This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] malware: "pervent unathorized access"

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Dear Tech Savior:

My Windows XP has been hit with its first piece of malware: the popup announces, "Warning: Potential Spyware Operation! Your computer is making unauthorized copies of your system and Internet files. Run full scan now to pervent unathorized access to your files. Click YES to download spyware remover." Thank goodness that these people can't spell! I have not hit YES, but have neverthless lost access to my control panel and the ability to write to a CD. My Google search suggests a fix that involves SmitfraudFix, but I have taken the advice on your site about pausing before I go in with a sledgehammer.

When this first happened, I ran Spybot. It identified some problematic files, and I told it to fix them. Unfortunately, nothing changed in the frequency of the popups, so it evidently did not resolve it. Spybot has the backups that it made when it did that cleanup, but I cannot figure out how to copy that list and insert it here. Please let me know if you need it.

The sequence of events is a bit unclear in my memory but I believe that, after Spybot failed to solve the problem, I went on line to look for another piece of spyware prevention software. I might have been trying to update Skybot; at this point, I really can't remember the sequence of events. (Now, I realize belatedly that it was a dumb move.) A program called Spywarebot somehow inserted itself into the fix. I cannot recall if I agreed to download it or if it presented itself and asked to be downloaded. I did not complete the process. I did send a question to what was described as their service to answer questions on-line 24 hours a day. I asked, "how are you different from Skybot?" After some delay, a paragraph appeared. I closed out of it, but there is a still a shortcut on my desktop – so, something got through.

The popup arrives fairly frequently, but has not changed over time.

Please review this Hijack This Log and give me your advice. Thanks so much.

***************


Logfile of HijackThis v1.99.1
Scan saved at 1:18:29 PM, on 11/10/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;*.local
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\system32\proper.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\deSrcAs.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {D27987B8-7244-4DE0-AE10-39B826B492F1} - C:\WINDOWS\system32\bronto.dll (file missing)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127913187735
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183694583031
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://connectto.mckennalong.com/msrdp.cab
O20 - AppInit_DLLs: skuns.dat
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
Welcome to the forum.

1. Download RVAXO.exe to your desktop.

2. Double click on RVAXO.exe and choose unzip.
It will install to a folder called Rvaxo.

3. Now open up the Rvaxo folder and double click on RVAXO.cmd

You will see a small window pop up, and quickly some lines will run , then the window will close by itself, this is normal behavior.
Then it is possible for an uninstaller of some roque scanner to start up, do not close this but follow all prompts there, and let it run its course.

4. When it's done the computer will reboot…..press any key to reboot.

5. After reboot RVAXO will run again, let it finish

6. After it's done it will create a file called RVAXO-results.log in C:\RVAXO-results.log

7. Copy and paste it back here with a fresh HJT log.

Note:
You can use Uninstall.cmd to remove everything from RVAXO, it will be found in the RVAXO-folder on your desktop.


—————–

Next…….

Please download SUPERAntiSpyware Home Edition (free)

Install it and double-click the icon on your desktop to run it.
It will ask if you want to update the program definitions, click Yes, Let it through your firewall!
Under Configuration and Preferences, click the Preferences button.
Click the Scanning Control tab.
Under Scanner Options make sure the following are checked:
  • Close browsers before scanning
  • Scan for tracking cookies
  • Terminate memory threats before quarantining.
  • Ignore System Restore/Volume Information on ME and XP
  • Please leave the others unchecked.
  • Click the Close button to leave the control center screen.
On the main screen, under Scan for Harmful Software click Scan your computer.
On the left check C:\Fixed Drive.
On the right, under Complete Scan, choose Perform Complete Scan.
Click Next to start the scan. Please be patient while it scans your computer.
After the scan is complete a summary box will appear. Click OK.
Make sure everything in the white box has a check next to it, then click Next.
It will quarantine what it found and if it asks if you want to reboot, click
Yes.

To retrieve the removal information - please do the following:
  • After reboot, double-click the SUPERAntispyware icon on your desktop.
  • Click Preferences . Click the Statistics/Logs tab .
  • Under Scanner Logs , double-click SUPERAntiSpyware Scan Log .
  • It will open in your default text editor (such as Notepad/Wordpad).
  • Please highlight everything , then right-click and choose copy.
  • Click close and close again to exit the program.
Now please paste the removal information along with a fresh HijackThis log in your reply. If it's a large log, you may need several replies to post it.
Please don't forget the log from RVAXO.

Good Luck, MrC
Dear Mr. Charlie –

Thanks so much. I used to live in the far north of Canada, and everyone there would stop to dig a stuck car out of a snow bank. This is a lot like that, and I am grateful for your neighborliness. I also promise to drive more carefully in the future.

Here is my RVAXO log:

Files found:

C:\WINDOWS\system32\bszip.dll

Uninstallers Rogue scanners:


Folders Found:


Hosts-file was reset, If you use a custom hosts file please replace it…

————–RVAXO.exe last run—————

Files found:

Folders Found:

————–RVAXO.exe finished—————-

And here is my SUPERantispyware Scan Log

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 11/11/2007 at 08:33 PM

Application Version : 3.9.1008

Core Rules Database Version : 3342
Trace Rules Database Version: 1343

Scan type : Complete Scan
Total Scan Time : 01:05:31

Memory items scanned : 533
Memory threats detected : 0
Registry items scanned : 6422
Registry threats detected : 14
File items scanned : 68043
File threats detected : 594

MyWay Search Assistant Computers
HKLM\Software\Classes\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32
HKCR\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}\Programmable
C:\PROGRAM FILES\MYWAYSA\SRCHASDE\DESRCAS.DLL
HKLM\Software\Classes\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\InprocServer32#ThreadingModel
HKCR\CLSID\{4D25F926-B9FE-4682-BF72-8AB8210D6D75}\Programmable
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{4D25F921-B9FE-4682-BF72-8AB8210D6D75}
HKU\S-1-5-21-4220525761-1362074759-3848679465-1005\Software\Microsoft\Internet Explorer\URLSearchHooks#{4D25F926-B9FE-4682-BF72-8AB8210D6D75}

Adware.Tracking Cookie
C:\Documents and Settings\Lynn\Cookies\lynn@statcounter[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@wpni.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@burstnet[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@keywordmax[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@nextstat[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@54137116[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@realmedia[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@questionmarket[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@web-stat[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@maxserving[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@zedo[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@revsci[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@msnportal.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@tribalfusion[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][6].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@nextag[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][11].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@6229559[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@trafficmp[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@kanoodle[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@overture[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adrevolver[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@indexstats[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adbrite[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@bizrate[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][4].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cgi-bin[3].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][8].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@edge.ru4[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@tacoda[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@ad1.m5-systems[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][5].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@harpo.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@atwola[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed]-sys[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@serving-sys[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@marketlive.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@indextools[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@broadspancommerce.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@revenue[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@homeclick[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@38237851[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@qksrv[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adinterax[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@expertrealty.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@azjmp[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@workopolis.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cgi-bin[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cgi-bin[6].txt
C:\Documents and Settings\Lynn\Cookies\lynn@9551721[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@LPBofA1[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@11906334[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@clickauditor[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@qnsr[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@neimanmarcus.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@fametracker[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@search4clicks[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@247realmedia[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cnn.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adlegend[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@commonsensemedia[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@indiads[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@roiservice[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@kiplinger.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@clickshift[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@hitbox[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@40715998[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@paypal.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@agoramedia[2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@dealtime[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@geosign.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@ads.i-am-bored[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@mcclatchy.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adtech[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@blockbuster.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@pro-market[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@aia.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@meetupcom.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@1351182[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@partner2profit[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@chefscatalog.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@giftscom.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@50715070[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@stpetersburgtimes.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@viacomedycentralrl.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@webstat[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@apnonline.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@mediaonenetwork[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@homestore.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@versiontracker[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@chitika[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][8].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@valueclick[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@easy-hit-counters[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@superstats[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@buycom.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@ad.m5prod[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adcentriconline[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@smartmoney.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@specificclick[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@shopping.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@bizjournals.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][3].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@bellglobemediapublishing.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed]-journalonline[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cvisits[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@xiti[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@microsoftwga.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cgi-bin[5].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@wilkesbarre.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@countertop[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][5].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][3].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@48286427[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@bluelavagroup.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@albertoculver.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@mannington.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@clickaider[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed].e-planning[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\lynn@smoothcorp.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@netmonster.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][9].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@honoluluadvertiser[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@angieslist.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][7].txt
C:\Documents and Settings\Lynn\Cookies\lynn@media-general[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@medhelpinternational.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][4].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@elitefitness[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@helptheaged[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@cratebarrel.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@airheads1[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@13644240[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@teenymanolo[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@dminsite.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@stats.channel4[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][10].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][7].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@usatoday1.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@gomyhit[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@gomyron[3].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\lynn@gostats[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@leeenterprises.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@www.3dstats[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@interclick[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@yelp.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@www.scripttrack433[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@mattressusa.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@collective-media[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][5].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@enhance[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][6].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@brightcove.112.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@netgear.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@thesexykitchen[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed]
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@adecn[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed]-to-run[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@eyewonder[1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@pointclickhome[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@mediabistro[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@sportingnews.122.2o7[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][9].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@gomyhit[3].txt
C:\Documents and Settings\Lynn\Cookies\[removed][4].txt
C:\Documents and Settings\Lynn\Cookies\lynn@blizzardtracker[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@avsystemcare[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\lynn@gomyron[1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][3].txt
C:\Documents and Settings\Lynn\Cookies\lynn@scrippshgtv.112.2o7[2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][2].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\[removed][1].txt
C:\Documents and Settings\Lynn\Cookies\lynn@click[1].txt

Unclassified.SpywareBot (Not A Threat)
C:\Documents and Settings\Lynn\Desktop\SpywareBot.lnk

And, finally, here is a fresh Highjack This log:

Logfile of HijackThis v1.99.1
Scan saved at 8:45:04 PM, on 11/11/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127913187735
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183694583031
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://connectto.mckennalong.com/msrdp.cab
O20 - AppInit_DLLs: skuns.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

What next? What now?

And thanks so much for your generous assistance. I promise to do many acts of kindness to "pay it forward."

Gratefully,

Albigensian
Well Done.

RVAXO actually did more than is show in the RVAXO log.

——————

Download to your desktop "FixPolicies.exe", a self-extracting ZIP archive from HERE.

Double-click FixPolicies.exe.
Click the Install button on the bottom toolbar of the box that will open.
The program will create a new Folder called FixPolicies.
Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd
A black box will briefly appear and then close.
Reboot the computer so the changes can take affect.

—————-

1. Please download The Avenger by Swandog46 to your Desktop.

* Click on Avenger.zip to open the file
* Extract avenger.exe to your desktop
* Don't run it yet

——————-

Close ALL programs down, leaving ONLY HijackThis running - Click Scan and…..
Place a check against the following items if found:

O4 - HKLM\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O4 - HKCU\..\Run: [Undefined] C:\WINDOWS\system32\winter.exe
O7 - HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1

Click on Fix Checked and exit HijackThis.

——————-

Back to the Avenger.

2. Copy all the text contained in the code box below to your Clipboard by highlighting it, then right click on it and choose Copy [or by pressing (Ctrl+C)]:


Files to delete:
C:\WINDOWS\system32\winter.exe
C:\WINDOWS\System32\skuns.dat

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs

Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


3. Now, start The Avenger program by clicking on its icon on your desktop.

* Under "Script file to execute" choose "Input Script Manually".
* Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
* Right click in the new window and choose Paste or use (Ctrl+V). This will paste the text from the clipboard into the new window.
* Click Done
* Now click on the Green Light to begin execution of the script
* Answer "Yes" twice when prompted.

4. The Avenger will automatically do the following:

* It will Restart your computer. ( In cases where the code to execute contains "Drivers to Unload", The Avenger will actually restart your system twice.)
* On reboot, it will briefly open a black command window on your desktop, this is normal.
* After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
* The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.

Post a fresh HJT log and the avenger.txt and we'll take another look, MrC
Dear Mr. Charlie….

Thanks for the guidance. I might be wrong, but I think that the exclamation point is a bad sign!

Only the two 04 items were found in the HijackThis; following your instructions, I checked them and fixed them. There was no 07 file as described in your post.

I can hear the line, "Mr. Charlie told me so…" but I can't remember which Grateful Dead song it comes from. On the other hand, Mr. Charlie could be the dog.

Many thanks. I await further instructions.

******************


Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\yhjrkckv

*******************

Script file located at: mkvcgxlw

Could not open script file! Error

Could not open script file! Status: 0xc000003b Abort!

**********************

Here is HijackThis:

Logfile of HijackThis v1.99.1
Scan saved at 8:59:32 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127913187735
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183694583031
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://connectto.mckennalong.com/msrdp.cab
O20 - AppInit_DLLs: skuns.dat
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
OK you didn't input the script for the Avenger correctly please try again:
Copy and paste this in (the text in blue)

Files to delete:
C:\WINDOWS\system32\winter.exe
C:\WINDOWS\System32\skuns.dat

Registry values to replace with dummy:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows | AppInit_DLLs


Under "Script file to execute" choose "Input Script Manually".
* Now click on the Magnifying Glass icon which will open a new window titled "View/edit script"
* Right click in the new window and choose Paste or use (Ctrl+V). This will paste the text from the clipboard into the new window.
* Click Done
* Now click on the Green Light to begin execution of the script
* Answer "Yes" twice when prompted.

Pos the log from Avenger and a fresh HJT log, MrC
Dear Mr. C.:

Thanks, and apologies. With the text accurately copied, Avenger gives this log file:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\pffrgjbm

*******************

Script file located at: \??\C:\Program Files\qdtkligt.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:



File C:\WINDOWS\system32\winter.exe not found!
Deletion of file C:\WINDOWS\system32\winter.exe failed!

Could not process line:
C:\WINDOWS\system32\winter.exe
Status: 0xc0000034



File C:\WINDOWS\System32\skuns.dat not found!
Deletion of file C:\WINDOWS\System32\skuns.dat failed!

Could not process line:
C:\WINDOWS\System32\skuns.dat
Status: 0xc0000034

Registry value HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows|AppInit_DLLs replaced with dummy successfully.

Completed script processing.

*******************

Finished! Terminate.


_____________________

HijackThis gives this log:


Logfile of HijackThis v1.99.1
Scan saved at 10:29:11 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16544)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\VPTray.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://mysearch.myway.com/jsp/dellsidebar.jsp?p=DE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local.,;*.local
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Audible Download Manager.lnk = C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1127913187735
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183694583031
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://connectto.mckennalong.com/msrdp.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe

My control panel has reappeared! This seems like a very good sign….

Albigensian
Dear Mr. C – Everything seems to be resolved – all functionality restored! Thanks so much for your help. You and your fellow WhatTheTech volunteers are just wonderful: your generosity and community spirit are an inspiration. And I am so grateful for the speed with which you helped me through this crisis. With much appreciation, Albigensian PS Can you make any recommendations about virus/malware protection? What about the market-dominating products like Norton or McAfee? I know that they aren't as nimble as some of the less widely known products, but I am wondering if their protection is reasonable given their ease of use and installation (for someone who is not very tech savvy). I am looking for something that has pretty good directions and support (in case of problems), and it seems as if there is a tradeoff between the degree to which a product will slow things down and how easy it is to install and troubleshoot. At least, that's the impression that I get by reading the reviews that I can find.

PS Can you make any recommendations about virus/malware protection? What about the market-dominating products like Norton or McAfee?

I actually just took McAfee (which my ISP provides for free) off my XP computers because it slowed them down (Norton seems to do the samething).
I put on AVG Anti-Virus free, SpywareBlaster, SpywareGuard and Comodo Free Firewall. I also keep the registry backed up with Erunt and have AVG-AS and SAS as scanners. System restore and automatic updates are turned off also.

Below you can find all the links and info.

—————–

If you have any questions - please post back

I'll leave you with……..

Some Preventive Maintenance:

Some of the programs you may have run create backups of what was deleted - you can safely delete them now: (delete folders in blue) You can also delete/uninstall the programs themselves.

C:\!KillBox (KillBox)
C:\VundoFix Backups (VundoFix)
C:\QooBox (ComboFix)
C:\SDFix\backups\backups.zip (SDFix)
C:\avenger\backup.zip (Avenger)

RVAXO
You can use Uninstall.cmd to remove everything from RVAXO, it will be found in the RVAXO-folder on your desktop.
Then delete the RVAXO folder and RVAXO.exe.

If you used AVG Anti-Spyware and/or SuperAntiSpyware………..

Open up SuperAntiSpyware > Preferences > General and Start-up > Start-up Options > Uncheck > Start SAS when Windows Starts.
"SAS free" provides no real time protection so there's no need for it to be running, I suggest you keep the program and update regularly - you can use it to scan for malware. It's an excellent program. When you want to start it - just double click on the SAS icon.

AVG Anti-Spyware will provide 30 days of real time protection and then after that you can use it to scan for malware - you'll have to manually update it first.


——————Must have or do:—————–

Now that you're clean: <—-Important Step!!!!
Delete your system restore files and create a new restore point (XP only):

Note: This will remove all previous Restore Points!

1. Turn off System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Restart your computer,

2. Turn on System Restore:

On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UnCheck Turn off System Restore.
Click Apply, and then click OK.

Visit Windows Update and install all the lastest critical updates.

Install these two free programs, they sit in the backround and protect your system from spy and adware being installed on your system, also from your browser being hijacked.

SpywareBlaster Check for updates weekly.

SpywareGuard

IE-SPYAD
Puts over 5000 sites in your restricted zone, so you'll be protected when you visit innocent-looking sites that aren't actually innocent at all.
or try the new ZonedOut

Blocking Unwanted Parasites with a Hosts File
Direct Download - MVPS HOSTS <==> MVPS HOSTS Tutorial

Need a free anti virus?
AVG*free
Avast Free
AntiVir® PersonalEdition Classic
–>Check for updates - daily<—

How about a firewall? The front door to your computer.
Windows firewall is not suffient…install a better one.
Comodo Free Firewall
ZoneAlarm*free
Other free firewalls

Keep those temp files off your system use
ATF Cleaner - hit "select all" then just uncheck "cookies" (uncheck cookies is optional - leave it checked if you want to delete all cookies) then "empty selected"
or
CCleaner
Uncheck "Cookies" under "Internet Explorer".
That will clear out all the temp files on the system.

IMPORTANT!!
Keep your Sun Java up-to-date JRE Version 6 Update 3<–newest version
Delete ALL old versions from add/remove programs if listed first!
Check HERE

Keep the registry backed up - use ERUNT
Print this out and save it
ERUNT Tutorial

Starter Manage you startup programs and services.

———-Free malware removal programs:———-

AVG Anti-Spyware<—VERY GOOD! (XP and 2K only)
SUPERAntiSpyware (free edition)<—Excellent!
AVG Anti-Rootkit Free Edition Run it!!
SpyBot
AD-Aware
CW-Shredder

Please consider using FireFox instead of Internet Explorer. A more secure browser! Easy to make the change!
FireFox Tutorial


Pop-up stoppers:
GoogleToolBar
Pop-upStopperFree

Disable "Windows Messenger Service" XP - 2K (stops pop-up ads -etc):
Shoot The Messenger

Anti-Rootkit Software - Detection, Removal & Protection

Reduce Online Fraud

Slow Computer - Check Here

Don't open e-mail attachments without first scanning them with an up-to-date anti virus program, even after doing that I would be very careful. Don't click on any executables in e-mails or any other links that you're not sure of.
Don't believe e-mails from your bank, financial institution, etc asking for personal informations - they're most likely fraudulent no matter how authentic they look.
Watch your surfing habits, don't click on or download anything you're not sure of. Don't install a program that hasn't been recommended by a reputable organization.

Good luck and thanks for using the forum - MrC
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI