This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Google Search Results Redirected On Internet Explorer

22 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I hope you can help me with this problem. Since I got back from a business trip in April, my IE search results on Google have been redirected. I have used many virus removal tools and nothing seems to help. Last week I went to the IE tools menu, advanced section, and there is an option to restore IE settings. I did this and IE was OK until the first time I rebooted, the problem is back. I did a system restore back to the time it was OK and everything was OK until the next reboot and the problem is back. Now neither restoring IE settings or system restore helps. I initially had IE6 loaded and updated to IE7 thinking it might fix the problem. Here is my Hijack This log:

Logfile of HijackThis v1.99.1
Scan saved at 8:23:32 AM, on 8/1/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\EarthLink TotalAccess\MailClnt.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\alg.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [Internet Explorer] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [EarthLink TotalAccess MailBox] C:\Program Files\EarthLink TotalAccess\\MailClnt.exe "%1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe



Thanks in advance,
Mike
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

1) Download F-Secure's BlackLight from here and save it to your Desktop.

2) Log off from the internet and disconnect your modem cable.

3) Go to Start > Run, copy and paste the following into the text box and hit OK:
"%userprofile%\desktop\fsbl.exe" /expert

The F-Secure Blacklight Beta window should open.
  • Accept the agreement and click Next >.
  • Click the Scan button to begin.
  • Leave the PC idle while the scan takes place.
  • When it has completed, click the Close button.
  • A text file, fsbl-date/time.txt, will be saved onto your Desktop - copy and paste this into your next reply.
Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Thank-You for the prompt reply. Here are the logs you requested: F-Secure BlackLight scan 08/01/07 18:15:39 [Info]: BlackLight Engine 1.0.64 initialized 08/01/07 18:15:39 [Info]: OS: 5.1 build 2600 (Service Pack 2) 08/01/07 18:15:39 [Note]: 7019 4 08/01/07 18:15:39 [Note]: 7005 0 08/01/07 18:16:09 [Note]: 7006 0 08/01/07 18:16:09 [Note]: 7011 1624 08/01/07 18:16:09 [Note]: 7026 0 08/01/07 18:16:09 [Note]: 7026 0 08/01/07 18:16:13 [Note]: FSRAW library version 1.7.1022 08/01/07 18:29:43 [Info]: Hidden file: c:\WINDOWS\SYSTEM32\kdmdo.exe 08/01/07 18:29:43 [Note]: 7002 32 08/01/07 18:29:43 [Note]: 7003 1 08/01/07 18:29:43 [Note]: 10002 1 08/01/07 18:32:21 [Note]: 2000 1012 HJT Uninstall_List: Ad-Aware SE Plus Adobe Photoshop 7.0 Adobe Photoshop Elements Adobe Reader 8.1.0 Adobe SVG Viewer Adobe® Photoshop® Album Starter Edition 3.2 ArcSoft PhotoBase 3 ArcSoft PhotoStudio 5 BCM V.92 56K Modem Britannica Ready Reference Broadcom Advanced Control Suite Canon Camera Window for ZoomBrowser EX Canon CanoScan Toolbox 4.1 Canon EOS Kiss REBEL 300D WIA Driver Canon i9100 Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities File Viewer Utility 1.3 Canon Utilities PhotoStitch 3.1 Canon Utilities RemoteCapture 2.7 Canon Utilities ZoomBrowser EX CCleaner (remove only) CleanUp!
It appears that the uninstall list has been cut off in it's prime - will you let me have the full list when you get a moment.
Sorry about that, Here's the complete uninstall list. Thanks again. Ad-Aware SE Plus Adobe Photoshop 7.0 Adobe Photoshop Elements Adobe Reader 8.1.0 Adobe SVG Viewer Adobe® Photoshop® Album Starter Edition 3.2 ArcSoft PhotoBase 3 ArcSoft PhotoStudio 5 BCM V.92 56K Modem Britannica Ready Reference Broadcom Advanced Control Suite Canon Camera Window for ZoomBrowser EX Canon CanoScan Toolbox 4.1 Canon EOS Kiss REBEL 300D WIA Driver Canon i9100 Canon PhotoRecord Canon RAW Image Task for ZoomBrowser EX Canon RemoteCapture Task for ZoomBrowser EX Canon Utilities File Viewer Utility 1.3 Canon Utilities PhotoStitch 3.1 Canon Utilities RemoteCapture 2.7 Canon Utilities ZoomBrowser EX CCleaner (remove only) CleanUp! DAO Dell Digital Jukebox Driver Dell Picture Studio - Dell Image Expert Dell Solution Center Dell Support DIMIN Image Viewer 2 (remove only) DivX 5.0.2 Bundle EarthLink 5.0 EarthLink FastLane Earthlink Installer - uninstall 'Earthlink 5.0' entry first if present EarthLink Spyware Blocker EarthLink TotalAccess 2004 Easy CD Creator 5 Basic Extensis Intellihance Pro 4.0 FreeCard 2.0 HijackThis 1.99.1 Hotfix for Windows XP (KB914440) Hotfix for Windows XP (KB915865) Intel® Extreme Graphics Driver InterVideo XPack (Combo) Lernout & Hauspie TruVoice for Microsoft Agent Manual CanoScan 5000,5000F,8000F McAfee SecurityCenter Microsoft .NET Framework (English) Microsoft .NET Framework (English) v1.0.3705 Microsoft .NET Framework 1.0 Hotfix (KB928367) Microsoft Data Access Components KB870669 Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Modem Helper Mozilla Firefox (2.0.0.5) Mozilla Firefox (2.0.0.6) MSN Music Assistant Musicmatch® Jukebox Neat Image v5 Demo Nikon Scan OmniPage SE Paint Shop Pro 7 Presto! PageManager 6 Quicken 2002 New User Edition QuickTime RealPlayer Secure IE 2003 and Private IE 2003 Security Update for Step By Step Interactive Training (KB898458) Security Update for Step By Step Interactive Training (KB923723) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901190) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Spybot - Search & Destroy 1.4 The Playa TuneUp Utilities 2007 Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB904942) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB936357) Viewpoint Media Player (Remove Only) Winamp (remove only) Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Internet Explorer 7 Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 WordPerfect Office 2002 WordPerfect Office 2002 Yahoo! Messenger
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download Fixwareout.exe by LonnyRJones from one of these two locations, and save it to your Desktop:

http://downloads.subratam.org/Fixwareout.exe
http://www.bleepingcomputer.com/files/lonny/Fixwareout.exe

2) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Double click Fixwareout.exe to start the Fixwareout Setup Wizard
  • Click Next > Install.
  • Ensure that the box to the left of Run fixit is checked.
  • Click on Finish.
  • Follow the prompts.
  • You will be asked to reboot your computer - please do so. Your system may take longer than usual to load - this is normal.
  • When your system reboots, follow the prompts.
Afterwards HijackThis should launch by itself - if it does not, start it manually.

Click on 'Do a system scan only' and place a checkmark in the boxes to the left of the following entries, by clicking on them:

O17 - HKLM\System\CCS\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78
O17 - HKLM\System\CS1\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78
O17 - HKLM\System\CS2\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: NameServer = 85.255.114.13,85.255.112.78
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: NameServer = 85.255.114.13 85.255.112.78


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Go to Start > Control Panel >Network Connections. Right click your default connection, usually Local Area Connection or Dial-up Connection if you are using Dial-up, and left click on Properties.
* Make a note of the settings before you change them just in case you need to put them back how they were.
Double-click on the Internet Protocol (TCP/IP) item and select the radio button that says Obtain DNS servers automatically. Click OK twice.

3) Go to Start > Run, enter cmd and click OK.
  • At the Dos Prompt Screen, type in ipconfig /flushdns and then press . (notice the space after ipconfig)
  • Close the command prompt window.
4) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
5) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

6) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

7) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete…
Under Temporary Internet Files, click Delete files…

8) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

9) Boot into Normal Mode.

Post a new HJT log (run in Normal Mode), the AVG A-S log, the contents of the logfile C:\fixwareout\report.txt AND a description of how your PC is running.
I finished your instructions. I made 1 mistake, don't know if it would affect the results. Before restarting in safe mode I spaced and missed the "ipconfig/flushdns" command. I noticed this just as I was booting down. I brought it up in normal mode to enter the command, checked that the internet settings stayed as you instructed and booted down. I then brought it up in safe mode. Also, when deleting the files in C:\Documents and Settings\Username\Local Settings\Temp,
got a popup saying "program used by another person or program, cannot delete" for these files:

DF2C37.temp
DF2C43.temp
TWUNK001.mtx
WT114.tmp
WT115.tmp
WT11.tmp
WT12.tmp
WT13.tmp

Here are the logs:

Logfile of HijackThis v1.99.1
Scan saved at 11:21:08 PM, on 8/2/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Corel\WordPerfect Office 2002\Programs\Wpwin10.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Internet Explorer] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [EarthLink TotalAccess MailBox] C:\Program Files\EarthLink TotalAccess\\MailClnt.exe "%1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe



———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:11:45 PM 8/2/2007

+ Scan result:



:mozilla.104:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.105:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.106:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.107:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.108:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.109:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.110:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.111:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.112:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.113:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.114:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.115:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.116:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.117:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.118:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.119:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.120:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.313:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.365:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.519:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.378:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.379:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.380:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Program Files\EarthLink 5.0\[removed]\Cookies\michael [removed][1].txt -> TrackingCookie.Adobe : Cleaned.
:mozilla.224:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.225:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.228:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.229:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.63:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.64:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.154:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.155:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.156:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.157:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.158:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.273:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.9:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.809:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.417:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.418:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.338:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.339:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.340:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.341:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.457:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.458:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.696:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.697:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned.
:mozilla.164:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\[removed][1].txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.39:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.478:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.479:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.289:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Esomniture : Cleaned.
:mozilla.252:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.253:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.254:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.255:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
:mozilla.171:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.833:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.268:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.524:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Hotlog : Cleaned.
:mozilla.33:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.34:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.101:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.102:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.103:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.778:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.762:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.147:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.18:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.285:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Paypal : Cleaned.
C:\Program Files\EarthLink 5.0\[removed]\Cookies\michael [removed][1].txt -> TrackingCookie.Paypal : Cleaned.
:mozilla.211:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.212:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.215:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.216:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.217:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.218:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.219:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.220:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.221:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.626:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.627:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Qksrv : Cleaned.
:mozilla.222:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.223:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.644:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.645:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.646:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.35:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.36:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.37:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.38:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.40:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.41:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.42:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.729:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.357:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.358:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.359:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.360:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.361:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.362:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.451:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.452:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.453:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.454:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.455:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.456:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Sexcounter : Cleaned.
:mozilla.258:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.259:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.260:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.261:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.262:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.263:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.264:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.265:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.266:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.355:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.43:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.44:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.45:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.46:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.47:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.48:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\michael_dober@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.685:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Trafic : Cleaned.
:mozilla.10:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.149:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Valueclick : Cleaned.
:mozilla.767:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\[removed][2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.715:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.198:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.199:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.200:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.201:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Michael Dober\Application Data\Earthlink\6.0\[removed]\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.286:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.287:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.288:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.


::Report end

I hope my mistake didn't mess things up.

Post…the contents of the logfile C:\fixwareout\report.txt

You appear to have omitted this step. Let me have a fresh log from Blacklight as well.
Started from the beginning of your instructions, Google search on Internet Explorer is fixed. Thanks so much. Here are the log files:

Username "Michael Dober" - 2007-08-04 7:47:37 [Fixwareout edited 2007/07/05]

»»»»»Prerun check
HKLM\SOFTWARE\~\Winlogon\ "System"="kdmdo.exe"

HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{61820C7F-1F2D-4EC6-AC52-4AA4C5CE956B}
"DhcpNameServer"="[removed],[removed]"
Successfully flushed the DNS Resolver Cache.


System was rebooted successfully.

»»»»» Postrun check
HKLM\SOFTWARE\~\Winlogon\ "system"=""
….
….
»»»»» Misc files.
….
»»»»» Checking for older varients.
….


C:\Program Files\AntiVermins < Found
Additional tools are recomended.

»»»»» Current runs (hklm hkcu "run" Keys Only)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\\WINDOWS\\System32\\igfxtray.exe"
"HotKeysCmds"="C:\\WINDOWS\\System32\\hkcmd.exe"
"BCMSMMSG"="BCMSMMSG.exe"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"
"MMTray"="\"C:\\Program Files\\MUSICMATCH\\MUSICMATCH Jukebox\\mm_tray.exe\""
"Adobe Photo Downloader"="\"C:\\Program Files\\Adobe\\Photoshop Album Starter Edition\\3.2\\Apps\\apdproxy.exe\""
"Adobe Reader Speed Launcher"="\"C:\\Program Files\\Adobe\\Reader 8.0\\Reader\\Reader_sl.exe\""
"!AVG Anti-Spyware"="\"C:\\Program Files\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Internet Explorer"="C:\\Program Files\\Internet Explorer\\iexplore.exe"
"EarthLink TotalAccess MailBox"="C:\\Program Files\\EarthLink TotalAccess\\\\MailClnt.exe \"%1\""
"ctfmon.exe"="C:\\WINDOWS\\system32\\ctfmon.exe"
….
Hosts file was reset, If you use a custom hosts file please replace it
»»»»» End report »»»»»


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 10:45:40 AM 8/4/2007

+ Scan result:



:mozilla.8:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Doubleclick : No action taken.
:mozilla.10:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tribalfusion : No action taken.


::Report end


Logfile of HijackThis v1.99.1
Scan saved at 11:37:51 AM, on 8/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\Program Files\EarthLink TotalAccess\MailClnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.earthlink.net/partner/more/msie…ton/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Internet Explorer] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [EarthLink TotalAccess MailBox] C:\Program Files\EarthLink TotalAccess\\MailClnt.exe "%1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe


Are there any settings I should restore? Thanks again Noviciate for the help. Tom Coyote Forum is the best!
Mike
1) Download SmitfraudFix.exe by S!Ri from here and save it to your Desktop.

2) Double click SmitfraudFix.exe - this will open a Command Window and also create the SmitfraudFix folder on your Desktop. Once you have read the information, "press any key to continue…"
Press "1" and then to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlogic.org/consulting/proc…processutil.htm
SmitFraudFix v2.208 Scan done at 13:59:03.23, Sat 08/04/2007 Run from C:\Documents and Settings\Michael Dober\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» Process C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\System32\igfxtray.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\BCMSMMSG.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe C:\Program Files\EarthLink TotalAccess\MailClnt.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\EarthLink TotalAccess\TaskPanl.exe C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe C:\WINDOWS\system32\cisvc.exe C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe c:\program files\common files\mcafee\mna\mcnasvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe C:\PROGRA~1\McAfee\MSC\mcpromgr.exe c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe C:\Program Files\McAfee\MPF\MPFSrv.exe C:\Program Files\SiteAdvisor\6066\SAService.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\PROGRA~1\mcafee.com\agent\mcagent.exe C:\WINDOWS\system32\svchost.exe C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe C:\WINDOWS\system32\cidaemon.exe C:\WINDOWS\system32\cidaemon.exe C:\Program Files\Mozilla Firefox\firefox.exe c:\PROGRA~1\mcafee\VIRUSS~1\mcvsshld.exe C:\WINDOWS\system32\cmd.exe »»»»»»»»»»»»»»»»»»»»»»»» hosts »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Michael Dober »»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Michael Dober\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND ! C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\MICHAE~1\APPLIC~1\EARTHL~1\6.0\MIKEDO~1.NET\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files C:\Program Files\AntiVermins\ FOUND ! »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components] "Source"="http://www.butkus.org/chinon/ricoh_mirai/body38.jpg" "SubscribedURL"="http://www.butkus.org/chinon/ricoh_mirai/body38.jpg" "FriendlyName"="" [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\1] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="My Current Home Page" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "system"="" »»»»»»»»»»»»»»»»»»»»»»»» Rustock »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport DNS Server Search Order: 207.69.188.185 DNS Server Search Order: 207.69.188.186 DNS Server Search Order: 207.69.188.187 HKLM\SYSTEM\CCS\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed] »»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware from here and save it to your Desktop.

If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "4" and then to check for updates.
Don't forget to allow SmiUpdate.exe access through your firewall.
Once it has updated, or if there are no updates available, close the window and the folder.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then .
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then .
Your PC now needs to be rebooted. If this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

4) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

5) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

6) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

7) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop… and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

8) Empty the Recycle Bin.

9) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG A-S.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG A-S.

10) Reboot into Normal Mode.

11) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then .

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The AVG A-S log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
The first time running in safe mode I could not find the 2 entries you said to check. here is the log:

Logfile of HijackThis v1.99.1
Scan saved at 4:40:44 PM, on 8/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Internet Explorer] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [EarthLink TotalAccess MailBox] C:\Program Files\EarthLink TotalAccess\\MailClnt.exe "%1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe


I completed the rest of the instructions. Here are the logs:


Logfile of HijackThis v1.99.1
Scan saved at 7:31:35 PM, on 8/4/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = wmplayer.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - c:\program files\mcafee\virusscan\scriptcl.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MMTray] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [Internet Explorer] C:\Program Files\Internet Explorer\iexplore.exe
O4 - HKCU\..\Run: [EarthLink TotalAccess MailBox] C:\Program Files\EarthLink TotalAccess\\MailClnt.exe "%1"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Camio Viewer.lnk = C:\Program Files\Dell Computer\Dell Image Expert\IXApplet.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…96/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,23/mcgdmgr.cab
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: McAfee E-mail Proxy (Emproxy) - McAfee, Inc. - C:\PROGRA~1\COMMON~1\McAfee\EmProxy\emproxy.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\HackerWatch\HWAPI.exe
O23 - Service: McAfee Update Manager (mcmispupdmgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcupdmgr.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Protection Manager (mcpromgr) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
O23 - Service: McAfee Redirector Service (McRedirector) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\redirsvc\redirsvc.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2006\WinStylerThemeSvc.exe


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:13:55 PM 8/4/2007

+ Scan result:



:mozilla.29:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.30:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.31:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.90:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.92:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.93:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.98:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.63:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.64:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.65:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.66:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.67:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.8:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.43:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.121:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.122:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.123:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.124:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.119:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.120:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.45:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.46:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.47:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.48:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.49:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.50:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.51:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.52:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.53:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.54:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.55:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.56:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned.
:mozilla.11:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.89:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.94:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.95:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.96:C:\Documents and Settings\Michael Dober\Application Data\Mozilla\Firefox\Profiles\cdzx70dt.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.


::Report end


rapport.txt:

SmitFraudFix v2.208

Scan done at 16:28:23.75, Sat 08/04/2007
Run from C:\Documents and Settings\Michael Dober\Desktop\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in safe mode

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

»»»»»»»»»»»»»»»»»»»»»»»» Killing process


»»»»»»»»»»»»»»»»»»»»»»»» hosts

127.0.0.1 localhost

»»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix

GenericRenosFix by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\AntiVermins\ Deleted

»»»»»»»»»»»»»»»»»»»»»»»» DNS

HKLM\SYSTEM\CS2\Services\Tcpip\..\{4C9D0E6D-2F07-4D45-A31C-D4C67BB0CEA6}: DhcpNameServer=[removed] [removed] [removed]
HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=[removed] [removed] [removed]


»»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
"system"=""


»»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning

Registry Cleaning done.

»»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» End


The computer seems to be working normally, I am not redirected on Google search results on Internet Explorer. I have a question. When running in safe mode, what is the easiest way to find programs since the screen doesn't show all of them with the difference in resolution. Sometimes when I go to My Computer and then to Desktop, I can't find the programs there (they are there, after reboot I see them). Several times I've had to do a search to find them.
After the instuctions before this last set, I checked to see if the updates to Ad-Aware SE worked because it wasn't working before. I had been updating the defs manually. Just checked to see if Ad-Aware SE updated now, I get an error retrieving update. I tried all the instructions on the Lavasoft FAQ for Ad-Aware SE with no success.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI