This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unwanted Pop Up Windows

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Greetings!

My wife got a new (old) laptop from work, and it has unwanted pop up windows that show up every 2-5 minutes. Examples include campusdirt.com, c5.zedo.com, & content.meevee.com.

To combat the problem, I've run Spybot, AdAware, AVG Anti-Spyware, ATF Cleaner, and a Hijack This log. Also downloaded Explorer 7.0 from 6.0, but that didn't solve it.

My logs from AVG Anti-Spyware and Hijack This:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 1:16:53 PM 4/21/2007

+ Scan result:



C:\WINDOWS\system32\cscentfy.dll -> Adware.Cscentfy : Cleaned.
C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe1173924829 -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007401.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007402.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007403.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007404.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007405.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007406.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007407.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007408.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007409.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007410.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007411.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007412.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP73\A0007413.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018927.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018936.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018937.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018938.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018939.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018940.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018941.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018942.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018943.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018944.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018945.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018946.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018947.exe -> Downloader.Agent.awf : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0018948.exe -> Downloader.Agent.awf : Cleaned.
C:\WINDOWS\system32\bak\lsasss.exe -> Downloader.Agent.awf : Cleaned.
C:\Documents and Settings\Debby Greenawalt\Local Settings\Temp\tmp32.tmp.exe -> Downloader.Agent.bjk : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP96\A0017912.dll -> Downloader.ConHook.ah : Cleaned.
:mozilla.10:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.154:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.179:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.227:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.250:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.267:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.312:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.75:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.22:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.23:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.387:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.388:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned.
:mozilla.367:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.368:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.369:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.66:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.129:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.130:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.131:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.132:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.133:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.134:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.332:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.333:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.362:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Cnn : Cleaned.
:mozilla.82:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Debby Greenawalt\Cookies\debby_greenawalt@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Debby Greenawalt\Cookies\debby_greenawalt@epilot[1].txt -> TrackingCookie.Epilot : Cleaned.
:mozilla.191:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.192:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.389:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.390:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.391:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.376:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.256:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.266:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.32:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.33:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.34:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.35:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.36:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.37:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.269:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.270:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.271:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.272:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.274:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.275:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.278:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.279:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.280:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.281:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.282:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.283:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.284:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.285:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.286:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.287:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.288:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.363:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.295:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.296:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.297:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.298:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.299:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.65:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.100:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.101:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.102:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.103:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.104:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.105:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.106:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.107:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.108:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.109:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.110:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.111:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.112:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.113:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.114:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.115:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.116:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.117:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.118:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.119:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.120:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.121:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.122:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.123:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.124:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.125:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.126:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.127:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.128:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.83:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.84:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.85:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.86:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.87:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.88:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.89:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.90:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.91:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.92:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.93:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.94:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.95:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.96:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.97:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.98:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.99:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.28:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.29:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.304:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.30:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.31:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.306:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.307:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.308:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.309:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.322:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Toplist : Cleaned.
:mozilla.323:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.324:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.325:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.358:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.359:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.360:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.361:C:\Documents and Settings\Debby Greenawalt\Application Data\Mozilla\Firefox\Profiles\qf9tu607.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP87\A0015520.dll -> Trojan.Agent.agv : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP88\A0015550.dll -> Trojan.Agent.agv : Cleaned.
C:\System Volume Information\_restore{3F92EE8D-1AE3-4A07-89D2-C4845C685762}\RP89\A0015579.dll -> Trojan.Agent.agv : Cleaned.


::Report end

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Logfile of HijackThis v1.99.1
Scan saved at 1:26:22 PM, on 4/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\OfficeScan NT\tmlisten.exe
C:\OfficeScan NT\OfcPfwSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\OfficeScan NT\pccntmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\OfficeScan NT\Pop3Trap.exe
C:\Program Files\NetZero\exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\TEMP\HW94E0.EXE
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hijackthis\HijackThis.exe
C:\WINDOWS\system32\wuauclt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tmp4.tmp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {d94cdf7b-b0fc-4630-a549-7b655311d514} - C:\WINDOWS\system32\c_86gt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\byvvtr.dll",realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1162352140917
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176043772171
O20 - AppInit_DLLs: c:\windows\system32\ssqpomm.dll
O20 - Winlogon Notify: c_86gt - C:\WINDOWS\SYSTEM32\c_86gt.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe

Any assistance is appreciated. 1,000 thank-yous!
-Randy
Hi and welcome to the forums. :) I'm Markka and I will be helping you with your malware issues. I'll check your HijackThis log. Right now I'm MRU Undergrad, everything that I post to you must be checked by teachers of Malware Removal University. Please be patient. :)
Hello :)

Please download VundoFix.exe to your desktop.
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log.
Note: It is possible that VundoFix encountered a file it could not remove.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Please download the following program and save it to your desktop:

http://noahdfear.geekstogo.com/FindAWF.exe

Once downloaded, double-click on the file to run it. When it is done there will be a file called awf.txt on your desktop. Please post the contents of that file as a reply to this topic.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~


Post:
- A fresh HijackThis log
- Contents of C:\vundofix.txt
- Logfile of FindAWF
Hello Markka and thank you for the help.

I ran vundofix.exe and findawf.exe, and re-ran the hijackthis program. vundofix did pick up and remove something, so I'm feeling optimistic. The log files are as follows:

VundoFix V6.3.19

Checking Java version…

Scan started at 9:45:36 AM 4/22/2007

Listing files found while scanning….

C:\WINDOWS\system32\c_86gt.dll

Beginning removal…

Attempting to delete C:\WINDOWS\system32\c_86gt.dll
C:\WINDOWS\system32\c_86gt.dll Has been deleted!

Performing Repairs to the registry.
Done!

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Logfile of HijackThis v1.99.1
Scan saved at 9:57:46 AM, on 4/22/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\OfficeScan NT\ntrtscan.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\OfficeScan NT\tmlisten.exe
C:\OfficeScan NT\OfcPfwSvc.exe
C:\WINDOWS\TEMP\QL4F88.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
C:\OfficeScan NT\pccntmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\OfficeScan NT\Pop3Trap.exe
C:\Program Files\HPQ\shared\hpqwmi.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\NetZero\exec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll (file missing)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tmp17.tmp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {d94cdf7b-b0fc-4630-a549-7b655311d514} - C:\WINDOWS\system32\c_86gt.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O3 - Toolbar: ZeroBar - {F0F8ECBE-D460-4B34-B007-56A92E8F84A7} - C:\Program Files\NetZero\toolbar.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe
O4 - HKLM\..\Run: [WatchDog] C:\Program Files\InterVideo\DVD Check\DVDCheck.exe
O4 - HKLM\..\Run: [OfficeScanNT Monitor] "C:\OfficeScan NT\pccntmon.exe" -HideWindow
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\pmlklk.dll",realset
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [NetZero_uoltray] C:\Program Files\NetZero\exec.exe regrun
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1162352140917
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1176043772171
O20 - AppInit_DLLs: c:\windows\system32\ssqpomm.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\shared\hpqwmi.exe
O23 - Service: OfficeScanNT RealTime Scan (ntrtscan) - Trend Micro Inc. - C:\OfficeScan NT\ntrtscan.exe
O23 - Service: OfficeScanNT Personal Firewall (OfcPfwSvc) - Trend Micro Inc. - C:\OfficeScan NT\OfcPfwSvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: OfficeScanNT Listener (tmlisten) - Trend Micro Inc. - C:\OfficeScan NT\tmlisten.exe

XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Find AWF report by noahdfear ©2006


bak folders found
~~~~~~~~~~~


Directory of C:\WINDOWS\SYSTEM32\BAK

04/25/2005 06:29 AM 77,824 hkcmd.exe
04/25/2005 06:32 AM 114,688 igfxpers.exe
04/25/2005 06:32 AM 94,208 igfxtray.exe
3 File(s) 286,720 bytes

Directory of C:\PROGRA~1\ANALOG~1\SOUNDMAX\BAK

09/23/2004 04:41 PM 860,160 Smax4.exe
10/14/2004 01:11 PM 1,388,544 SMax4PNP.exe
2 File(s) 2,248,704 bytes

Directory of C:\PROGRA~1\HPQ\DEFAUL~1\BAK

09/07/2004 08:28 PM 213,054 cpqset.exe
1 File(s) 213,054 bytes

Directory of C:\PROGRA~1\HPQ\HPWIRE~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\HPQ\QUICKL~1\BAK

12/03/2004 05:24 PM 290,816 EabServr.exe
1 File(s) 290,816 bytes

Directory of C:\PROGRA~1\INTERV~1\DVDCHE~1\BAK

03/09/2005 06:54 PM 184,320 DVDCheck.exe
1 File(s) 184,320 bytes

Directory of C:\PROGRA~1\SYNAPT~1\SYNTP\BAK

06/20/2005 07:50 AM 729,178 SynTPEnh.exe
1 File(s) 729,178 bytes

Directory of C:\WINDOWS\SYSTEM32\DLA\BAK

04/27/2005 09:33 AM 122,941 tfswctrl.exe
1 File(s) 122,941 bytes

Directory of C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK

08/19/2003 05:01 AM 110,592 sgtray.exe
1 File(s) 110,592 bytes

Directory of C:\PROGRA~1\JAVA\JRE15~1.0\BIN\BAK

11/01/2006 01:09 AM 36,972 jusched.exe
1 File(s) 36,972 bytes

Directory of C:\PROGRA~1\ADOBE\PHOTOS~1\3.0\APPS\BAK

06/07/2005 12:46 AM 57,344 apdproxy.exe
1 File(s) 57,344 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

77824 Apr 25 2005 "C:\WINDOWS\system32\bak\hkcmd.exe"
114688 Apr 25 2005 "C:\WINDOWS\system32\bak\igfxpers.exe"
94208 Apr 25 2005 "C:\WINDOWS\system32\bak\igfxtray.exe"
860160 Sep 23 2004 "C:\Program Files\Analog Devices\SoundMAX\bak\Smax4.exe"
1388544 Oct 14 2004 "C:\Program Files\Analog Devices\SoundMAX\bak\SMax4PNP.exe"
213054 Sep 7 2004 "C:\Program Files\HPQ\Default Settings\bak\cpqset.exe"
290816 Dec 3 2004 "C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe"
184320 Mar 9 2005 "C:\Program Files\InterVideo\DVD Check\bak\DVDCheck.exe"
729178 Jun 20 2005 "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
729178 Jun 20 2005 "C:\Program Files\Synaptics\SynTP\Media\SYNTPENH.EXE"
122941 Apr 27 2005 "C:\Program Files\Sonic\DLA\install\tfswctrl.exe"
122941 Apr 27 2005 "C:\WINDOWS\system32\dla\bak\tfswctrl.exe"
110592 Aug 19 2003 "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe"
36972 Nov 1 2006 "C:\Program Files\Java\jre1.5.0\bin\bak\jusched.exe"
57344 Jun 7 2005 "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe"


end of report

Thanks!
Open HijackThis, Click Do a system scan only, checkmark these. Then close all others windows except HijackThis and press fix checked.

O2 - BHO: Shell Event Object Class - {00534B55-3155-CA4F-B41D-0E922121D03C} - C:\WINDOWS\system32\cscentfy.dll (file missing)
O2 - BHO: (no name) - {1557B435-8242-4686-9AA3-9265BF7525A4} - C:\WINDOWS\system32\tmp17.tmp.dll
O2 - BHO: (no name) - {d94cdf7b-b0fc-4630-a549-7b655311d514} - C:\WINDOWS\system32\c_86gt.dll (file missing)
O4 - HKLM\..\Run: [BootService] rundll32.exe "C:\WINDOWS\pmlklk.dll",realset
O20 - AppInit_DLLs: c:\windows\system32\ssqpomm.dll


Open Notepad
-> copy the following lines into a new document:

@ECHO OFF
move /Y "C:\WINDOWS\system32\bak\hkcmd.exe" "C:\WINDOWS\system32"
move /Y "C:\WINDOWS\system32\bak\igfxpers.exe" "C:\WINDOWS\system32"
move /Y "C:\WINDOWS\system32\bak\igfxtray.exe" "C:\WINDOWS\system32"
move /Y "C:\Program Files\Analog Devices\SoundMAX\bak\Smax4.exe" "C:\Program Files\Analog Devices\SoundMAX"
move /Y "C:\Program Files\Analog Devices\SoundMAX\bak\SMax4PNP.exe" "C:\Program Files\Analog Devices\SoundMAX"
move /Y "C:\Program Files\HPQ\Default Settings\bak\cpqset.exe" "C:\Program Files\HPQ\Default Settings"
move /Y "C:\Program Files\HPQ\Quick Launch Buttons\bak\EabServr.exe" "C:\Program Files\HPQ\Quick Launch Buttons"
move /Y "C:\Program Files\InterVideo\DVD Check\bak\DVDCheck.exe" "C:\Program Files\InterVideo\DVD Check"
move /Y "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe" "C:\Program Files\Synaptics\SynTP"
move /Y "C:\WINDOWS\system32\dla\bak\tfswctrl.exe" "C:\WINDOWS\system32\dla"
move /Y "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" "C:\Program Files\Common Files\Sonic\Update Manager"
move /Y "C:\Program Files\Java\jre1.5.0\bin\bak\jusched.exe" "C:\Program Files\Java\jre1.5.0\bin"
move /Y "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\bak\apdproxy.exe" "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps"
exit

Save the document to your desktop as Fix.bat and filetype: All Files

Please then reboot your computer in Safe Mode by doing the following:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, the Advanced Options Menu should appear;
  • Select the first option, to run Windows in Safe Mode, then press Enter.
  • Choose your usual account.
Go to your desktop and run the file Fix.bat and answer yes to any questions.

Delete these files: (if found)
C:\WINDOWS\system32\tmp17.tmp.dll
C:\WINDOWS\pmlklk.dll
C:\windows\system32\ssqpomm.dll

Reboot in normal mode!


Re-run with AWF.

Post:
- A fresh HijackThis log
- Logfile of AWF

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI