This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I Think I Might Have Hijackers!

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi there! I'm not sure of what to do as I believe I might have browser hijackers? Internet Explorer seems to have turned into Mirar so I stopped using it & have changed to Mozilla firefox instead, but it looks like it is trying to get in there as well. With a bit of help, I have run an ATF cleaner, tune up start up manager which removed Intel Common User Interface Module & I have just run an online scan through Kasperscan which detected 2 viruses & 11 objects infected which looks like, Trojan & Trojan Downloader. Plz, plz plz help me!! Logfile of HijackThis v1.99.1 Scan saved at 7:2bit 7:37 PM, on 3/05/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\Program Files\Common Files\Symantec Shared\ccProxy.exe C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\system32\brsvc01a.exe C:\WINDOWS\system32\brss01a.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe C:\Program Files\LG Software\IP Operator\IP Operator.exe C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe C:\Program Files\Brother\ControlCenter2\brctrcen.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe C:\WINDOWS\AGRSMMSG.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopDisplay.exe C:\Program Files\Google\Google Desktop Search\GoogleDesktopCrawl.exe C:\Program Files\Google\Google Updater\GoogleUpdater.exe C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\Program Files\LG Software\System Control Manager\edd.exe C:\Program Files\Hijackthis\HijackThis.exe C:\WINDOWS\system32\o2flash.exe C:\WINDOWS\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\lg_swupdate\tmcheck.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\system32\UpMedia\ContentTool.dll O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\autoupdate.exe" Gilautouc O4 - HKLM\..\Run: [IPO3] "C:\Program Files\LG Software\IP Operator\IP Operator.exe" -aUtOsTaRtFrOmReG O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun O4 - HKLM\..\Run: [PPort9reminder] "C:\Program Files\ScanSoft\PaperPort\WebEreg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\9\Config\ereg.ini" O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [PC Doc Pro - 3.5] C:\Program Files\PC Doc Pro\pcdocpro.exe /m O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing) O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing) O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: ColdFusion MX Application Server - Unknown owner - C:\CFusionMX\runtime\bin\jrunsvc.exe (file missing) O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe (file missing) O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe (file missing) O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe O23 - Service: GoogleDesktopManager - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: Evil Driver Daemon (NishService) - Unknown owner - C:\Program Files\LG Software\System Control Manager\edd.exe O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
diannejute :D

Welcome to Tom Coyote . Sorry about the delay in responding but we are as most times just overwhelmed with logs.

You need to enable windows to show all files and folders, instructions Here


Make sure you follow these instructions correctly to Remove or Quarantine what it finds and also to save the report, without me seeing the report my hands are tied.
Download and install the 30 day trial of AVG Anti-Spyware 7.5 to your desktop. It's very important that I see the report so make sure you follow the instructions and save the log.
  • Once you have downloaded AVG Anti-Spyware 7.5, locate the icon on the desktop and double-click it to launch the set up program.
  • Once the setup is complete you will need run AVG and update the definition files.
  • On the main screen select the icon Update then select the Update now link.
  • Next select the Start Update button, the update will start and a progress bar will show the updates being installed.
  • Once the update has completed select the Scanner icon at the top of the screen, then select the Settings tab.
  • Once in the Settings screen click on Recommended actions and then select Quarantine <– Dont forget this
  • Under Reports
  • Select Automatically generate report after every scan
  • Un-Select Only if threats were found
  • Close AVG Anti-Spyware 7.5 <– Do not run the scan yet.
Open HijackThis > Do a System Scan Only, close your browser and all open windows, the only program or window you should have open is HijackThis, check the following entries and click on Fix Checked.

O2 - BHO: ohb - {5ED7D3DE-6DBE-4516-8712-01B1B64B7057} - C:\WINDOWS\system32\UpMedia\ContentTool.dll
O9 - Extra button: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra 'Tools' menuitem: UltimateBet - {94148DB5-B42D-4915-95DA-2CBB4F7095BF} - C:\Program Files\UltimateBet\UltimateBet.exe
O9 - Extra button: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyCasino.com - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Program Files\PartyGaming\PartyCasino\RunCasino.exe (file missing)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)



Boot your computer into Safemode
  • Go to Start> Shut Off your Computer> Restart
  • As the computer starts to boot-up, Tap the F8 KEY somewhat rapidly.
  • This will bring up a menu.
  • Use the Up and Down Arrow Keys to scroll up to SAFEMODE
  • Then press the Enter on your Keyboard
Tutorial if you need it How to boot into Safemode


IMPORTANT: Do not open any other windows or programs while ewido is scanning, it may interfere with the scanning process:
  • Launch AVG Anti-Spyware 7.5 by double-clicking the icon on your desktop.
  • Select the Scanner icon at the top and then the Scan tab then click on Complete System Scan.
  • AVG will now begin the scanning process, be patient this may take a little time.
  • Once the scan is complete do the following:
  • If you have any infections you will prompted, then select Apply all actions
  • Next select the Reports icon at the top.
  • Select the Save report as button in the lower left hand of the screen and save it to a text file on your system <–Don't forget this
  • make sure to remember where you saved that file, this is important, I need to see that log.
  • Close AVG Anti-Spyware 7.5
Still in Safemode, delete this folder
C:\WINDOWS\system32\UpMedia



Reboot and run this system cleaner


Download and Install CCleaner
If you don't want the Yahoo Toolbar, be sure to uncheck it during installation
* Click on Run Cleaner
* Run the Issues Scan < – After it scans your system, when you click on the Fix button and it asks you to backup the Registry..Say Yes
Tutorial for CCleaner



Let me see the AVG Report and a New HJT log please.
Hey,
I believe I have followed your instructions & have pasted the hijack this & the report scan, thanks for your help so far.
Di

Logfile of HijackThis v1.99.1
Scan saved at 7:12:55 PM, on 21/05/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\LG Software\System Control Manager\edd.exe
C:\WINDOWS\system32\o2flash.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe
C:\Program Files\LG Software\IP Operator\IP Operator.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\Brother\ControlCenter2\brctrcen.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\lg_swupdate\tmcheck.exe
C:\PROGRA~1\MICROS~2\OFFICE11\OUTLOOK.EXE
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\WINDOWS\msagent\AgentSvr.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.5672\swg.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [MGSysCtrl] C:\Program Files\LG Software\System Control Manager\MGSysCtrl.exe
O4 - HKLM\..\Run: [LG Intelligent Update] "C:\Program Files\lg_swupdate\autoupdate.exe" Gilautouc
O4 - HKLM\..\Run: [IPO3] "C:\Program Files\LG Software\IP Operator\IP Operator.exe" -aUtOsTaRtFrOmReG
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Program Files\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ElbyCheckAnyDVD] "C:\Program Files\SlySoft\AnyDVD\ElbyCheck.exe" /L AnyDVD
O4 - HKLM\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [SetDefPrt] C:\Program Files\Brother\Brmfl05a\BrStDvPt.exe
O4 - HKLM\..\Run: [ControlCenter2.0] C:\Program Files\Brother\ControlCenter2\brctrcen.exe /autorun
O4 - HKLM\..\Run: [PPort9reminder] "C:\Program Files\ScanSoft\PaperPort\WebEreg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\9\Config\ereg.ini"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [B'sCLiP] C:\PROGRA~1\CYBERL~1\INSTAN~1\Win2K\IBurn.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_03\bin\jusched.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Power2GoExpress] "C:\Program Files\CyberLink\Power2Go\Power2GoExpress.exe" /Startup
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: Status Monitor.lnk = C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partner/d…can_unicode.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ColdFusion MX Application Server - Unknown owner - C:\CFusionMX\runtime\bin\jrunsvc.exe (file missing)
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - C:\CFusionMX\db\slserver52\bin\swagent.exe (file missing)
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - C:\CFusionMX\db\slserver52\bin\swstrtr.exe (file missing)
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Evil Driver Daemon (NishService) - Unknown owner - C:\Program Files\LG Software\System Control Manager\edd.exe
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: O2Micro Flash Memory (O2Flash) - Unknown owner - C:\WINDOWS\system32\o2flash.exe
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe





———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 1:46:44 PM 19/05/2007

+ Scan result:



C:\Program Files\Hijackthis\backups\backup-20070519-123856-820.dll -> Adware.SmartShopper : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP109\A0020233.dll -> Adware.SmartShopper : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP76\A0010985.dll -> Adware.SmartShopper : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP99\A0016284.exe -> Adware.SpyHunter : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP75\A0010783.exe -> Downloader.Agent.auv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP75\A0010784.exe -> Downloader.Agent.auv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP76\A0010983.exe -> Downloader.Agent.auv : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP76\A0010984.exe -> Downloader.Agent.auv : Cleaned with backup (quarantined).
:mozilla.170:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.184:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.36:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.37:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.92:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.93:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne j@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.138:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.139:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.223:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.224:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.214:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.215:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.216:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.217:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.55:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.56:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.57:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.58:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.39:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.84:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.315:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.67:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.68:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.244:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.247:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.248:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.249:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.250:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.251:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.79:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.80:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.83:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.84:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.85:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.86:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.87:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.88:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.292:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Clickbank : Cleaned.
:mozilla.40:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.41:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
:mozilla.42:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne j@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
:mozilla.20:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.78:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.410:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.425:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.426:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.163:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.164:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.165:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.221:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.222:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.69:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.70:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.71:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.72:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.141:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.142:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Gemius : Cleaned.
:mozilla.103:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.118:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.119:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.123:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.144:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.182:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.241:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.275:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.281:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.286:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.295:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.298:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.303:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.325:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.331:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.356:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.398:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.438:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.167:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.168:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne [removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne j@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.386:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Hypertracker : Cleaned.
:mozilla.171:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.172:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.8:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.9:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.111:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.112:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Live : Cleaned.
:mozilla.113:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne [removed][2].txt -> TrackingCookie.Live : Cleaned.
:mozilla.21:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.30:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.18:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne [removed][2].txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.102:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.149:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.111:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.116:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.109:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.110:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.400:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.401:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.112:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.113:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.114:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.115:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.116:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.117:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.85:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.86:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.87:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.88:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.89:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.90:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne [removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne j@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.204:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.205:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.206:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.207:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.114:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.115:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.73:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.74:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.184:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.185:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.186:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.187:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.189:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.43:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.52:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.53:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.54:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.16:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.66:C:\Documents and Settings\Shaun D\Application Data\Mozilla\Firefox\Profiles\fvuez9oe.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.320:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.321:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.322:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Web-stat : Cleaned.
:mozilla.158:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Dianne J\Cookies\dianne [removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.166:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.167:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.256:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.258:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.259:C:\Documents and Settings\Dianne J\Application Data\Mozilla\Firefox\Profiles\uskitotq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{23BD1E7C-144F-4FE4-BF69-1108B7FC1E95}\RP86\A0011794.exe -> Trojan.Obfuscated.en : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Documents\My Music1 Track 1, sexy.wma -> Trojan.Wimad.a : Cleaned with backup (quarantined).
C:\Documents and Settings\All Users\Documents\My Music1 Track 1.wma -> Trojan.Wimad.a : Cleaned with backup (quarantined).


::Report end
Good Morning Di, :D

Remove this entry with HJT.
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
The rest of your log looks fine :thumbup: and I don't see any evidence of Mirar on your system, lets do a couple of quick things.

First open AVG Anti Spyware ( FYI this program is yours to keep after the trial, you will still be able to check for updates, run scans and remove what it finds, you will just lose some bells and whistles like the auto update and the background guard ) and go into the Quarantine folder and remove everything thats in there.



You also have some bad entries in your Windows System Restore program which means that if you ever use it to revert your system to an earlier date for any reason you take the risk of those bad entries being restored… and we don't want that to happen. So follow these steps to flush it all out and I can't emphasize enough how important it is to create a new restore point.

Turn off System Restore.
  • Right-click My Computer.
  • Click Properties.
  • Click the System Restore tab.
  • Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Turn ON System Restore.
  • Right-click My Computer.
  • ClickProperties.
  • Click the System Restore tab.
  • UN-Check Turn off System Restore on all Drives.
  • Click Apply, and then click OK.
Create a new Restore Point <– Very Important
  • You will have to be in Catagory View in the Control Panel to see this.
  • Go to Start> Control Panel> and up on the top left, make sure your in Catagory View
  • Go to Performance and Maintenance> System Restore> ( this will also be up on your top left ) then Create a New Restore Point
  • You can name the Restore Point anything you like
System Restore Tutorial <– If you need it




Now do this and if there is no evidence of Mirar than you will be good to go.

Open Hijackthis
  • Go to Misc Tools> Open Uninstall Manager.
  • Click on Save List.
  • The list will open in Notepad.
  • Copy and Paste the List into this thread
Let me just see the Uninstall list please and let me know how your system is behaving now.
Hey there, Everything seems to be improving! It's no where near as slow as it has been and I haven't seen mirar pop up, thanx so much! Di 1 Click PC Fix 2007 v3.2 ADing FontManager Adobe Flash Player ActiveX Adobe Illustrator 7.0 Adobe Photoshop CS Adobe Reader 8 Agere Systems HDA Modem AnyDVD AVG Anti-Spyware 7.5 Battle Realms Demo Brother MFL-Pro Suite Canon S750 CC_ccProxyExt ccCommon CCleaner (remove only) ccPxyCore Chicken Invaders 2 demo v2.60 CloneDVD CyberLink InstantBurn Drug Lord 2 DVD Solution Font Creator Program 3.0 Font Xplorer Lite 1.2.1 FontFinder 32 FontLister 3.4.9 FontLoader FontReview 2.6 Full Tilt Poker Google Desktop Google Toolbar for Internet Explorer Google Toolbar for Internet Explorer Google Updater High Definition Audio Driver Package - KB888111 Hijackthis 1.99.1 HijackThis 1.99.1 Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows XP (KB926239) Hotfix for Windows XP (KB929120) Hotfix for Windows XP (KB935448) Intel® Graphics Media Accelerator Driver IP Operator J2SE Runtime Environment 5.0 Update 3 Kaspersky Online Scanner LG Intelligent Update LimeWire PRO 4.11.0 LiveUpdate 3.0 (Symantec Corporation) Macromedia Dreamweaver MX Macromedia Extension Manager Macromedia Fireworks MX Macromedia Flash MX Macromedia FreeHand 10 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Office Standard Edition 2003 Microsoft OpenType Font Properties Extension (Remove Only) Microsoft User-Mode Driver Framework Feature Pack 1.0 Mozilla Firefox (2.0.0.3) MSRedist MyFonts Font Manager Norton AntiSpam Norton AntiSpam Norton AntiVirus 2006 Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security Norton Internet Security 2006 (Symantec Corporation) Norton Protection Center Norton WMI Update Norton WMI Update Norton™ Security Scan O2Micro Flash Memory Card Windows Driver V2.06 PaperPort Penguin Puzzle Power2Go 4.0 PowerDVD PowerProducer Printer's Apprentice RealPlayer REALTEK GbE & FE Ethernet PCI-E NIC Driver Realtek High Definition Audio Driver Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899589) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Soul Reaver 2 Demo SPBBC Star Trek Armada II DEMO Symantec KB-DocID:2003093015493306 System Control Manager TuneUp Utilities 2007 Typograf4.8f UltimateBet Update for Windows XP (KB894391) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB908531) Update for Windows XP (KB910437) Update for Windows XP (KB911280) Update for Windows XP (KB912945) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Uptown Engine Wallpaper Installation Windows Installer 3.1 (KB893803) Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB884575 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893056 Yahoo! Install Manager Yahoo! Toolbar
Di,

These are no biggies, they are your call.

It looks like this is installed twice.

Hijackthis 1.99.1
HijackThis 1.99.1


C:\Program Files\Hijackthis\HijackThis.exe <– Keep this one and remove the other.


If you don't use these than uninstall them. Gambling sites and file sharing sites are not always but sometimes can bring you problems.
Full Tilt Poker
LimeWire PRO 4.11.0
UltimateBet



You need to update your Java as the older versions leave holes in your system for the bad guys to sneak in.
  • Your Java is out of date and leaving your system vulnerable.
  • Go to your Add-Remove Programs in the Control Panel and uninstall any previous versions of Java (J2SE Runtime Environment)

    J2SE Runtime Environment 5.0 Update 3 <– uninstall this
  • It should have an icon next to it:
    [external image: Posted Image]
    Select it and click Remove.
  • Reboot your system.
  • Then go to the Sun Microsystems and install the update
  • Java Runtime Environment Version 6 Update 1 <–This is what you need to download and install.
  • If you chose the online installation, it will prompt you to run the program.
  • If you chose the offline installation, you will be prompted to save the file and you can run it from wherever you saved it.
  • Then after install you can verify your installation here Sun Java Verify
I like to to do the offline installation and save the setup file in case I may need it in the future



Malware Complaints
Are you mad ? I mean really mad, seething mad, so mad your ready to spit, mad that you have taken your hard earned dollars to buy a computer only to have some Miscredents, Dirt Bags and Cyber Criminals install a malicious program on your computer without your knowledge or consent. You can post your complaint at the above site. If you live in the U.S.A. you can also report your grievance to your State Attorney Generals Office and the Federal Trade Commission's Bureau of Consumer Protection.


How did I get infected in the first place ? Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • Tom Coyote
  • TonyKlein CastleCops
  • Grinler BleepingComputer
  • Geeks To Go
  • Dslreports



Here are some free programs to install, don't leave home without them
  • Spybot Search and Destroy 1.4
    Check for Updates/ Immunize and run a Full System Scan on a regular basis.
  • Ad-Aware SE Personal 1.06
    Check for Updates and run a Full System Scan on a regular basis.
  • Spyware Blaster It will prevent most spyware from ever being installed.
  • Spyware Guard It offers realtime protection from spyware installation attempts.
  • Win Patrol This program will warn you when any changes are being made to your system and give you the option to deny the change.
  • IE-Spyad
    IE-Spyad places over 4000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 2.0 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.
  • Zone Alarm Here is a free Firewall from Zone Labs, I wouldn't access the internet without it.
Thanks for stopping by Tom Coyote , I'm glad I was able to help you. :D
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI