM\..\Run: [MSKAGENTEXE] C:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - HKLM\..\Run: [MSKDetectorExe] C:\PROGRA~1\McAfee\SPAMKI~1\MSKDetct.exe /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [mmtask] "C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1171131137\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MSKAGENTEXE] c:\PROGRA~1\mcafee\SPAMKI~1\mskagent.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra 'Tools' menuitem: McAfee AntiPhishing Filter - {39FD89BF-D3F1-45b6-BB56-3582CCF489E1} - c:\program files\mcafee\spamkiller\mcapfbho.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) - http://real.gamehouse.com/games/adventureball/abx.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1161965638196
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/4h/pla…0/Installer.exe
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: McAfee SpamKiller Server (MskService) - McAfee Inc. - C:\PROGRA~1\McAfee\SPAMKI~1\MSKSrvr.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Where do I go from here?

Ed
Erynex :D ,

Remove these with HJT, the 016 entries for games sometimes brings the bad guys with it.

R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - (no file)

O16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) - http://real.gamehouse.com/games/adventureball/abx.cab
O16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F98} (CR64Loader Object) - http://www.miniclip.com/puzzlepirates/miniclipGameLoader.dll



Panda found nothing bad and the rest of your log looks fine :thumbup: :thumbup: :thumbup:


Whenever you go into a website that says this or that is required to view the page properly, most times its legit but sometimes its not, don't take a chance. GOOGLE the program it wants you to install and check it out before you download it.

How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Thank you so much for your time. My expertise is in accounting, not computers. My nephew seems to have expertise in messing my machine up. Have a wonderful day. Ed
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI