hmarie775
Topic Starter
I am not that literate when it comes to anything beyond using software so forgive me in advance for my ignorance. I am in tears, I have been working on this for 2 days trying to stop the 20 windows that pop up with ads some of them inappropriate ones when my kids use the computer. I use windows defender and AVG virus scan 7.5 on a daily basis (schedule scans for 3 am) I keep getting little messages about corrupt files too. I'm in tears and so ready to throw this computer out the window. I tried to follow the self help section an have done this so far….
Downloaded and ran Prevx1, fixed whatever it said to fix.
I first ran Spybot, which I use weekly usually. It found over 90 problems, fixed them
Downloaded Adaware, ran it fixed everything it found
Dowloaded the AVG spyware ran that as directed on the self help section, this is that report:
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 5:47:51 PM 3/31/2007
+ Scan result:
C:\WINDOWS\Downloaded Program Files\turbo.inf -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141638.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\brix6ie.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
C:\WINDOWS\cpbrkpie.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
HKU\S-1-5-21-2646752555-1850456698-4159782051-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56B90057-DFC9-4075-87B6-2AAFED4FEF0F} -> Adware.Fatpickle : Cleaned with backup (quarantined).
C:\WINDOWS\eliteunstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145765.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0137557.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138583.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138584.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138588.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141639.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141640.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141651.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\micro1\a1.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145743.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\WINDOWS\itpb_3.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145769.dll -> Adware.RK : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\WUInst.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Alexa\Local Settings\Temp\v4x3.ga2me -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{6CDA57D7-09D8-1033-0830-020403020001}\system.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\DeskAlerts\deskbar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138558.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138566.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138604.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138644.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0139650.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0140642.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141693.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1349\A0141750.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145745.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145762.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\vexga5me3.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145763.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\micro1\a4.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145761.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145764.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145768.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138625.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138626.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\amstream.exe.tcf -> Adware.UrlSpy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141645.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141646.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141647.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141635.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141636.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141637.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142735.dll -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2646752555-1850456698-4159782051-1006\Dc23.exe -> Downloader.Agent.ac : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138572.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138611.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138652.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0139655.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0140650.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\svchosts.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\tmp7F.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWAS7_0001_N91M1112NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0144733.exe -> Proxy.Small.osw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142748.sys -> Rootkit.Agent.dh : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Cookies\heather@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\Mike\Local Settings\Temp\Cookies\mike@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Mike\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Dbbsrv : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@info[1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@info[1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@linkbuddies[2].txt -> TrackingCookie.Linkbuddies : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@popuptraffic[2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Porntrack : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@_[1].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@toplist[2].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@trafficcenter[1].txt -> TrackingCookie.Trafficcenter : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1335\A0132527.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145735.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp3.tmp.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1AC0E789-9DAD-4713-9601-8D65D244D81F} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{52777FCD-2A3F-41D2-A502-010D4393EC2A} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{73D0584D-0A4E-4186-95BB-0A1008147521} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{87AC4B9F-5C48-419B-BD35-79B760BBE560} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{AD4EEA6B-EB22-4664-A697-329DC7F84201} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D018BC33-38D9-4291-B72C-2AD62B5A8119} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wapisvsu.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141652.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142745.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145733.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\adirka.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142746.dll -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141730.exe -> Worm.Zhelatin.bp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142747.exe -> Worm.Zhelatin.by : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2646752555-1850456698-4159782051-1006\Dc25.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0137563.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141711.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141720.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141722.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
::Report end
After that once I figued out what Hijack this was I downloaded it and ran a log I guess it's called.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:55:35 PM, on 3/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\desktop weather\desktopweather_1351785.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Heather\Desktop\HiJackThis_v2.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…p://my.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r21.mchsi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r21.mchsi.com;
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {553c73a2-b85b-4b21-b25a-464d7d8add05} - C:\WINDOWS\system32\lfl10N.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {632C3EC7-0013-0310-CEA5-03C04EEFDD0D} - C:\WINDOWS\system32\trxriqi.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {9A56BA79-BA75-4584-9A36-38DF91947EB5} - \
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [lnwin.exe] C:\WINDOWS\system32\lnwin.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271 (User 'Default user')
O4 - Startup: check-ip-changed.bat
O4 - Startup: desktop weather.lnk = C:\Program Files\desktop weather\desktopweather_1351785.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://mf.hud.gov:63001/CFIDE/classes/CFJava.cab
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {140F03AE-0588-11D4-BD45-0050048A82BF} (eShare Web Collaboration Class) - http://chat.1800flowers.com/netagent/objects/emagic.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1267/ftp…/v6/brix6ie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.photoworks.com/pixami/BPImageEditor.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…64/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.55.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152532782703
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7B461720-5910-45A3-B617-3B53A972F209} (Pixami-PhotoWorks Upload UI Control) - http://services.photoworks.com/Pixami/PixamiSFWUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/1d/www.n…GAPANEL_USA.cab
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com/panel/grapevine/dcainst.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4010/ftp…21/cpbrkpie.cab
O16 - DPF: {AB9820A0-02A9-11D5-A72F-004F4E002BD6} (JFC Classes) - http://igweb04.iamgame.com/java2/cabs/swing.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,11/mcgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://a.download.toontown.com/sv1.0.24.15/ttinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab53852.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.89.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - http://entimg.msn.com/client/msnmusax2602.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by7fd.bay7.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab53083.cab
O20 - Winlogon Notify: lfl10N - C:\WINDOWS\SYSTEM32\lfl10N.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apache2 - Unknown owner - C:\OpenSA\Apache2\bin\Apache.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Program Files\Prevx1\PXAgent.exe
–
End of file - 14133 bytes
PLease, this is all so above my head and I have no idea what any of it means, I would love any help or advice I could get. THANK YOU!!!!!
Heather
Downloaded and ran Prevx1, fixed whatever it said to fix.
I first ran Spybot, which I use weekly usually. It found over 90 problems, fixed them
Downloaded Adaware, ran it fixed everything it found
Dowloaded the AVG spyware ran that as directed on the self help section, this is that report:
AVG Anti-Spyware - Scan Report
———————————————————
+ Created at: 5:47:51 PM 3/31/2007
+ Scan result:
C:\WINDOWS\Downloaded Program Files\turbo.inf -> Adware.BetterInternet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141638.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\cfg32a.exe -> Adware.BookedSpace : Cleaned with backup (quarantined).
C:\WINDOWS\brix6ie.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
C:\WINDOWS\cpbrkpie.ocx -> Adware.Coupons : Cleaned with backup (quarantined).
HKU\S-1-5-21-2646752555-1850456698-4159782051-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{56B90057-DFC9-4075-87B6-2AAFED4FEF0F} -> Adware.Fatpickle : Cleaned with backup (quarantined).
C:\WINDOWS\eliteunstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll -> Adware.Minibug : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145765.exe -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0137557.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138583.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138584.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138588.dll -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141639.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141640.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141651.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\micro1\a1.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145743.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\WINDOWS\itpb_3.exe -> Adware.Relevant : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145769.dll -> Adware.RK : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Save.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/SaveUninst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Sync.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\WUInst01.cab/SaveInstCm.exe/Uninst.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\WUInst.dll -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\Documents and Settings\Alexa\Local Settings\Temp\v4x3.ga2me -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\{6CDA57D7-09D8-1033-0830-020403020001}\system.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\DeskAlerts\deskbar.dll -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138558.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138566.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138604.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138644.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0139650.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0140642.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141693.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1349\A0141750.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145745.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145762.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\vexga5me3.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145763.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\micro1\a4.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145761.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145764.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145768.exe -> Adware.TTC : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138625.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138626.lnk -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145766.exe/empty_00000001 -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\amstream.exe.tcf -> Adware.UrlSpy : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141645.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141646.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141647.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Adware.WebSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141635.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141636.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141637.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142735.dll -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2646752555-1850456698-4159782051-1006\Dc23.exe -> Downloader.Agent.ac : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138572.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138611.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0138652.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0139655.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1343\A0140650.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\svchosts.exe -> Downloader.Agent.bca : Cleaned with backup (quarantined).
C:\Documents and Settings\Mike\Local Settings\Temp\tmp7F.tmp.exe -> Downloader.Agent.bjk : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWA7P_0001_N91M0809NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
C:\WINDOWS\Downloaded Program Files\UWAS7_0001_N91M1112NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\WinOpts -> Proxy.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0144733.exe -> Proxy.Small.osw : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142748.sys -> Rootkit.Agent.dh : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Cookies\heather@microsoftwlmessengermkt.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\Mike\Local Settings\Temp\Cookies\mike@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adobe : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@adorigin[2].txt -> TrackingCookie.Adorigin : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Adtrak : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Mike\Local Settings\Temp\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@connextra[2].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Dbbsrv : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][2].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Epilot : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@hypertracker[1].txt -> TrackingCookie.Hypertracker : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@info[1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@info[1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Info : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@linkbuddies[2].txt -> TrackingCookie.Linkbuddies : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Myaffiliateprogram : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\LocalService\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@popuptraffic[2].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Popuptraffic : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Porntrack : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@_[1].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Real : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Realcastmedia : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Searchingbooth : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@starware[2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@toplist[2].txt -> TrackingCookie.Toplist : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@login.tracking101[1].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@trafficcenter[1].txt -> TrackingCookie.Trafficcenter : Cleaned.
C:\Documents and Settings\Alexa\Cookies\alexa@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed]-stat[2].txt -> TrackingCookie.Web-stat : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Heather\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@yadro[2].txt -> TrackingCookie.Yadro : Cleaned.
C:\Documents and Settings\Alexa\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Heather\Cookies\heather@yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mike\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mike\Cookies\mike@yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1335\A0132527.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145735.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\tmp3.tmp.dll -> Trojan.Agent.agv : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{1AC0E789-9DAD-4713-9601-8D65D244D81F} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{52777FCD-2A3F-41D2-A502-010D4393EC2A} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{73D0584D-0A4E-4186-95BB-0A1008147521} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{87AC4B9F-5C48-419B-BD35-79B760BBE560} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{AD4EEA6B-EB22-4664-A697-329DC7F84201} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\Documents and Settings\Heather\Local Settings\Application Data\Microsoft\Windows Defender\FileTracker\{D018BC33-38D9-4291-B72C-2AD62B5A8119} -> Trojan.Qhost.f : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\wapisvsu.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1345\A0141652.exe -> Trojan.VB.tg : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142745.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1353\A0145733.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\adirka.dll -> Worm.Banwarum.f : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142746.dll -> Worm.Zhelatin.al : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141730.exe -> Worm.Zhelatin.bp : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1350\A0142747.exe -> Worm.Zhelatin.by : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-2646752555-1850456698-4159782051-1006\Dc25.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1341\A0137563.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141711.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141720.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{21D7D692-4662-421F-93B0-877BC3820711}\RP1347\A0141722.exe -> Worm.Zhelatin.cc : Cleaned with backup (quarantined).
::Report end
After that once I figued out what Hijack this was I downloaded it and ran a log I guess it's called.
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 6:55:35 PM, on 3/31/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Prevx1\PXAgent.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Prevx1\PXConsole.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\desktop weather\desktopweather_1351785.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Heather\Desktop\HiJackThis_v2.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.com/0SEENUS/SAOS01
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=566…p://my.msn.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r21.mchsi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r21.mchsi.com;
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {553c73a2-b85b-4b21-b25a-464d7d8add05} - C:\WINDOWS\system32\lfl10N.dll
O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
O2 - BHO: (no name) - {57E218E6-5A80-4f0c-AB25-83598F25D7E9} - (no file)
O2 - BHO: (no name) - {632C3EC7-0013-0310-CEA5-03C04EEFDD0D} - C:\WINDOWS\system32\trxriqi.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: (no name) - {9A56BA79-BA75-4584-9A36-38DF91947EB5} - \
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [lnwin.exe] C:\WINDOWS\system32\lnwin.exe
O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [{6CDA57D7-09D7-1033-0830-020403020001}] "C:\Program Files\Common Files\{6CDA57D7-09D7-1033-0830-020403020001}\Update.exe" te-110-12-0000271 (User 'Default user')
O4 - Startup: check-ip-changed.bat
O4 - Startup: desktop weather.lnk = C:\Program Files\desktop weather\desktopweather_1351785.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\netfilter.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0335A685-ED24-4F7B-A08E-3BD15D84E668} - http://dl.filekicker.com/send/file/128985-NZIL/PhPSetup.cab
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab53083.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://mf.hud.gov:63001/CFIDE/classes/CFJava.cab
O16 - DPF: {084F552D-19EB-4668-9788-984CBC781A8F} - http://survey.otxresearch.com/Preloader.dll
O16 - DPF: {140F03AE-0588-11D4-BD45-0050048A82BF} (eShare Web Collaboration Class) - http://chat.1800flowers.com/netagent/objects/emagic.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1954A4B1-9627-4CF2-A041-58AA2045CB35} (Brix6ie Control) - http://a19.g.akamai.net/7/19/7125/1267/ftp…/v6/brix6ie.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/inst…leanerstart.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (ZoneBuddy Class) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab53083.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {427273CC-764E-11D3-823D-006097F90453} (Pixami Image Editor Control) - http://www.photoworks.com/pixami/BPImageEditor.cab
O16 - DPF: {4620BC29-8B8E-4F4E-9D92-1DB6633D6793} - http://rd1.surfernetwork.com/surferplugin.ocx
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsc…64/mcinsctl.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://spaces.msn.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab53083.cab
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) - http://zone.msn.com/bingame/dsh2/default/D…h2.1.0.0.55.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1152532782703
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} - http://www.nick.com/common/groove/gx/GrooveAX27.cab
O16 - DPF: {7B461720-5910-45A3-B617-3B53A972F209} (Pixami-PhotoWorks Upload UI Control) - http://services.photoworks.com/Pixami/PixamiSFWUploader.cab
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} (MJLauncherCtrl Class) - http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
O16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} - http://dm.screensavers.com/dm/installers/si/1/sinstaller.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab31267.cab
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://ftp.us.dell.com/fixes/PROFILER.CAB
O16 - DPF: {92CA8ACC-4E99-4A2A-93F1-B2C5CADC8613} (NMInstall Control) - http://a14.g.akamai.net/f/14/7141/1d/www.n…GAPANEL_USA.cab
O16 - DPF: {93EFDAB8-8800-4896-B428-76F943140E1B} - http://www.consumerinput.com/panel/grapevine/dcainst.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/4010/ftp…21/cpbrkpie.cab
O16 - DPF: {AB9820A0-02A9-11D5-A72F-004F4E002BD6} (JFC Classes) - http://igweb04.iamgame.com/java2/cabs/swing.cab
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/…ro.cab53083.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmg…,11/mcgdmgr.cab
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} - http://a.download.toontown.com/sv1.0.24.15/ttinst.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {C915801D-6F00-49CD-8A9A-8DE5C11ADDC1} (Pixami Drag/Drop Upload UI Control) - http://www.photoworks.com/pixami/DragDropUploader.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) - http://zone.msn.com/bingame/pacz/default/pandaonline.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (StadiumProxy Class) - http://zone.msn.com/binframework/v10/StProxy.cab53852.cab
O16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) - http://zone.msn.com/bingame/dash/default/D…sh.1.0.0.89.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} - http://entimg.msn.com/client/msnmusax2602.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by7fd.bay7.hotmail.msn.com/activex/HMAtchmt.ocx
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {FF3C5A9F-5A91-4930-80E8-4709194C2AD3} (CheckersZPA Object) - http://zone.msn.com/bingame/zpagames/Check…PA.cab53083.cab
O20 - Winlogon Notify: lfl10N - C:\WINDOWS\SYSTEM32\lfl10N.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\System32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\System32\browseui.dll
O23 - Service: Apache2 - Unknown owner - C:\OpenSA\Apache2\bin\Apache.exe (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: GoogleDesktopManager - Unknown owner - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Program Files\Prevx1\PXAgent.exe
–
End of file - 14133 bytes
PLease, this is all so above my head and I have no idea what any of it means, I would love any help or advice I could get. THANK YOU!!!!!
Heather