This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Did we miss something?

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

spywarebot s&d died on me and doesn't work even tho I uninstalled and reinstalled. I did download and install AVG spyware

avg log:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 11:59:43 PM 12/23/2007

+ Scan result:



C:\WINDOWS\SYSTEM32\H2\mccwb2.exe -> Adware.Agent : Ignored.
C:\Program Files\kazaa_setup.exe -> Adware.Altnet : Ignored.
C:\WINDOWS\SYSTEM32\b02FdUe\b02FdUe1065.exe -> Downloader.VB.awj : Cleaned with backup (quarantined).
C:\Program Files\QdrModule\QdrModule9.exe -> Not-A-Virus.Adware.Agent : Ignored.
C:\Documents and Settings\Amber Jackson\Local Settings\Temp\mit35C.tmp.cab/NNBar_VCSetup_876919_LOG_IES_NoDMY_AFF.exe -> Not-A-Virus.Adware.Mirar : Ignored.
C:\Documents and Settings\Amber Jackson\Local Settings\Temp\mit35C.tmp/NNBar_VCSetup_876919_LOG_IES_NoDMY_AFF.exe -> Not-A-Virus.Adware.Mirar : Ignored.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.a : Ignored.
:mozilla.10:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.10:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.11:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.12:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.13:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.14:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.15:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.16:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.17:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.18:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.19:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.442:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.46:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.50:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.566:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.6:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.7:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.80:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.8:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.2o7 : Cleaned.
:mozilla.9:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@brightcove.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@classifiedventures1.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@homestore.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@maxim.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@mediatwo.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@mpire.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@waterfrontmedia.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@buycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@cupolaventures.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@mpire.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq41.tmp -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq42.tmp -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@arn.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@crush.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@grouplotto.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@paidmarketingpanel.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@pan.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@prizeamerica.aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1B.tmp -> TrackingCookie.Abetterinternet : Cleaned.
:mozilla.14:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.15:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.16:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.45:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
:mozilla.46:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@3.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@adengage[2].txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.adengage[2].txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@media.adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq44.tmp -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adtech[1].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq47.tmp -> TrackingCookie.Advertising : Cleaned.
:mozilla.278:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.279:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.39:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
:mozilla.98:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq48.tmp -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq49.tmp -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned.
:mozilla.1123:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.1124:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
:mozilla.1125:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.137:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.138:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
:mozilla.47:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2A.tmp -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq2E.tmp -> TrackingCookie.Clickzs : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@connextra[3].txt -> TrackingCookie.Connextra : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@doubleclick[3].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
:mozilla.53:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
:mozilla.54:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@fastclick[3].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@goclick[1].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ehg-maniatv.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq19.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4B.tmp -> TrackingCookie.Hitbox : Cleaned.
:mozilla.348:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.349:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.350:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.351:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.86:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
:mozilla.87:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Imrworldwide : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@info[2].txt -> TrackingCookie.Info : Cleaned.
:mozilla.1062:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Information : Cleaned.
:mozilla.274:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Information : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@linkbuddies[2].txt -> TrackingCookie.Linkbuddies : Cleaned.
:mozilla.1068:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Liveperson : Cleaned.
:mozilla.1014:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Masterstats : Cleaned.
:mozilla.248:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Matchcraft : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq38.tmp -> TrackingCookie.Mediaplex : Cleaned.
:mozilla.724:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Netflame : Cleaned.
:mozilla.156:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.538:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.539:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.540:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Overture : Cleaned.
:mozilla.572:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
:mozilla.26:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.27:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.28:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.29:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.30:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.31:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.32:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.33:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.34:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.55:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.56:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.57:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
:mozilla.58:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq33.tmp -> TrackingCookie.Pointroll : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4C.tmp -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
:mozilla.161:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.162:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.614:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.615:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
:mozilla.616:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@real[1].txt -> TrackingCookie.Real : Cleaned.
:mozilla.163:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.164:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.165:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.637:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.638:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
:mozilla.639:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@stats2.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
:mozilla.167:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.656:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
:mozilla.657:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.658:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.659:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.660:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.661:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.662:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.663:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.664:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
:mozilla.255:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.67:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
:mozilla.136:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.168:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.169:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.170:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.171:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.172:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.45:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.688:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.689:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.690:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.691:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.692:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
:mozilla.972:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed]-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq34.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
:mozilla.194:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.195:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.196:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.754:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.755:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.756:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.757:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
:mozilla.943:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@anat.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq35.tmp -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
:mozilla.204:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.205:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.206:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.207:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.208:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.209:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.210:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.794:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.795:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.796:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.797:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.798:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.799:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.800:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4E.tmp -> TrackingCookie.Trafficmp : Cleaned.
:mozilla.212:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
:mozilla.805:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Valuead : Cleaned.
:mozilla.1024:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.1025:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.266:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@m.webtrends[2].txt -> TrackingCookie.Webtrends : Cleaned.
:mozilla.226:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.875:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.876:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yadro : Cleaned.
:mozilla.238:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.239:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.240:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.241:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.242:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.243:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.244:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.245:C:\Documents and Settings\NIYA!\Application Data\Mozilla\Firefox\Profiles\gz5t2ghh.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.919:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.920:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.921:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.922:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
:mozilla.923:C:\Documents and Settings\Amber Jackson\Application Data\Mozilla\Firefox\Profiles\sgk74bcw.Default User\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq1F.tmp -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq43.tmp -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\NIYA!\Cookies\niya!@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.


::Report end

Hijack this Logfile:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:06:01 AM, on 12/24/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Amber Jackson\Desktop\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {05A3D0E6-2983-4011-B886-A5F9402B0C72} - \
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {135cb0a0-ad82-499a-a6bf-2bc0ad489495} - C:\WINDOWS\system32\vfunvfq.dll (file missing)
O2 - BHO: (no name) - {3E8EC2D9-806B-4C7F-AE7F-F44AD4ABE8B5} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6C30980B-F845-4B0A-A4DB-B1D9DF83F04F} - \
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: (no name) - {CC0FED23-0208-45EA-91C4-A8A7C4D1A83D} - (no file)
O2 - BHO: (no name) - {DCD53738-C4F9-414A-A03C-C7405A4AC844} - (no file)
O2 - BHO: (no name) - {E9BD0828-1FD9-410C-A50F-43EBE65D310F} - (no file)
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O2 - BHO: (no name) - {FFFAF82C-8133-4541-A2B9-025BBA477291} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [WinAntiSpyware 2007 Free] "C:\Program Files\WinAntiSpyware 2007\was7.exe" /min
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WebBuying] C:\Program Files\Web Buying\v1.8.4\webbuying.exe
O4 - HKCU\..\Run: [WinAble] C:\Program Files\WinAble\winable.exe
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O4 - HKCU\..\Run: [Words] C:\Program Files\Words\Words.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amber Jackson\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} (PCConfigTool.ATMailConfig) - https://secure.adrentech.com/PCConfigtool/PCConfigTool.CAB
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,19/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D92D7607-05D9-4DD8-B68B-D458948FB883} (QuickBooks Online Edition Utilities Class v7) - https://accounting.quickbooks.com/v11.225/qboax7.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O20 - Winlogon Notify: pmkhf - C:\WINDOWS\
O20 - Winlogon Notify: pmnll - C:\WINDOWS\
O20 - Winlogon Notify: rqromlj - C:\WINDOWS\
O20 - Winlogon Notify: tuvtrqq - tuvtrqq.dll (file missing)
O20 - Winlogon Notify: wvuutrq - wvuutrq.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 10707 bytes
Hi,

welcome to What The Tech. My name is Rosty and I'm going to help you with your log.

Download ComboFix from Here or Here to your Desktop.
  • Double click combofix.exe and follow the prompts.
  • When finished, it shall produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall

Regards,

Rosty.
thank you for helping me

combofix log:

ComboFix 07-12-21.4 - Amber Jackson 2007-12-25 9:31:43.1 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
* Created a new restore point
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\All Users\Application Data.\winantispyware 2007
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data.\winantispyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiSpyware 2007\Data\ProductCode
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\Abbr
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ActivationCode
C:\Documents and Settings\All Users\Application Data\WinAntiVirus Pro 2007\Data\ProductCode
C:\Documents and Settings\Amber Jackson\Application Data\WinTouch
C:\Documents and Settings\Amber Jackson\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\Amber Jackson\Application Data\WinTouch\wintouch.cfg.7f050a3ab4ed12a80c949c0a3c92dcb1
C:\Documents and Settings\Amber Jackson\Application Data\WinTouch\wintouch.cfg.e7742da6d7d3112ad169c863231adef4
C:\Documents and Settings\Amber Jackson\err.log
C:\Documents and Settings\Amber Jackson\Start Menu\Programs\Internet Speed Monitor
C:\Documents and Settings\Amber Jackson\Start Menu\Programs\Internet Speed Monitor\Check Now.lnk
C:\Documents and Settings\Amber Jackson\Start Menu\Programs\Internet Speed Monitor\Uninstall.lnk
C:\Documents and Settings\NIYA!\Application Data\WinAntiSpyware 2007
C:\Documents and Settings\NIYA!\Application Data\WinAntiSpyware 2007\Logs\update.log
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\avtasks.dat
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\history.db
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\Logs\update.log
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\Logs\wa7Support.log
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\Logs\winav.log
C:\Documents and Settings\NIYA!\Application Data\WinAntiVirus Pro 2007\PGE.dat
C:\Documents and Settings\NIYA!\Start Menu\Programs\Startup\TA_Start.lnk
C:\Program Files\Common Files\Yazzle1122OinUninstaller.exe
C:\Program Files\Insider
C:\Program Files\ISM
C:\Program Files\ISM\ism.exe
C:\Program Files\ISM\Uninstall.exe
C:\Program Files\QdrDrive
C:\Program Files\QdrDrive\QdrDrive8.dll
C:\Program Files\QdrDrive\qdrloader.exe
C:\Program Files\QdrModule
C:\Program Files\QdrModule\dic.gz
C:\Program Files\QdrModule\kwd.gz
C:\Program Files\QdrModule\QdrModule9.exe
C:\Program Files\WinAble
C:\temp\0b9
C:\temp\0b9\tmpTF.log
C:\temp\0c2
C:\temp\0c2\tmpFF.log
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\temp\brr
C:\temp\brr\tmpZTF.log
C:\Temp\fse
C:\Temp\fse\tmpZTF.log
C:\temp\tn3
C:\WINDOWS\system32\A1
C:\WINDOWS\system32\b02FdUe
C:\WINDOWS\system32\driver
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\drivers\core.sys
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\H2
C:\WINDOWS\system32\H2\mccwb2.exe
C:\WINDOWS\system32\stera.log
C:\WINDOWS\system32\T3
C:\WINDOWS\system32\T4
C:\WINDOWS\system32\T6
C:\WINDOWS\system32\Z1
C:\WINDOWS\system32\Z11
C:\WINDOWS\system32\Z3
C:\WINDOWS\system32\Z5
C:\WINDOWS\system32\Z7

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CORE
——-\core


((((((((((((((((((((((((( Files Created from 2007-11-25 to 2007-12-25 )))))))))))))))))))))))))))))))
.

2007-12-25 08:43 . 2007-12-25 08:43 d——– C:\Program Files\Fisher-Price
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbccgp.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hidusb.sys
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\Amber Jackson\Application Data\Grisoft
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-23 22:52 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-21 17:54 . 2007-12-21 17:55 d——– C:\Documents and Settings\Amber Jackson\Application Data\MSNInstaller
2007-12-18 17:40 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-12-18 17:40 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\SYSTEM32\actskin4.ocx
2007-12-18 17:40 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-12-18 17:40 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-12-18 17:40 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-12-18 17:40 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-12-18 17:40 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-12-18 17:40 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-12-17 13:31 . 2007-12-17 11:13 102,664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2007-12-17 11:13 . 2007-12-18 17:21 d——– C:\Documents and Settings\Amber Jackson\.housecall6.6
2007-11-28 13:18 . 2007-11-28 13:22 d——– C:\Program Files\Picasa2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 05:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 22:40 ——— d—–w C:\Program Files\Alwil Software
2007-12-17 16:12 18,524 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\wklnhst.dat
2007-12-12 02:27 ——— d—–w C:\Program Files\Lexmark X1100 Series
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-02 00:43 1,562 —-a-w C:\Documents and Settings\NIYA!\Application Data\wklnhst.dat
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-03-18 16:24 5,816 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2006-07-02 20:04 62,328 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\GDIPFONTCACHEV1.DAT
2006-04-01 23:00 1,050,422 —-a-w C:\Program Files\EzThmb_Setup.exe
2006-04-01 17:56 611,272 —-a-w C:\Program Files\kazaa_setup.exe
2006-03-30 15:37 24,666,624 —-a-w C:\Program Files\CJXP1100EN.exe
2004-11-20 21:09 6,654,064 —-a-w C:\Program Files\zlsSetup_55_062_000.exe
2004-10-02 16:26 5,827,728 —-a-w C:\Program Files\zlsSetup_51_033_000.exe
2004-09-06 00:21 1,302,528 —-a-w C:\Program Files\mirc616.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05A3D0E6-2983-4011-B886-A5F9402B0C72}]

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{135cb0a0-ad82-499a-a6bf-2bc0ad489495}]
C:\WINDOWS\system32\vfunvfq.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6C30980B-F845-4B0A-A4DB-B1D9DF83F04F}]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"fozr"="C:\Program Files\Common Files\fozr\fozrm.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 02:04]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 10:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhf]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnll]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqromlj]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtrqq]
tuvtrqq.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuutrq]
wvuutrq.dll


.
Contents of the 'Scheduled Tasks' folder
"2004-02-19 00:32:03 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
- C:\WINDOWS\System32\OOBE\OOBEBALN.EXE
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 09:51:08
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-25 9:57:11 - machine was rebooted
.
2007-12-12 08:12:47 — E O F —


New Hijackthis log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:06:55 AM, on 12/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Documents and Settings\Amber Jackson\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: (no name) - {05A3D0E6-2983-4011-B886-A5F9402B0C72} - \
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {135cb0a0-ad82-499a-a6bf-2bc0ad489495} - C:\WINDOWS\system32\vfunvfq.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: (no name) - {6C30980B-F845-4B0A-A4DB-B1D9DF83F04F} - \
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amber Jackson\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} (PCConfigTool.ATMailConfig) - https://secure.adrentech.com/PCConfigtool/PCConfigTool.CAB
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,19/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D92D7607-05D9-4DD8-B68B-D458948FB883} (QuickBooks Online Edition Utilities Class v7) - https://accounting.quickbooks.com/v11.225/qboax7.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: pmkhf - C:\WINDOWS\
O20 - Winlogon Notify: pmnll - C:\WINDOWS\
O20 - Winlogon Notify: rqromlj - C:\WINDOWS\
O20 - Winlogon Notify: tuvtrqq - tuvtrqq.dll (file missing)
O20 - Winlogon Notify: wvuutrq - wvuutrq.dll (file missing)
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 9374 bytes
Hi,

open HijackThis, click doa scan only and place a check next to the following entries:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…/search/ie.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: (no name) - {05A3D0E6-2983-4011-B886-A5F9402B0C72} - \
O2 - BHO: (no name) - {135cb0a0-ad82-499a-a6bf-2bc0ad489495} - C:\WINDOWS\system32\vfunvfq.dll (file missing)
O2 - BHO: (no name) - {6C30980B-F845-4B0A-A4DB-B1D9DF83F04F} - \
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} - http://a19.g.akamai.net/7/19/7125/4047/ftp…23/cpbrkpie.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} -
O20 - Winlogon Notify: pmkhf - C:\WINDOWS\
O20 - Winlogon Notify: pmnll - C:\WINDOWS\
O20 - Winlogon Notify: rqromlj - C:\WINDOWS\
O20 - Winlogon Notify: tuvtrqq - tuvtrqq.dll (file missing)
O20 - Winlogon Notify: wvuutrq - wvuutrq.dll (file missing)

Close all other windows and browsers, except HijackThis, and clcick Fix Checked. Close HijackThis.

Next,
1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05A3D0E6-2983-4011-B886-A5F9402B0C72}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{135cb0a0-ad82-499a-a6bf-2bc0ad489495}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6C30980B-F845-4B0A-A4DB-B1D9DF83F04F}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmkhf]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\pmnll]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqromlj]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtrqq]
tuvtrqq.dll"=-
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuutrq]
wvuutrq.dll"=-



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
combofix did not reboot but here is the log: (thank you so much, so far no popups)

ComboFix 07-12-21.4 - Amber Jackson 2007-12-25 15:33:24.2 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Amber Jackson\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-25 to 2007-12-25 )))))))))))))))))))))))))))))))
.

2007-12-25 08:43 . 2007-12-25 08:43 d——– C:\Program Files\Fisher-Price
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbccgp.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hidusb.sys
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\Amber Jackson\Application Data\Grisoft
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-23 22:52 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-21 17:54 . 2007-12-21 17:55 d——– C:\Documents and Settings\Amber Jackson\Application Data\MSNInstaller
2007-12-18 17:40 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-12-18 17:40 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\SYSTEM32\actskin4.ocx
2007-12-18 17:40 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-12-18 17:40 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-12-18 17:40 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-12-18 17:40 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-12-18 17:40 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-12-18 17:40 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-12-17 13:31 . 2007-12-17 11:13 102,664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2007-12-17 11:13 . 2007-12-18 17:21 d——– C:\Documents and Settings\Amber Jackson\.housecall6.6
2007-11-28 13:18 . 2007-11-28 13:22 d——– C:\Program Files\Picasa2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 05:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 22:40 ——— d—–w C:\Program Files\Alwil Software
2007-12-17 16:12 18,524 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\wklnhst.dat
2007-12-12 02:27 ——— d—–w C:\Program Files\Lexmark X1100 Series
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-02 00:43 1,562 —-a-w C:\Documents and Settings\NIYA!\Application Data\wklnhst.dat
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-03-18 16:24 5,816 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2006-07-02 20:04 62,328 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\GDIPFONTCACHEV1.DAT
2006-04-01 23:00 1,050,422 —-a-w C:\Program Files\EzThmb_Setup.exe
2006-04-01 17:56 611,272 —-a-w C:\Program Files\kazaa_setup.exe
2006-03-30 15:37 24,666,624 —-a-w C:\Program Files\CJXP1100EN.exe
2004-11-20 21:09 6,654,064 —-a-w C:\Program Files\zlsSetup_55_062_000.exe
2004-10-02 16:26 5,827,728 —-a-w C:\Program Files\zlsSetup_51_033_000.exe
2004-09-06 00:21 1,302,528 —-a-w C:\Program Files\mirc616.exe
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"fozr"="C:\Program Files\Common Files\fozr\fozrm.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 02:04]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 10:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtrqq]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuutrq]

S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-09-27 16:12]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\netusbxp.sys [2002-02-19 13:34]

.
Contents of the 'Scheduled Tasks' folder
"2004-02-19 00:32:03 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 15:44:26
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-25 15:47:35
C:\ComboFix2.txt … 2007-12-25 09:57
.
2007-12-12 08:12:47 — E O F —

and a new hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:49:36 PM, on 12/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Amber Jackson\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amber Jackson\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} (PCConfigTool.ATMailConfig) - https://secure.adrentech.com/PCConfigtool/PCConfigTool.CAB
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,19/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D92D7607-05D9-4DD8-B68B-D458948FB883} (QuickBooks Online Edition Utilities Class v7) - https://accounting.quickbooks.com/v11.225/qboax7.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O20 - Winlogon Notify: tuvtrqq - C:\WINDOWS\
O20 - Winlogon Notify: wvuutrq - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 8060 bytes
Hi again,

nearly done!!

Open HijackThis, click do a scan only and place a check next to the following entries:

O20 - Winlogon Notify: tuvtrqq - C:\WINDOWS\
O20 - Winlogon Notify: wvuutrq - C:\WINDOWS\

Close all other windows and browsers, except HijackThis, and click Fix Checked. Close HijackThis.

1. Please open Notepad
  • Click Start , then Run
  • Type notepad .exe in the Run Box.

2. Now copy/paste the entire content of the codebox below into the Notepad window:

Registry::
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tuvtrqq]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\wvuutrq]



3. Save the above as CFScript.txt

4. Then drag the CFScript.txt into ComboFix.exe as depicted in the animation below. This will start ComboFix again.

[external image: Posted Image]


5. After reboot, (in case it asks to reboot), please post the following reports/logs into your next reply:
  • Combofix.txt
  • A new HijackThis log.
combofix log:

ComboFix 07-12-21.4 - Amber Jackson 2007-12-25 16:16:20.3 - NTFSx86
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Amber Jackson\Desktop\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2007-11-25 to 2007-12-25 )))))))))))))))))))))))))))))))
.

2007-12-25 08:43 . 2007-12-25 08:43 d——– C:\Program Files\Fisher-Price
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\usbccgp.sys
2007-12-25 07:49 . 2004-08-04 02:08 31,616 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\usbccgp.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2007-12-25 07:49 . 2001-08-17 14:02 9,600 –a—— C:\WINDOWS\SYSTEM32\DLLCACHE\hidusb.sys
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\Amber Jackson\Application Data\Grisoft
2007-12-23 22:52 . 2007-12-23 22:52 d——– C:\Documents and Settings\All Users\Application Data\Grisoft
2007-12-23 22:52 . 2007-05-30 07:10 10,872 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\AvgAsCln.sys
2007-12-21 17:54 . 2007-12-21 17:55 d——– C:\Documents and Settings\Amber Jackson\Application Data\MSNInstaller
2007-12-18 17:40 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\SYSTEM32\aswBoot.exe
2007-12-18 17:40 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\SYSTEM32\actskin4.ocx
2007-12-18 17:40 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\SYSTEM32\AvastSS.scr
2007-12-18 17:40 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon2.sys
2007-12-18 17:40 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswmon.sys
2007-12-18 17:40 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswTdi.sys
2007-12-18 17:40 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aavmker4.sys
2007-12-18 17:40 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\aswRdr.sys
2007-12-17 13:31 . 2007-12-17 11:13 102,664 –a—— C:\WINDOWS\SYSTEM32\DRIVERS\tmcomm.sys
2007-12-17 11:13 . 2007-12-18 17:21 d——– C:\Documents and Settings\Amber Jackson\.housecall6.6
2007-11-28 13:18 . 2007-11-28 13:22 d——– C:\Program Files\Picasa2

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-12-24 05:05 ——— d—–w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-12-18 22:40 ——— d—–w C:\Program Files\Alwil Software
2007-12-17 16:12 18,524 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\wklnhst.dat
2007-12-12 02:27 ——— d—–w C:\Program Files\Lexmark X1100 Series
2007-11-13 10:25 20,480 —-a-w C:\WINDOWS\system32\drivers\secdrv.sys
2007-11-02 00:43 1,562 —-a-w C:\Documents and Settings\NIYA!\Application Data\wklnhst.dat
2007-10-30 23:42 3,590,656 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2007-10-29 22:43 1,287,680 —-a-w C:\WINDOWS\SYSTEM32\quartz.dll
2007-10-29 22:43 1,287,680 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\quartz.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\wmasf.dll
2007-10-27 22:40 222,720 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wmasf.dll
2007-10-26 03:34 8,460,288 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\shell32.dll
2007-10-10 23:56 824,832 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\wininet.dll
2007-10-10 23:56 232,960 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\webcheck.dll
2007-10-10 23:56 1,159,680 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\urlmon.dll
2007-10-10 23:55 671,232 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mstime.dll
2007-10-10 23:55 63,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\icardie.dll
2007-10-10 23:55 6,065,664 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieframe.dll
2007-10-10 23:55 52,224 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeedsbs.dll
2007-10-10 23:55 478,208 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtmled.dll
2007-10-10 23:55 459,264 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\msfeeds.dll
2007-10-10 23:55 44,544 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iernonce.dll
2007-10-10 23:55 384,512 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iedkcs32.dll
2007-10-10 23:55 383,488 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieapfltr.dll
2007-10-10 23:55 27,648 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\jsproxy.dll
2007-10-10 23:55 267,776 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iertutil.dll
2007-10-10 23:55 230,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieaksie.dll
2007-10-10 23:55 214,528 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dxtrans.dll
2007-10-10 23:55 193,024 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\msrating.dll
2007-10-10 23:55 153,088 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakeng.dll
2007-10-10 23:55 132,608 —-a-w C:\WINDOWS\SYSTEM32\DLLCACHE\extmgr.dll
2007-10-10 23:55 124,928 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\advpack.dll
2007-10-10 23:55 105,984 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\url.dll
2007-10-10 23:55 102,400 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\occache.dll
2007-10-10 10:59 70,656 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2007-10-10 10:59 625,152 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2007-10-10 10:59 13,824 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2007-10-10 05:46 161,792 ——w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2007-03-18 16:24 5,816 —-a-w C:\Documents and Settings\All Users\Application Data\ypinfo.bin
2006-07-02 20:04 62,328 —-a-w C:\Documents and Settings\Amber Jackson\Application Data\GDIPFONTCACHEV1.DAT
2006-04-01 23:00 1,050,422 —-a-w C:\Program Files\EzThmb_Setup.exe
2006-04-01 17:56 611,272 —-a-w C:\Program Files\kazaa_setup.exe
2006-03-30 15:37 24,666,624 —-a-w C:\Program Files\CJXP1100EN.exe
2004-11-20 21:09 6,654,064 —-a-w C:\Program Files\zlsSetup_55_062_000.exe
2004-10-02 16:26 5,827,728 —-a-w C:\Program Files\zlsSetup_51_033_000.exe
2004-09-06 00:21 1,302,528 —-a-w C:\Program Files\mirc616.exe
.

((((((((((((((((((((((((((((( snapshot@2007-12-25_ 9.53.20.82 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-12-25 20:54:39 16,384 —-atw C:\WINDOWS\Temp\Perflib_Perfdata_cc.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
"fozr"="C:\Program Files\Common Files\fozr\fozrm.exe" []
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2005-05-31 01:04]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2003-08-06 02:04]
"Lexmark X1100 Series"="C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" [2003-08-19 10:43]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-10-25 18:58]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00]
"!AVG Anti-Spyware"="C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" [2007-06-11 04:25]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"SpecifyDefaultButtons"= 0 (0x0)
"Btn_Search"= 0 (0x0)
"NoBandCustomize"= 0 (0x0)
"NoToolbarCustomize"= 0 (0x0)

S3 hamachi_oem;PlayLinc Adapter;C:\WINDOWS\system32\DRIVERS\gan_adapter.sys [2006-09-27 16:12]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver;C:\WINDOWS\system32\DRIVERS\netusbxp.sys [2002-02-19 13:34]

.
Contents of the 'Scheduled Tasks' folder
"2004-02-19 00:32:03 C:\WINDOWS\Tasks\ISP signup reminder 1.job"
.
**************************************************************************

catchme 0.3.1333 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-12-25 16:25:29
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2007-12-25 16:28:25
C:\ComboFix2.txt … 2007-12-25 15:47
C:\ComboFix3.txt … 2007-12-25 09:57
.
2007-12-12 08:12:47 — E O F —


hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:31:06 PM, on 12/25/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Amber Jackson\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SidebarAutoLaunch Class - {F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D} - C:\Program Files\Yahoo!\browser\YSidebarIEBHO.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amber Jackson\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} (PCConfigTool.ATMailConfig) - https://secure.adrentech.com/PCConfigtool/PCConfigTool.CAB
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,19/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D92D7607-05D9-4DD8-B68B-D458948FB883} (QuickBooks Online Edition Utilities Class v7) - https://accounting.quickbooks.com/v11.225/qboax7.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 7968 bytes
Hi,

Your log looks clean.
How are things running?
Please let me know.

Disable and Enable System Restore. - You should disable and enable system restore to make sure there are no infected files found in a restore point.

You can find instructions on how to enable and re-enable system restore here:
Windows XP System Restore Guide.
Glad to hear you don't have any problems!

Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we at WTT are to help you, for your sake we would rather not have repeat customers. :P

1) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

AVG-AntiSpyware
Install it,update it to the latest definitions, and perform a full system scan.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.


Please also read Tony Klein's excellent article: So how I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. :D (prevention speech by Swandog46)

With friendly regards,

Rosty.
even tho I followed everything to a T boohoo

http://forums.whatthetech.com/My_Hijack_th…505#entry425505

avast will not come up…it scans the memory then says continuing program but it doesn't.

here is the avg log:

———————————————————
AVG Anti-Spyware - Scan Report
———————————————————

+ Created at: 5:09:08 PM 1/6/2008

+ Scan result:



C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP3\A0000019.exe -> Adware.Agent : Ignored.
C:\qoobox\Quarantine\C\WINDOWS\SYSTEM32\H2\mccwb2.exe.vir -> Adware.Agent : Ignored.
C:\Program Files\kazaa_setup.exe -> Adware.Altnet : Ignored.
C:\qoobox\Quarantine\C\Program Files\QdrModule\QdrModule9.exe.vir -> Not-A-Virus.Adware.Agent : Ignored.
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.a : Ignored.
C:\qoobox\Quarantine\catchme2007-12-25_ 94939.57.zip/core.sys -> Rootkit.Agent.eq : Cleaned with backup (quarantined).
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@shopping.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adbrite[3].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Adengage : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@adrevolver[4].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][4].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@advertising[4].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@atdmt[3].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@bluestreak[3].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@casalemedia[4].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@clickbank[2].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@clickbank[3].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@dealtime[1].txt -> TrackingCookie.Dealtime : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@findwhat[1].txt -> TrackingCookie.Findwhat : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@intelli-direct[1].txt -> TrackingCookie.Intelli-direct : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][4].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][5].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][6].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][7].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@realmedia[2].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@revsci[1].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@login.tracking101[2].txt -> TrackingCookie.Tracking101 : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@tribalfusion[3].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\[removed][2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Amber Jackson\Cookies\amber_jackson@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Program Files\Common Files\Update\dnse.exe -> Trojan.DNSChanger.abm : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\dj2\axebmbrpl6.exe -> Trojan.Pakes.bvs : Cleaned with backup (quarantined).


::Report end

it couldn't quarantine one rootkit so I had to select quarantine the whole file

here is hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:12:27 PM, on 1/6/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe
C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Alwil Software\Avast4\ashSimpl.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Amber Jackson\Desktop\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://verizon.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://verizon.yahoo.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [fozr] C:\Program Files\Common Files\fozr\fozrm.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: WKCALREM.LNK = C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Verizon Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\PROGRA~1\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Amber Jackson\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/OAS/ActiveX/MSDcode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkId=39204&clcid=0x409
O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
O16 - DPF: {230C3D02-DA27-11D2-8612-00A0C93EEA3C} (SAXFile FileUpload ActiveX Control) - http://www.winkflash.com/photo/loaders/SAXFile.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {3DE051B7-CE1E-4149-A39E-3037F29068E1} (PCConfigTool.ATMailConfig) - https://secure.adrentech.com/PCConfigtool/PCConfigTool.CAB
O16 - DPF: {77E32299-629F-43C6-AB77-6A1E6D7663F6} (Groove Control) - http://www.nick.com/common/groove/gx/GrooveAX25.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,19/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) - http://zone.msn.com/bingame/feed/default/SproutLauncher.cab
O16 - DPF: {D92D7607-05D9-4DD8-B68B-D458948FB883} (QuickBooks Online Edition Utilities Class v7) - https://accounting.quickbooks.com/v11.225/qboax7.cab
O16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) - http://fdl.msn.com/zone/datafiles/heartbeat.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINDOWS\SYSTEM32\YPCSER~1.EXE

–
End of file - 7380 bytes
please help spybot and caused fatal blue screen while trying to remove trojans i now have black dos screens on startup help
Hi sorry for the delay!!
Didn't receive an e-mail notification.

Download and Save Blacklight to your desktop:

Double-click blbeta.exe then accept the agreement, leave [X]scan through Windows Explorer checked, click > scan then > next

You'll see a list of all items found. There will also be a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers).

Copy and paste this log in your next reply. Don't choose the rename option yet! I want to see the log first, because legitimate items can also be present there, such as "wbemtest.exe"
Rosty I am so sorry I haven't gotten back to you yet…been unable to get to the internet. I am at my mothers house now and she is going to take over for me. btw I haven't received email notifications either…going to check my settings on this software as I have to change my email address anyway. thank you so much for your attention.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI