This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

assistance with hjt log file-remove oinadserver popup

17 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting a oinadserver IE window opening on me about every 5 minutes. I have d/l'd hijackthis and created a log. can someone read this for me and advise. Thanks.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:05:00 PM, on 11/12/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\Common Files\A?pPatch\m?iexec.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: (no name) - {00000000-d9e3-4bc6-a0bd-3d0ca4be5271} - (no file)
O2 - BHO: (no name) - {029e02f0-a0e5-4b19-b958-7bf2db29fb13} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AFF3B60-CFE0-D711-8D79-DF066DA7AFFA} - C:\WINDOWS\system32\flwnunlt.dll (file missing)
O2 - BHO: (no name) - {1adbcce8-cf84-441e-9b38-afc7a19c06a4} - (no file)
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: (no name) - {2d7cb618-cc1c-4126-a7e3-f5b12d3bcf71} - (no file)
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: (no name) - {51641ef3-8a7a-4d84-8659-b0911e947cc8} - (no file)
O2 - BHO: (no name) - {54645654-2225-4455-44A1-9F4543D34546} - (no file)
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: (no name) - {669695bc-a811-4a9d-8cdf-ba8c795f261e} - (no file)
O2 - BHO: (no name) - {6abc861a-31e7-4d91-b43b-d3c98f22a5c0} - (no file)
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {944864a5-3916-46e2-96a9-a2e84f3f1208} - (no file)
O2 - BHO: Her - {971D5B7B-F7DF-43ee-B771-6B7FA09975C3} - C:\WINDOWS\system32\sipov.dll (file missing)
O2 - BHO: (no name) - {a4a435cf-3583-11d4-91bd-0048546a1450} - (no file)
O2 - BHO: (no name) - {b8875bfe-b021-11d4-bfa8-00508b8e9bd3} - (no file)
O2 - BHO: (no name) - {bb936323-19fa-4521-ba29-eca6a121bc78} - (no file)
O2 - BHO: (no name) - {c2680e10-1655-4a0e-87f8-4259325a84b7} - (no file)
O2 - BHO: (no name) - {c5af2622-8c75-4dfb-9693-23ab7686a456} - (no file)
O2 - BHO: (no name) - {ca1d1b05-9c66-11d5-a009-000103c1e50b} - (no file)
O2 - BHO: oembios32.msdn_hlp - {D79E1D43-C805-40EF-8ACB-DFFB17E9A4AF} - C:\WINDOWS\system32\oembios32.dll (file missing)
O2 - BHO: (no name) - {d8efadf1-9009-11d6-8c73-608c5dc19089} - (no file)
O2 - BHO: (no name) - {e9147a0a-a866-4214-b47c-da821891240f} - (no file)
O2 - BHO: (no name) - {e9306072-417e-43e3-81d5-369490beef7c} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Gmsccbl] "C:\Program Files\Common Files\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 9563 bytes
Go here and click the Kaspersky Online Scanner button - I.E. is required for this scan.
  • Read the Requirements and limitations before you click Accept.
  • Allow the ActiveX download if necessary.
  • Once the database has downloaded click Next.
  • Click Scan Settings and check the "Scan using the following antivirus database" is set to extended, not standard, and then click OK.
  • Click on "My Computer" and then put the kettle on!
  • When the scan has completed, click Save Report As…
  • Enter a name for the file in the Filename: text box and then click the down arrow to the right of Save as type: and select text file (*.txt)
  • Click Save - by default the file will be saved to your Desktop, but you can change this if you wish.
Copy and paste the report into your next reply along with a fresh HJT log and a description of how your PC is behaving.

Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.

Also, run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
Scan took over two hours. Below is log for virus scan and new hjt log. System seems to be running okay speed wise. But I am still getting those adds popping up. I had several during the scan.

Additional question: this laptop is my daughters and all this stuff started happening after she loaned it to a friend. I brought it to my home and it is now connected to my wireless home network with two other computers. Are they at risk because this infected computer is now on the same network? Thank.

This site rocks! I have read many postings and you guys have great responses with step by step actions that even I can follow.

Log for Virus scan:

——————————————————————————-
KASPERSKY ONLINE SCANNER REPORT
Friday, November 16, 2007 12:56:46 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 16/11/2007
Kaspersky Anti-Virus database records: 460162
——————————————————————————-

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 42398
Number of viruses found: 10
Number of infected objects: 13
Number of suspicious objects: 0
Duration of the scan process: 02:33:54

Infected Object Name / Virus Name / Last Action
C:\19.tmp Infected: Trojan-PSW.Win32.Zbot.z skipped
C:\B.tmp/data0002 Infected: Trojan-Downloader.Win32.PurityScan.eg skipped
C:\B.tmp NSIS: infected - 1 skipped
C:\C.tmp/stream/data0002 Infected: not-a-virus:Downloader.Win32.Agent.q skipped
C:\C.tmp/stream/data0003 Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\C.tmp/stream Infected: not-a-virus:AdWare.Win32.AdBand.b skipped
C:\C.tmp NSIS: infected - 3 skipped
C:\D.tmp Infected: Trojan-Downloader.Win32.Small.fxy skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\Christina\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Christina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Christina\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Christina\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Christina\Local Settings\History\History.IE5\MSHist012007111520071116\index.dat Object is locked skipped
C:\Documents and Settings\Christina\Local Settings\Temp\272461.exe Infected: Rootkit.Win32.Agent.ey skipped
C:\Documents and Settings\Christina\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Christina\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Christina\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\AрpPatch\mѕiexec.exe Infected: not-a-virus:AdWare.Win32.PurityScan.gg skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{0010A1A2-0D1C-4DD1-89F3-BAA5D69BA537}\RP423\A0077696.exe Infected: Trojan.Win32.VB.azo skipped
C:\System Volume Information\_restore{0010A1A2-0D1C-4DD1-89F3-BAA5D69BA537}\RP426\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Cookies\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\WINDOWS\system32\drivers\ip6fw.sys Infected: Trojan-Downloader.Win32.Agent.acl skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\ntos.exe Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\system32\wsnpoem\audio.dll Object is locked skipped
C:\WINDOWS\system32\wsnpoem\video.dll Object is locked skipped
C:\WINDOWS\tsitra72.exe Infected: Trojan-Downloader.Win32.Agent.enr skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:46:11 AM, on 11/16/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Common Files\Real\Update_OB\realevent.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\F?nts\??oolsv.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {0AFF3B60-CFE0-D711-8D79-DF066DA7AFFA} - C:\WINDOWS\system32\flwnunlt.dll (file missing)
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {EBF9D210-37F8-6F2A-DC2B-3DE679F60DC4} - C:\WINDOWS\system32\odyyb.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\RunOnce: [AAW] "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" "+b1"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Gmsccbl] "C:\Program Files\Common Files\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Rxhce] "C:\Program Files\F?nts\??oolsv.exe"
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 7821 bytes
Sorry, it was late last night when I made previous reply and I forgot to add the below uninstall list. Ad-Aware SE Personal Adobe Download Manager 2.0 (Remove Only) Adobe Reader 7.0.8 AntiVir/XP AOL Instant Messenger AOL Toolbar 2.0 ATI Control Panel ATI Display Driver BCM V.92 56K Modem Broadcom 440x Driver Installer Camera Driver Dell ResourceCD DivX DivX Converter DivX Player HighMAT Extension to Microsoft Windows XP CD Writing Wizard HijackThis 2.0.2 iPod for Windows 2005-03-23 iTunes J2SE Runtime Environment 5.0 Update 1 Jasc Paint Shop Photo Album Jasc Paint Shop Pro 8 Dell Edition Kaspersky Online Scanner Macromedia Flash Player 8 McAfee Privacy Service McAfee SecurityCenter McAfee SpamKiller McAfee VirusScan Microsoft Office Professional Edition 2003 Microsoft Windows XP Video Decoder Checkup Utility Mozilla Firefox (1.5.0.12) MSXML 4.0 SP2 (KB936181) ORiNOCO 802.11 Wireless Client Outerinfo QuickTime RealOne Player Roxio VideoWave Movie Creator Samsung USB Driver Security Update for Windows Media Player (KB911564) Security Update for Windows Media Player 10 (KB911565) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 10 (KB936782) Security Update for Windows Media Player 6.4 (KB925398) Security Update for Windows XP (KB883939) Security Update for Windows XP (KB890046) Security Update for Windows XP (KB893756) Security Update for Windows XP (KB896358) Security Update for Windows XP (KB896422) Security Update for Windows XP (KB896423) Security Update for Windows XP (KB896424) Security Update for Windows XP (KB896428) Security Update for Windows XP (KB896688) Security Update for Windows XP (KB899587) Security Update for Windows XP (KB899588) Security Update for Windows XP (KB899591) Security Update for Windows XP (KB900725) Security Update for Windows XP (KB901017) Security Update for Windows XP (KB901214) Security Update for Windows XP (KB902400) Security Update for Windows XP (KB903235) Security Update for Windows XP (KB904706) Security Update for Windows XP (KB905414) Security Update for Windows XP (KB905749) Security Update for Windows XP (KB905915) Security Update for Windows XP (KB908519) Security Update for Windows XP (KB908531) Security Update for Windows XP (KB911280) Security Update for Windows XP (KB911562) Security Update for Windows XP (KB911567) Security Update for Windows XP (KB911927) Security Update for Windows XP (KB912812) Security Update for Windows XP (KB912919) Security Update for Windows XP (KB913446) Security Update for Windows XP (KB913580) Security Update for Windows XP (KB914388) Security Update for Windows XP (KB914389) Security Update for Windows XP (KB916281) Security Update for Windows XP (KB917159) Security Update for Windows XP (KB917344) Security Update for Windows XP (KB917422) Security Update for Windows XP (KB917953) Security Update for Windows XP (KB918118) Security Update for Windows XP (KB918439) Security Update for Windows XP (KB918899) Security Update for Windows XP (KB919007) Security Update for Windows XP (KB920213) Security Update for Windows XP (KB920214) Security Update for Windows XP (KB920670) Security Update for Windows XP (KB920683) Security Update for Windows XP (KB920685) Security Update for Windows XP (KB921398) Security Update for Windows XP (KB921503) Security Update for Windows XP (KB921883) Security Update for Windows XP (KB922616) Security Update for Windows XP (KB922760) Security Update for Windows XP (KB922819) Security Update for Windows XP (KB923191) Security Update for Windows XP (KB923414) Security Update for Windows XP (KB923689) Security Update for Windows XP (KB923694) Security Update for Windows XP (KB923980) Security Update for Windows XP (KB924191) Security Update for Windows XP (KB924270) Security Update for Windows XP (KB924496) Security Update for Windows XP (KB924667) Security Update for Windows XP (KB925454) Security Update for Windows XP (KB925486) Security Update for Windows XP (KB925902) Security Update for Windows XP (KB926255) Security Update for Windows XP (KB926436) Security Update for Windows XP (KB927779) Security Update for Windows XP (KB927802) Security Update for Windows XP (KB928090) Security Update for Windows XP (KB928255) Security Update for Windows XP (KB928843) Security Update for Windows XP (KB929123) Security Update for Windows XP (KB929969) Security Update for Windows XP (KB930178) Security Update for Windows XP (KB931261) Security Update for Windows XP (KB931768) Security Update for Windows XP (KB931784) Security Update for Windows XP (KB932168) Security Update for Windows XP (KB933566) Security Update for Windows XP (KB933729) Security Update for Windows XP (KB935839) Security Update for Windows XP (KB935840) Security Update for Windows XP (KB936021) Security Update for Windows XP (KB937143) Security Update for Windows XP (KB938127) Security Update for Windows XP (KB938829) Security Update for Windows XP (KB939653) Security Update for Windows XP (KB941202) Security Update for Windows XP (KB943460) SigmaTel AC97 Audio Drivers Sonic DLA Sonic RecordNow! Sonic Update Manager Synaptics Pointing Device Driver Update for Windows XP (KB894391) Update for Windows XP (KB896727) Update for Windows XP (KB898461) Update for Windows XP (KB900485) Update for Windows XP (KB910437) Update for Windows XP (KB916595) Update for Windows XP (KB920872) Update for Windows XP (KB922582) Update for Windows XP (KB927891) Update for Windows XP (KB929338) Update for Windows XP (KB930916) Update for Windows XP (KB931836) Update for Windows XP (KB933360) Update for Windows XP (KB936357) Update for Windows XP (KB938828) V4100 Digital Camera Driver Viewpoint Manager (Remove Only) Viewpoint Media Player Windows Genuine Advantage v1.3.0254.0 Windows Installer 3.1 (KB893803) Windows Installer 3.1 (KB893803) Windows Media Format Runtime Windows Media Player 10 Windows XP Hotfix - KB834707 Windows XP Hotfix - KB867282 Windows XP Hotfix - KB873333 Windows XP Hotfix - KB873339 Windows XP Hotfix - KB885250 Windows XP Hotfix - KB885835 Windows XP Hotfix - KB885836 Windows XP Hotfix - KB886185 Windows XP Hotfix - KB887472 Windows XP Hotfix - KB887742 Windows XP Hotfix - KB888113 Windows XP Hotfix - KB888302 Windows XP Hotfix - KB890047 Windows XP Hotfix - KB890175 Windows XP Hotfix - KB890859 Windows XP Hotfix - KB890923 Windows XP Hotfix - KB891781 Windows XP Hotfix - KB893066 Windows XP Hotfix - KB893086 Windows XP Service Pack 2 Yahoo! extras Yahoo! Install Manager Yahoo! Internet Mail Yahoo! Messenger Yahoo! Toolbar

You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of AVG Anti-Spyware 7.5 from here and save it to your Desktop.
If you already have this program installed, skip to Updating AVG Anti-Spyware: below.

* Please note that this program was formerly known as Ewido anti-spyware 4.0.
Taken from the Ewido website -

ewido anti-spyware 4.0 will now continue under the new product name AVG Anti-Spyware 7.5. AVG Anti-Spyware 7.5 contains the same ewido technology, but with some further enhanced features:

Highly improved cleaning
Lower resource usage
Additional languages supported

All current licenses for ewido anti-spyware 4.0 will continue to be valid, and users can change over to the new AVG Anti-Spyware 7.5 for free.

Double click the avgas-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, AVG A-S will open.
  • Updating AVG Anti-Spyware:

    By default AVG A-S is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either AVG A-S will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed AVG A-S, double click avgas-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is…" - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
  • Under "Reports:" click the radio button to the left of "Do not automatically generate reports".
You can now close AVG A-S.

AVG A-S is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that AVG A-S will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

3) Log off from the internet and disconnect your modem cable for the duration of the fix.

4) Go to Start > Control Panel > Add/Remove Programs and remove the following:

Outerinfo

5) Reboot your PC.

Removal

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

F2 - REG:system.ini: UserInit=userinit.exe,C:\WINDOWS\system32\ntos.exe,

O2 - BHO: (no name) - {0AFF3B60-CFE0-D711-8D79-DF066DA7AFFA} - C:\WINDOWS\system32\flwnunlt.dll (file missing)
O2 - BHO: (no name) - {EBF9D210-37F8-6F2A-DC2B-3DE679F60DC4} - C:\WINDOWS\system32\odyyb.dll


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options.

For I.E. 6 - under Temporary Internet files, click on Delete Files…
Check the box to the left of 'Delete all offline content' and then click on OK.

For I.E. 7 - under Browsing History, click delete…
Under Temporary Internet Files, click Delete files…

6) Ensure that ALL open Windows / Programs / Folders are closed and then run AVG Anti-Spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that AVG A-S has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When AVG A-S has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close AVG Anti-Spyware.

7) Remove any/all of the following files/folders that you can find:

Files

C:\19.tmp
C:\B.tmp
C:\C.tmp
C:\D.tmp
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\tsitra72.exe
C:\WINDOWS\system32\odyyb.dll


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


8) Boot into Normal Mode.

Post a new HJT log, the AVG log AND a description of how your PC is running.

Please ignore my use of the Quote Tags - it's due to a forum glitch that shouldn't affect you.
Second attempt to reply. popup ads took over the computer on first try and locked it up. I completed the process you provided but had a couple issues.

1. Popups from outerinfo and internet speed monitor are still occuring.

2. During the process in the REMOVAL step, on of the Hijack this fils was not there:
O2-BHO: (no name)-{EBF9D210-37F8-6F2A-DC2B-3DE679F60DC4}-C:\WINDOWS\system32\odyyb.dll

3. When deleting C:\WINDOWS\temp files the following file would not delete. I received a message "cannot delete startdrv" and the file in the transfer window (from C drive to recycle bin) was Sqlite_yp5q58kQJvR4BXF

4. After closing AVG Anti-Spyware, removing files, the following files were not there:
C:\19.tmp
C:\WINDOWS\system32\drivers\ip6fw.sys
C:\WINDOWS\system32\odyyb.dll

Logs
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:43:01 PM, on 11/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\alg.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\QdrPack\QdrPack9.exe
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\SSTEM~1\csrss.exe
C:\WINDOWS\?icrosoft.NET\?serinit.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\ntos.exe,
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {BEAE8B49-30AE-3F26-DA2B-3DE679F65891} - C:\WINDOWS\system32\dxoko.dll (file missing)
O2 - BHO: (no name) - {BFA6DB41-62FE-682B-DA2B-3DE679F659C0} - C:\WINDOWS\system32\spn.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Gmsccbl] "C:\Program Files\Common Files\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\system32\SSTEM~1\csrss.exe" -vt ndrv
O4 - HKCU\..\Run: [Vbfnate] C:\WINDOWS\?icrosoft.NET\?serinit.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 8361 bytes


———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 7:20:01 PM 11/21/2007

+ Scan result:



C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1708537768-1682526488-854245398-1004\Dc377.exe -> Adware.SuspectModule : Cleaned with backup (quarantined).
C:\WINDOWS\system32\drivers\ip6fw.sys -> Downloader.Agent.acl : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1708537768-1682526488-854245398-1004\Dc95.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{0010A1A2-0D1C-4DD1-89F3-BAA5D69BA537}\RP427\A0095687.exe -> Downloader.PurityScan.ee : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1708537768-1682526488-854245398-1004\Dc38.tmp -> Logger.Zbot.bg : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1708537768-1682526488-854245398-1004\Dc39.tmp -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[132] VM_00301000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[204] VM_00CC1000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[248] VM_00041000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[260] VM_00B61000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[416] VM_00771000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[476] VM_00A21000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[4] VM_00051000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[556] VM_00631000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[604] VM_006C1000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
[792] VM_00FD1000 -> Logger.Zbot.bg : Cleaned with backup (quarantined).
C:\RECYCLER\S-1-5-21-1708537768-1682526488-854245398-1004\Dc349.exe -> Rootkit.Agent.ey : Cleaned with backup (quarantined).
:mozilla.278:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.247realmedia : Cleaned.
:mozilla.263:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.264:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.265:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.266:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.267:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.268:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.269:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.270:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.271:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.272:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.273:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.274:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.275:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.276:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.277:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.291:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.297:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.303:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.338:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.339:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.209:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.375:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.378:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.379:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.380:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.382:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.385:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.46:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.47:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.48:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.49:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.50:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.51:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.52:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
:mozilla.236:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.237:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Adtech : Cleaned.
:mozilla.30:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.31:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.32:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.33:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.34:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
:mozilla.26:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.340:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.73:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
:mozilla.115:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.116:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.117:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.312:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.311:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.313:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.226:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.227:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.228:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.229:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.230:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.231:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
:mozilla.424:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Coremetrics : Cleaned.
:mozilla.372:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.39:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
:mozilla.177:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.178:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.179:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.180:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.383:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Falkag : Cleaned.
:mozilla.165:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.166:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.167:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.168:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
:mozilla.304:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
:mozilla.401:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.402:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
:mozilla.334:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Hitslink : Cleaned.
:mozilla.309:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.310:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.298:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.215:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.216:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.221:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.222:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.425:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.426:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Onestat : Cleaned.
:mozilla.238:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.239:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.240:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.389:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.200:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.201:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.202:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.203:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.204:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.205:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.206:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.207:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.208:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.191:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.192:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.62:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.63:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.64:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.65:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.66:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.299:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.317:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.318:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.319:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.320:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.321:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.322:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.346:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.347:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.243:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.244:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.245:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.246:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.247:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.281:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.355:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.252:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.253:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.254:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.255:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.373:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned.
:mozilla.74:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.75:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.76:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.77:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.78:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.79:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.80:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.81:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.82:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.38:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.431:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.257:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
:mozilla.109:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.110:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.111:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.112:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.113:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.193:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.194:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
:mozilla.195:C:\Documents and Settings\Christina\Application Data\Mozilla\Firefox\Profiles\tcsxiara.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
C:\System Volume Information\_restore{0010A1A2-0D1C-4DD1-89F3-BAA5D69BA537}\RP423\A0077696.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\WINDOWS\system32\wnsinticomsv.exe -> Trojan.Small : Cleaned with backup (quarantined).
C:\19.tmp -> Trojan.Zbot.h : Cleaned with backup (quarantined).


::Report end

Thank you for all your assistance:
You may need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

1) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

F2 - REG:system.ini: UserInit=C:\WINDOWS\SYSTEM32\Userinit.exe,C:\WINDOWS\system32\ntos.exe,

O2 - BHO: (no name) - {BEAE8B49-30AE-3F26-DA2B-3DE679F65891} - C:\WINDOWS\system32\dxoko.dll (file missing)
O2 - BHO: (no name) - {BFA6DB41-62FE-682B-DA2B-3DE679F659C0} - C:\WINDOWS\system32\spn.dll

O4 - HKCU\..\Run: [Gmsccbl] "C:\Program Files\Common Files\A?pPatch\m?iexec.exe"
O4 - HKCU\..\Run: [QdrPack9] "C:\Program Files\QdrPack\QdrPack9.exe"
O4 - HKCU\..\Run: [QdrModule9] "C:\Program Files\QdrModule\QdrModule9.exe"
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\system32\SSTEM~1\csrss.exe" -vt ndrv
O4 - HKCU\..\Run: [Vbfnate] C:\WINDOWS\?icrosoft.NET\?serinit.exe


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

2) Reboot your computer in Safe Mode.
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
3) Remove any/all of the following files/folders that you can find:

Files

C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\spn.dll


As an example:
To delete C:\WINDOWS\system32\filetogo.bye
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on filetogo.bye and from the menu that appears, click on 'Delete'


Folders

C:\Program Files\QdrPack
C:\Program Files\QdrModule

C:\Program Files\Common Files\A?pPatch
C:\WINDOWS\?icrosoft.NET


* These two folders will have each "?" in their names replaced by another character so you will need to be a little careful. As long as there is only one folder that fits the bill for each, delete it. If there are two, or more, folders that could be the malicious one, and you cannot be sure having checked the contents of each, leave them alone and get back to me.

C:\WINDOWS\system32\SSTEM~1

* The tilde(~) in either a file or folder name indicates that this name is longer than six characters and these have been replaced by the tilde for brevity. E.G. C:\DOCUME~1 = C:\Documents and Settings.
The first file, or folder, that uses these particular six letters gets the suffix ~1, the next ~2 and so on.
As there may be more than one folder that meets this criterion, you need to be careful to delete the right one. The contents should give you a clue, but if in doubt don't guess.

As an example:
To delete C:\WINDOWS\system32\foldertogo
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on foldertogo and from the menu that appears, click on 'Delete'


4) Boot into normal mode.

5) You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download SDFix by AndyManchesta from here and save it to your Desktop.
Double click SDFix.exe and it will extract the files to a folder on the drive that contains the Windows Directory - typically C:\SDFix.

2) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode:
  • If the computer is running, shut down Windows, and then turn off the power.
  • Wait 30 seconds, and then turn the computer on.
  • Start tapping the F8 key. The Windows Advanced Options Menu appears. If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Ensure that the Safe Mode option is selected.
  • Press Enter. The computer then begins to start in Safe mode.
  • Login on your usual account.
2) Navigate to and open the SDFix folder and double click RunThis.bat to begin the fix.
  • Type Y to begin the cleanup process.
  • It will remove any Trojan Services and Registry Entries that it finds then prompt you to press any key to Reboot.
  • Press any Key and it will restart the PC.
  • When the PC restarts the Fixtool will run again and complete the removal process then display Finished - press any key to end the script and load your desktop icons.
  • Once the desktop icons load, the SDFix report will open on screen and a copy will be saved into the SDFix folder as Report.txt
    (Report.txt will also be copied to Clipboard ready for posting back on the forum).
Post a new HJT log, Report.txt AND a description of how your PC is running.
Thank you all very much. You've been a great help. I can't believe this is free!!!! I completed the actions and actually made it to this screen with no popups (knock on wood). The computer seems to be running fine. This is my daughters computer and she let the McAfee run out, then she put AntiVir guard on it (which won't complete a update. I now also have AVG trial on it (which is the only one active). Should I uninstall McAfee and AntiVir and just run AVG until I purchase a program? Which program do you recommend?

Thanks again. I will definately recommend this site to everyone. And I will be back if I run into trouble again. I guess I should ask if I am done. There were some files not showing while running this process:

System scan from HJT, the following files were not present to click
O2 - BHO: (no name) - {BFA6DB41-62FE-682B-DA2B-3DE679F659C0} - C:\WINDOWS\system32\spn.dll
O4 - HKCU\..\Run: [Vbfnate] C:\WINDOWS\?icrosoft.NET\?serinit.exe

In safe Mode, removing files, the following files were not there:
C:\WINDOWS\system32\ntos.exe
C:\WINDOWS\system32\spn.dll

HJT Log
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:37:35 PM, on 11/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\Program Files\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\AVPersonal\AVGNT.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\Christina\My Documents\S?mantec\??chost.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\ymsgr_tray.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: McBrwHelper Class - {227B8AA8-DAF2-4892-BD1D-73F568BCB24E} - c:\program files\mcafee.com\mps\mcbrhlpr.dll
O2 - BHO: McAfee Privacy Service Popup Blocker - {3EC8255F-E043-4cae-8B3B-B191550C2A22} - c:\program files\mcafee.com\mps\popupkiller.dll
O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: (no name) - {BAAEDF42-37AD-687A-DA2B-3DE679F65FC5} - C:\WINDOWS\system32\jjdwstv.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Program Files\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" -quiet
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [Zesdri] "C:\Documents and Settings\Christina\My Documents\S?mantec\??chost.exe"
O4 - HKCU\..\Run: [Aida] "C:\WINDOWS\SMBOLS~1\winspool.exe" -vt ndrv
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM; Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL; Toolbar Search - c:\program files\aol\aol toolbar 2.0\resources\en-US\local\search.html
O8 - Extra context menu item: &Yahoo;! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary; - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps; - file:///C:\Program Files\Yahoo!\Common/ycmap.htm
O8 - Extra context menu item: Yahoo! &SMS; - file:///C:\Program Files\Yahoo!\Common/ycsms.htm
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/english/kavwebscan_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Program Files\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Program Files\AVPersonal\AVWUPSRV.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 7644 bytes

SDFix Log


SDFix: Version 1.115

Run by [removed] on Sat 11/24/2007 at 04:39 PM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:
runtime

Path:
\??\C:\WINDOWS\System32\drivers\runtime.sys

runtime - Deleted



Infected ip6fw.sys Found!

ip6fw.sys File Locations:

"C:\WINDOWS\ServicePackFiles\i386\ip6fw.sys" 29056 08/04/2004 01:00 AM
"C:\WINDOWS\system32\dllcache\ip6fw.sys" 29056 08/04/2004 01:00 AM
"C:\WINDOWS\system32\drivers\ip6fw.sys" 29056 08/04/2004 01:00 AM

Infected File Listed Below:

C:\WINDOWS\system32\drivers\ip6fw.sys

Trojan File copied to Backups Folder
Attempting to replace ip6fw.sys with original version…

Original ip6fw.sys Restored


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting…

Service runtime2 - Deleted after Reboot

Normal Mode:
Checking Files:

Trojan Files Found:

C:\12.TMP - Deleted
C:\1A.TMP - Deleted
C:\1C.TMP - Deleted
C:\E.TMP - Deleted
C:\17.TMP - Deleted
C:\WINDOWS\system32\7_exception.nls - Deleted
C:\WINDOWS\system32\lt.res - Deleted
C:\WINDOWS\system32\other.txt - Deleted
C:\WINDOWS\system32\sft.res - Deleted
C:\WINDOWS\Temp\startdrv.exe - Deleted
C:\WINDOWS\system32\drivers\runtime2.sys - Deleted
C:\WINDOWS\system32\ntos.exe - Deleted
C:\WINDOWS\system32\wsnpoem\audio.dll - Deleted
C:\WINDOWS\system32\wsnpoem\video.dll - Deleted




Removing Temp Files…

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1262.1 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-24 17:24:09
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden services & system hive …

scanning hidden registry entries …

scanning hidden files …

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
——————



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\Real\\RealOne Player\\realplay.exe"="C:\\Program Files\\Real\\RealOne Player\\realplay.exe:*:Enabled:RealOne Player"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1126541461\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1126541461\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
"C:\\Program Files\\Real\\RealOne Player\\trueplay.exe"="C:\\Program Files\\Real\\RealOne Player\\trueplay.exe:*:Enabled:RealOne Player"
"C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"="C:\\Program Files\\Yahoo!\\Messenger\\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Disabled:LimeWire"
"C:\\WINDOWS\\system32\\sessmgr.exe"="C:\\WINDOWS\\system32\\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"="C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe:*:Enabled:EasyShare"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\Common Files\\AOL\\1126541461\\ee\\AOLServiceHost.exe"="C:\\Program Files\\Common Files\\AOL\\1126541461\\ee\\AOLServiceHost.exe:*:Enabled:AOL Services"
"C:\\Program Files\\AIM\\aim.exe"="C:\\Program Files\\AIM\\aim.exe:*:Enabled:AOL Instant Messenger"

Remaining Files:
—————

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:

Sat 24 Nov 2007 71,680 ..SHR — "C:\WINDOWS\s?mbols\winspool.exe"
Sun 2 Oct 2005 24,064 …H. — "C:\Documents and Settings\Christina\My Documents\~WRL0001.tmp"
Wed 31 Jan 2007 21,504 …H. — "C:\Documents and Settings\Christina\My Documents\~WRL1886.tmp"
Wed 31 Jan 2007 22,016 …H. — "C:\Documents and Settings\Christina\My Documents\~WRL2342.tmp"
Thu 1 Nov 2007 230,400 ..SHR — "C:\Documents and Settings\Christina\My Documents\S?mantec\??chost.exe"
Fri 12 Nov 2004 37,376 …H. — "C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe"
Mon 15 Oct 2007 0 A..H. — "C:\WINDOWS\SoftwareDistribution\Download\fe95c915e785c18bf9cc0792fb5a73df\BITC.tmp"

Finished!

I am praying you don't find anything, but if you do, I trust you will have a solution. Thanks again for everything!!! Happy Holidays to you and the Tech Crew!!
Please advise on the Anti Virus program.
BTW still no popups!!
Update: I guess knocking on wood didn't help. After logging off here I notice there is still an outerinfo program in All Programs. Then I got two popups on from oinadserver and one from outerinfo. I guess we still have some work to do.
The only AVG items I see are associated with the Anti-Spyware program, which isn't an anti-virus. So you need an AV and a firewall as well - i'd start with free and see how you get on.

AVG Free Edition + manual: Available here.

Comodo firewall: Available here.
Comodo manual: Available here

There is a newer version of Comodo firewall available, but it's a little more involved and you may not wish to spend the time with it.
If you want the latest, click here. The manual is built into the program - just open the interface and click the Miscellaneous icon at the top and select Help.

I run AVG on my laptop and Comodo on my Desktop, and both work just fine. I'd have had Comodo on my lappy too, but the old version wasn't compatible with Vista and I haven't got around to swapping over yet.

Whichever you choose, download the two installation files to your PC and the disconnect from the internet. Uninstall McAfee and AntiVir, and the Outerinfo entry in Add/Remove as well, reboot the PC and then install your two programs. Reconnect to the internet and update AVG. Have it run a full system scan and then post a fresh HJT log and we'll sort out the last of the slime your PC is hanging on to.
I downloaded AVG and Comodo successfully. I uninstalled antivir from add and remove programs. Outerinfo was not in there, but I was able to uninstall it from all programs. When trying to unistall mcafee I get an error that says the unistallation components cannot be initialized. I tried to open the program and it says some of the components are missing and it will not open. I don't have the CD. I tried rebooting but that didn't help. I plan to install the AVG and Comodo anyway so I will have the protection. Any ideas on how to get rid of McAfee. I know on my laptop, I switched from McAfee to Norton and had all kinds of problems getting rid of McAfee. I will now continue your process without removing McAfee. Thanks again. I almost pitched this computer it was so bad, LOL. Now I will be able to give it to my younger daughter.
I went to McAfee website and in chat they gave me a removal tool. So McAfee is all gone now. Comodo and AVG are working fine. I ran a scan with AVG and it found 5 infections and removed them. System is running very good. I haven't had a popup all morning!!!!! Thank you again, you've been a great help and I am very appreciative of your service. Also, I went through and cleaned out a lot of programs. Here is the HJT log, I hope is looks clean. If all is clean can I delete SDFix? and HJT? Thanks a million!!!

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:29:14 PM, on 11/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Comodo\Firewall\CPF.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://channels.aimtoday.com/search/aimtoolbar.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {BAAEDF42-37AD-687A-DA2B-3DE679F65FC5} - C:\WINDOWS\system32\jjdwstv.dll (file missing)
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\CPF.exe" /background
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Comodo Application Agent (CmdAgent) - COMODO - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe

–
End of file - 5576 bytes
Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

O2 - BHO: (no name) - {BAAEDF42-37AD-687A-DA2B-3DE679F65FC5} - C:\WINDOWS\system32\jjdwstv.dll (file missing)

CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

That could be, as they say, that! You can delete SDFix.exe and also this folder: C:\SDFix - whether you wish to keep HJT or not is up to you.

I want you to run your PC as normal for a few days and when you are happy that everything is fine, do the following:

Disable System Restore,
Reboot your PC,
Re-enable System Restore,
Create a Restore Point - this will give a clean one should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI