Here's the latest...
Kaspersky scan log:
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Thursday, August 02, 2007 11:04:58 PM
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 3/08/2007
Kaspersky Anti-Virus database records: 371345
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 193043
Number of viruses found: 5
Number of infected objects: 159 / 0
Number of suspicious objects: 0
Duration of the scan process: 02:07:00
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Crypto\RSA\MachineKeys\3ad391678a806ec4d691e83aaa393b6f_24adf822-76f7-4481-b30b-ff1b40f8687f Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\eHome\logs\ehRecvr.log Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt.log Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\DSAgnt_GTActions.log Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\gdql_d_DSAgnt.log Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Gtek\GTUpdate\AUpdate\DellSupport\glog.log Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\cert8.db Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\formhistory.dat Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\history.dat Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\key3.db Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\parent.lock Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\search.sqlite Object is locked skipped
C:\Documents and Settings\Jen\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\urlclassifier2.sqlite Object is locked skipped
C:\Documents and Settings\Jen\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\Cache\_CACHE_001_ Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\Cache\_CACHE_002_ Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\Cache\_CACHE_003_ Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Application Data\Mozilla\Firefox\Profiles\t9uuyk0z.default\Cache\_CACHE_MAP_ Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\History\History.IE5\MSHist012007080220070803\index.dat Object is locked skipped
C:\Documents and Settings\Jen\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Jen\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Jen\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS100.CAB/A0045109.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS100.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS104.CAB/A0045116.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS104.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS105.CAB/A0045129.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS105.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS106.CAB/A0045136.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS106.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS107.CAB/A0046138.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS107.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS108.CAB/A0046148.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS108.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS109.CAB/A0046177.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS109.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS110.CAB/A0046185.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS110.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS111.CAB/A0046191.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS111.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS112.CAB/A0046198.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS112.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS113.CAB/A0046208.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS113.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS114.CAB/A0046307.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS114.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS115.CAB/A0046351.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS115.CAB/A0046402.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS115.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS123.CAB/A0033994.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS123.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS124.CAB/A0034003.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS124.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS125.CAB/A0034067.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS125.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS126.CAB/A0035066.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS126.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS128.CAB/A0036066.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS128.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS129.CAB/A0037066.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS129.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS131.CAB/A0038119.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS131.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS132.CAB/A0038126.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS132.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS133.CAB/A0038136.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS133.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS134.CAB/A0038156.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS134.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS135.CAB/A0038171.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS135.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS136.CAB/A0038178.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS136.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS137.CAB/A0038189.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS137.CAB/A0038192.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS137.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS138.CAB/A0038199.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS138.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS139.CAB/A0038206.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS139.CAB/A0038209.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS139.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS140.CAB/A0038223.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS140.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS141.CAB/A0038230.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS141.CAB/A0038233.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS141.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS367.CAB/A0006035.CPY Infected: not-a-virus:AdWare.Win32.Coupons.b skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS367.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS50.CAB/A0041362.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS50.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS51.CAB/A0042362.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS51.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS52.CAB/A0042373.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS52.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS53.CAB/A0042385.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS53.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS54.CAB/A0042392.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS54.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS55.CAB/A0042403.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS55.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS56.CAB/A0042513.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS56.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS57.CAB/A0042522.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS57.CAB/A0042526.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS57.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS58.CAB/A0042540.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS58.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS59.CAB/A0042568.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS59.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS60.CAB/A0042575.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS60.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS61.CAB/A0042582.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS61.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS62.CAB/A0042588.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS62.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS63.CAB/A0042595.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS63.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS64.CAB/A0042603.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS64.CAB/A0042607.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS64.CAB CAB: infected - 2 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS65.CAB/A0042623.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS65.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS66.CAB/A0042653.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS66.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS67.CAB/A0042670.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS67.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS68.CAB/A0042686.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS68.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS69.CAB/A0042693.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS69.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS70.CAB/A0043692.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS70.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS71.CAB/A0043698.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS71.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS72.CAB/A0043705.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS72.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS73.CAB/A0043713.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS73.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS75.CAB/A0043724.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS75.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS76.CAB/A0043744.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS76.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS77.CAB/A0043752.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS77.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS78.CAB/A0043758.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS78.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS79.CAB/A0043777.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS79.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS80.CAB/A0043792.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS80.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS81.CAB/A0043801.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS81.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS82.CAB/A0043974.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS82.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS83.CAB/A0020547.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS83.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS85.CAB/A0043982.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS85.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS86.CAB/A0043997.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS86.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS87.CAB/A0044004.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS87.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS89.CAB/A0044046.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS89.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS90.CAB/A0044057.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS90.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS91.CAB/A0044064.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS91.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS92.CAB/A0023597.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS92.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS95.CAB/A0044073.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS95.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS96.CAB/A0044079.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS96.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS98.CAB/A0044101.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS98.CAB CAB: infected - 1 skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS99.CAB/A0044108.CPY Infected: not-a-virus:AdWare.Win32.HelpExpress skipped
C:\Jen's Old Machine\C Drive\_RESTORE\ARCHIVE\FS99.CAB CAB: infected - 1 skipped
C:\Program Files\Trend Micro\Internet Security 12\Quarantine\10.tmp Infected: Trojan-Dropper.Win32.Agent.bmk skipped
C:\QooBox\Quarantine\C\WINDOWS\system32\xxyvuuv.dll.vir Infected: not-a-virus:AdWare.Win32.Virtumonde.jp skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\VundoFix Backups\pmkjh.dll.bad Infected: not-a-virus:AdWare.Win32.Virtumonde.lc skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt Object is locked skipped
C:\WINDOWS\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{06ABB95C-F70D-4F67-B453-B45F103EF2C8}.crmlog Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\DEFAULT Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\IntelDH.evt Object is locked skipped
C:\WINDOWS\system32\config\Media Ce.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SYSTEM Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
Scan process completed.
HijackThis for main XP account (the one I use):
Logfile of HijackThis v1.99.1
Scan saved at 11:06:43 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\internet explorer\iexplore.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\Documents and Settings\Jen\Desktop\HJT\Spyware.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) -
https://www.microsof...iveXClient1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase8300.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
HijackThis for secondary XP account #1:
Logfile of HijackThis v1.99.1
Scan saved at 11:09:33 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Documents and Settings\Jen\Desktop\HJT\Spyware.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.dell.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) -
https://www.microsof...iveXClient1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase8300.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
HijackThis for secondary XP account #2:
Logfile of HijackThis v1.99.1
Scan saved at 11:11:04 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
C:\WINDOWS\system32\dllhost.exe
C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Documents and Settings\Jen\Desktop\HJT\Spyware.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
https://secure.sysen...auth/login.aspx
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [pccguide.exe] "C:\Program Files\Trend Micro\Internet Security 12\pccguide.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [OE_OEM] "C:\Program Files\Trend Micro\Internet Security 12\TMAS_OE\TMAS_OEMon.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Program Neighborhood Agent.lnk = C:\Program Files\Citrix\ICA Client\pnagent.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cab
O16 - DPF: {4EFA317A-8569-4788-B175-5BAF9731A549} (Microsoft Virtual Server VMRC Advanced Control) -
https://www.microsof...iveXClient1.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onec...lscbase8300.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel® Quick Resume Technology Drivers (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology\ELService.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~1\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~1\tmproxy.exe
Many many thanks!
- Jen