This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Malware, Adware, viruses, Trj Horses, etc.

25 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer is infected by a myriad of things all causing it to do crazy things. Stuff is popping up all over the place. I have run Avast and Spywarebot programs, have tried to do a system restore, and have tried to uninstall programs that I recognized as troublesome. Here is my Hijack This Log:

Logfile of HijackThis v1.99.1
Scan saved at 8:32:54 AM, on 2/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\??sks\?hkdsk.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.earthlink.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [rydo] C:\Program Files\Messenger\rydo77798.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [00502736] rundll32.exe "C:\WINDOWS\system32\hqxppips.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Uaol] "C:\DOCUME~1\DONALD~1\MYDOCU~1\YSTEM3~1\explorer.exe" -vt ndrv
O4 - HKCU\..\Run: [Dogr] "C:\Program Files\??sks\?hkdsk.exe"
O4 - HKCU\..\Run: [ofwm] C:\PROGRA~1\COMMON~1\ofwm\ofwmm.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{34BF1BEB-7003-4BBC-8E7F-D9F08B63417B}: NameServer = 205.188.146.145
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Please advise. thank you for your time.
Hello, and welcome to the forum.

My name is Simon V., and I'll be glad to help you with your computer problems.

Please download and install CCleaner.

Open CCleaner. On the Windows tab, leave the default options alone.

  • On the Applications tab, check (tick) all the boxes except Saved Form Information. This will remove all your saved passwords if you leave this box checked.
  • Click on the Run Cleaner button at the bottom right hand corner.
  • When the cleaner has completed, click Tools in the Left Pane.
  • Verify that Uninstall is highlighted in color, or click on it.
  • In the lower right, click Save to Text File.
  • Pull down the arrow at the top of the Save dialog and choose Desktop as the location.
  • You can leave the filename as install.txt.
  • Click Save, then exit Ccleaner.
_______________________________________

Please visit this webpage for instructions for downloading and running ComboFix:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Post the log from ComboFix (C:\Combofix.txt) when you've accomplished that, along with a new HijackThis log and the CCleaner Uninstall List (install.txt).
I did as you instructed. Here are the three log files requested:

ComboFix
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons



Logfile of HijackThis v1.99.1
Scan saved at 8:34:23 PM, on 2/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)


Logfile of HijackThis v1.99.1
Scan saved at 8:34:23 PM, on 2/23/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\SpywareBot\SpywareBot.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Microsoft Works\WkDStore.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.earthlink.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [rydo] C:\Program Files\Messenger\rydo77798.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [BM036314aa] Rundll32.exe "C:\WINDOWS\system32\whovaqhf.dll",s
O4 - HKLM\..\Run: [00502736] rundll32.exe "C:\WINDOWS\system32\rpiirxuj.dll",b
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Uaol] "C:\DOCUME~1\DONALD~1\MYDOCU~1\YSTEM3~1\explorer.exe" -vt ndrv
O4 - HKCU\..\Run: [Dogr] "C:\Program Files\??sks\?hkdsk.exe"
O4 - HKCU\..\Run: [ofwm] C:\PROGRA~1\COMMON~1\ofwm\ofwmm.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [SpywareBot] C:\Program Files\SpywareBot\SpywareBot.exe
O4 - Startup: RABCO - Auto Update.lnk = C:\Program Files\RABCO\RABCOse.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{34BF1BEB-7003-4BBC-8E7F-D9F08B63417B}: NameServer = 205.188.146.145
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe


Adobe Flash Player 9 ActiveX
Adobe Reader 7.0
AOL Coach Version 1.0(Build:20040229.1 en)
AOL Uninstaller (Choose which Products to Remove)
AOLIcon
avast! Antivirus
Babylon
Babylon Toolbar
BUM
CCleaner (remove only)
CCScore
Clifford Phonics
Dell Driver Reset Tool
Dell Photo AIO Printer 924
Dell Picture Studio v3.0
Dell Support Center
Dell System Restore
DellConnect
DellSupport
Dragon Tales
EarthLink setup files
ESPNMotion
ESSCDBK
ESScore
ESSgui
ESShelp
ESSini
ESSPCD
ESSSONIC
ESSTOOLS
ESSvpaht
ESSvpot
Get High Speed Internet!
Google Toolbar for Internet Explorer
High Definition Audio Driver Package - KB835221
Hijackthis 1.99.1
HijackThis 1.99.1
HLPIndex
HLPRFO
Intel® 537EP V9x DF PCI Modem
Intel® Graphics Media Accelerator Driver
Intel® PRO Network Connections Software v9.2.4.11
Intel® PROSafe for Wired Connections
Internet Explorer Default Page
Jasc Paint Shop Photo Album 5
Jasc Paint Shop Pro Studio, Dell Editon
Java 2 Runtime Environment, SE v1.4.2_03
KODAK EASYSHARE Gallery Easy Upload, v2.1
Kodak EasyShare software
KSU
Learn2 Player (Uninstall Only)
Macromedia Flash Player
Microsoft .NET Framework 1.0 Hotfix (KB887998)
Microsoft .NET Framework 1.0 Hotfix (KB930494)
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 Hotfix (KB928366)
Microsoft Digital Image Library 9 - Blocker
Microsoft Encarta Encyclopedia Standard 2005
Microsoft Money 2005
Microsoft Office Outlook 2003
Microsoft Picture It! Library 10
Microsoft Picture It! Premium 10
Microsoft Plus! Digital Media Edition Installer
Microsoft Plus! Photo Story 2 LE
Microsoft Streets and Trips 2005
Microsoft Word 2002
Microsoft Works
Microsoft Works 2005 Setup Launcher
Microsoft Works Suite Add-in for Microsoft Word
Modem Event Monitor
Modem Helper
Modem On Hold
MSN Messenger 7.5
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
Musicmatch for Windows Media Player
Musicmatch® Jukebox
MyWay Search Assistant
NetZeroInstallers
Notifier
OTtBPSDK
PCDADDIN
PCDHELP
PowerDVD 5.5
QuickBooks
QuickBooks Simple Start Special Edition
Quicken 2006
QuickTime
RABCO
RealPlayer
Router
Security Update for Step By Step Interactive Training (KB898458)
Security Update for Step By Step Interactive Training (KB923723)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 10 (KB917734)
Security Update for Windows Media Player 10 (KB936782)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows XP (KB883939)
Security Update for Windows XP (KB890046)
Security Update for Windows XP (KB893066)
Security Update for Windows XP (KB893756)
Security Update for Windows XP (KB896358)
Security Update for Windows XP (KB896422)
Security Update for Windows XP (KB896423)
Security Update for Windows XP (KB896424)
Security Update for Windows XP (KB896428)
Security Update for Windows XP (KB896688)
Security Update for Windows XP (KB899588)
Security Update for Windows XP (KB899589)
Security Update for Windows XP (KB899591)
Security Update for Windows XP (KB900725)
Security Update for Windows XP (KB901017)
Security Update for Windows XP (KB901214)
Security Update for Windows XP (KB902400)
Security Update for Windows XP (KB904706)
Security Update for Windows XP (KB905414)
Security Update for Windows XP (KB905749)
Security Update for Windows XP (KB905915)
Security Update for Windows XP (KB908519)
Security Update for Windows XP (KB908531)
Security Update for Windows XP (KB911280)
Security Update for Windows XP (KB911562)
Security Update for Windows XP (KB911567)
Security Update for Windows XP (KB911927)
Security Update for Windows XP (KB912812)
Security Update for Windows XP (KB912919)
Security Update for Windows XP (KB913446)
Security Update for Windows XP (KB913580)
Security Update for Windows XP (KB914388)
Security Update for Windows XP (KB914389)
Security Update for Windows XP (KB916281)
Security Update for Windows XP (KB917159)
Security Update for Windows XP (KB917344)
Security Update for Windows XP (KB917422)
Security Update for Windows XP (KB917953)
Security Update for Windows XP (KB918118)
Security Update for Windows XP (KB918439)
Security Update for Windows XP (KB918899)
Security Update for Windows XP (KB919007)
Security Update for Windows XP (KB920213)
Security Update for Windows XP (KB920214)
Security Update for Windows XP (KB920670)
Security Update for Windows XP (KB920683)
Security Update for Windows XP (KB920685)
Security Update for Windows XP (KB921398)
Security Update for Windows XP (KB921503)
Security Update for Windows XP (KB921883)
Security Update for Windows XP (KB922616)
Security Update for Windows XP (KB922760)
Security Update for Windows XP (KB922819)
Security Update for Windows XP (KB923191)
Security Update for Windows XP (KB923414)
Security Update for Windows XP (KB923689)
Security Update for Windows XP (KB923694)
Security Update for Windows XP (KB923980)
Security Update for Windows XP (KB924191)
Security Update for Windows XP (KB924270)
Security Update for Windows XP (KB924496)
Security Update for Windows XP (KB924667)
Security Update for Windows XP (KB925454)
Security Update for Windows XP (KB925486)
Security Update for Windows XP (KB925902)
Security Update for Windows XP (KB926255)
Security Update for Windows XP (KB926436)
Security Update for Windows XP (KB927779)
Security Update for Windows XP (KB927802)
Security Update for Windows XP (KB928090)
Security Update for Windows XP (KB928255)
Security Update for Windows XP (KB928843)
Security Update for Windows XP (KB929123)
Security Update for Windows XP (KB929969)
Security Update for Windows XP (KB930178)
Security Update for Windows XP (KB931261)
Security Update for Windows XP (KB931768)
Security Update for Windows XP (KB931784)
Security Update for Windows XP (KB932168)
Security Update for Windows XP (KB933566)
Security Update for Windows XP (KB933729)
Security Update for Windows XP (KB935839)
Security Update for Windows XP (KB935840)
Security Update for Windows XP (KB936021)
Security Update for Windows XP (KB937143)
Security Update for Windows XP (KB937894)
Security Update for Windows XP (KB938127)
Security Update for Windows XP (KB938829)
Security Update for Windows XP (KB939653)
Security Update for Windows XP (KB941202)
Security Update for Windows XP (KB941568)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB941644)
Security Update for Windows XP (KB942615)
Security Update for Windows XP (KB943055)
Security Update for Windows XP (KB943460)
Security Update for Windows XP (KB943485)
Security Update for Windows XP (KB944533)
Security Update for Windows XP (KB944653)
Security Update for Windows XP (KB946026)
SFR
SHASTA
Shockwave
SKIN0001
SKINXSDK
Sonic DLA
Sonic Encoders
Sonic MyDVD LE
Sonic RecordNow Audio
Sonic RecordNow Copy
Sonic RecordNow Data
Sonic Update Manager
SpywareBot
Update for Windows XP (KB894391)
Update for Windows XP (KB896727)
Update for Windows XP (KB898461)
Update for Windows XP (KB900485)
Update for Windows XP (KB910437)
Update for Windows XP (KB916595)
Update for Windows XP (KB920872)
Update for Windows XP (KB922582)
Update for Windows XP (KB927891)
Update for Windows XP (KB929338)
Update for Windows XP (KB930916)
Update for Windows XP (KB931836)
Update for Windows XP (KB933360)
Update for Windows XP (KB936357)
Update for Windows XP (KB938828)
Update for Windows XP (KB942763)
Update for Windows XP (KB942840)
Update for Windows XP (KB946627)
Update Rollup 1 for Windows XP Media Center Edition 2005 with HDTV Support (KB873369)
Virtools 3D Life Player
VPRINTOL
WebCyberCoach 3.2 Dell
WebFldrs XP
Windows Genuine Advantage Notifications (KB905474)
Windows Installer 3.1 (KB893803)
Windows Media Player 10
Windows XP Hotfix - KB873333
Windows XP Hotfix - KB873339
Windows XP Hotfix - KB885250
Windows XP Hotfix - KB885354
Windows XP Hotfix - KB885835
Windows XP Hotfix - KB885884
Windows XP Hotfix - KB886185
Windows XP Hotfix - KB887472
Windows XP Hotfix - KB887742
Windows XP Hotfix - KB888113
Windows XP Hotfix - KB888302
Windows XP Hotfix - KB888310
Windows XP Hotfix - KB890175
Windows XP Hotfix - KB890859
Windows XP Hotfix - KB891781
Windows XP Hotfix - KB893086
Windows XP Media Center Edition 2005 KB895198
WinTouch
WIRELESS
Works Upgrade
Yahoo! Install Manager
Yahoo! Toolbar for Internet Explorer
Hi :)

That wasn't the log from Combofix I required… Have you followed the instructions on the webpage I linked to?

If so, please post the contents of this file: C:\Combofix.txt.
Sorry…

ComboFix 08-02-24.2 - Donald Scanlon 2008-02-24 8:38:51.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.598 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Documents and Settings\Donald Scanlon\My Documents\YSTEM3~1
C:\Documents and Settings\Donald Scanlon\My Documents\YSTEM3~1\?ystem32\
C:\Documents and Settings\Donald Scanlon\Start Menu\Programs\Outerinfo
C:\Documents and Settings\Donald Scanlon\Start Menu\Programs\Outerinfo\Terms.lnk
C:\Documents and Settings\Donald Scanlon\Start Menu\Programs\Outerinfo\Uninstall.lnk
C:\Documents and Settings\LocalService\Application Data\NetMon
C:\Documents and Settings\LocalService\Application Data\NetMon\domains.txt
C:\Documents and Settings\LocalService\Application Data\NetMon\log.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon
C:\Documents and Settings\NetworkService\Application Data\NetMon\domains.txt
C:\Documents and Settings\NetworkService\Application Data\NetMon\log.txt
C:\Program Files\Common Files\Yazzle1281OinAdmin.exe
C:\Program Files\Movie Maker\zyqoludi.html
C:\Program Files\Router
C:\Program Files\sks~1
C:\Program Files\sks~1\?hkdsk.exe
C:\Program Files\Temporary
C:\Program Files\Temporary\InsiDERIns.exe
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\fse
C:\Temp\isgTi19
C:\Temp\isgTi19\lPig.log
C:\WINDOWS\b116.exe
C:\WINDOWS\b153.exe
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\UGA6P_0001_N122M0611NetInstaller.exe
C:\WINDOWS\system32\a1
C:\WINDOWS\system32\aeugvlpc.dll
C:\WINDOWS\system32\bpqifqwc.dll
C:\WINDOWS\system32\bszip.dll
C:\WINDOWS\system32\drfrpgjv.dll
C:\WINDOWS\system32\eebpnyas.ini
C:\WINDOWS\system32\f02WtR
C:\WINDOWS\system32\hckxglsm.ini
C:\WINDOWS\system32\hkyithsy.dll
C:\WINDOWS\system32\iifcbaw.dll
C:\WINDOWS\system32\ixfvriix.dll
C:\WINDOWS\system32\juxriipr.ini
C:\WINDOWS\system32\kjeluglw.dll
C:\WINDOWS\system32\nGpxx01
C:\WINDOWS\system32\nGpxx01\nGpxx011065.exe
C:\WINDOWS\system32\nqstv.ini
C:\WINDOWS\system32\nqstv.ini2
C:\WINDOWS\system32\onnmp.ini
C:\WINDOWS\system32\onnmp.ini2
C:\WINDOWS\system32\ossmkmx.dll
C:\WINDOWS\system32\p9
C:\WINDOWS\system32\p9\liopud89104.exe
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\packet.dll
C:\WINDOWS\system32\patyqkvw.ini
C:\WINDOWS\system32\pkivrpjp.ini
C:\WINDOWS\system32\qakjeigc.dllbox
C:\WINDOWS\system32\qracmoiq.dll
C:\WINDOWS\system32\rpiirxuj.dll
C:\WINDOWS\system32\rrutv.ini
C:\WINDOWS\system32\rrutv.ini2
C:\WINDOWS\system32\tuvwtus.dll
C:\WINDOWS\system32\v6
C:\WINDOWS\system32\vaatkrpr.dll
C:\WINDOWS\system32\vlsgjpmm.dll
C:\WINDOWS\system32\vtsqn.dll
C:\WINDOWS\system32\w11
C:\WINDOWS\system32\w11\hiba3133.exe
C:\WINDOWS\system32\wayambgr.ini
C:\WINDOWS\system32\whovaqhf.dll
C:\WINDOWS\system32\windows
C:\WINDOWS\system32\wmvrcaow.dll
C:\WINDOWS\system32\wpcap.dll
C:\WINDOWS\system32\yotxjksx.dll

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))

.
——-\LEGACY_CMDSERVICE
——-\LEGACY_NETWORK_MONITOR
——-\NPF


((((((((((((((((((((((((( Files Created from 2008-01-24 to 2008-02-24 )))))))))))))))))))))))))))))))
.

2008-02-24 08:35 . 2008-02-24 08:35 d——– C:\Program Files\Viewpoint
2008-02-24 08:35 . 2008-02-24 08:35 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-23 07:54 . 2008-02-23 07:54 d——– C:\Program Files\CCleaner
2008-02-22 11:26 . 2008-02-23 07:52 2,190,930 –ahs—- C:\WINDOWS\system32\ccbauedf.ini
2008-02-22 08:26 . 2008-02-24 08:32 70,824 –a—— C:\WINDOWS\BM036314aa.xml
2008-02-22 08:26 . 2008-02-24 08:35 22 –a—— C:\WINDOWS\pskt.ini
2008-02-21 08:29 . 2008-02-22 08:03 2,202,367 –ahs—- C:\WINDOWS\system32\spippxqh.ini
2008-02-19 16:14 . 2008-02-19 16:14 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-02-19 16:13 . 2008-02-19 16:14 d——– C:\Program Files\Dell Support Center
2008-02-19 16:13 . 2008-02-19 16:13 d——– C:\Program Files\Common Files\supportsoft
2008-02-19 00:23 . 2008-02-19 00:23 9,662 –a—— C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-02-18 18:37 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-02-18 18:37 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-18 18:37 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-18 18:37 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-18 18:36 . 2008-02-18 18:36 d——– C:\Program Files\Alwil Software
2008-02-18 18:36 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-02-18 18:36 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-02-18 18:36 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-18 18:36 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-18 18:19 . 2008-02-18 18:19 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-02-18 18:19 . 2008-02-06 11:45 19,696 –a—— C:\WINDOWS\system32\drivers\spywarebot.sys
2008-02-18 16:49 . 2008-02-22 03:00 d——– C:\Program Files\SpywareBot
2008-02-18 16:49 . 2008-02-22 03:00 d——– C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot
2008-02-18 16:42 . 2008-02-18 16:42 d——– C:\WINDOWS\system32\NtmsData
2008-02-18 05:04 . 2008-02-18 05:05 d——– C:\WINDOWS\ofwm
2008-02-18 05:04 . 2008-02-18 18:48 d——– C:\Program Files\Common Files\ofwm
2008-02-16 11:39 . 2008-02-16 11:39 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-16 11:36 . 2008-02-18 19:05 d–hs—- C:\WINDOWS\RG9uYWxkIFNjYW5sb24
2008-02-16 11:36 . 2008-02-16 11:38 d——– C:\Program Files\RABCO
2008-01-28 08:42 . 2008-02-19 16:17 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-23 13:16 ——— d—–w C:\Program Files\Dl_cats
2008-02-20 14:00 812,344 —-a-w C:\Program Files\HJTInstall
2008-02-19 23:14 ——— d—–w C:\Program Files\GemMaster
2008-02-19 18:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-15 15:45 20,800 —-a-w C:\Documents and Settings\Donald Scanlon\Application Data\wklnhst.dat
2008-01-09 23:10 ——— d—–w C:\Documents and Settings\Donald Scanlon\Application Data\Babylon
2008-01-09 02:13 ——— d—–w C:\Program Files\Babylon
2007-12-27 01:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-07 14:37 3,059,200 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 13:07 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ——w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-04-20 02:54 75,200 —-a-w C:\Documents and Settings\Donald Scanlon\Application Data\GDIPFONTCACHEV1.DAT
.

——- Sigcheck ——-

"C:\WINDOWS\system32\svchost.exe"
—-a-w 14,336 2004-08-10 10:00:00 C:\WINDOWS\system32\svchost.exe

"C:\WINDOWS\system32\ws2_32.dll"
—-a-w 82,944 2004-08-10 10:00:00 C:\WINDOWS\system32\ws2_32.dll

"C:\WINDOWS\system32\winlogon.exe"
—-a-w 502,272 2004-08-10 10:00:00 C:\WINDOWS\system32\winlogon.exe

"C:\WINDOWS\system32\drivers\ndis.sys"
—-a-w 182,912 2004-08-10 10:00:00 C:\WINDOWS\system32\drivers\ndis.sys

"C:\WINDOWS\system32\drivers\ip6fw.sys"
—-a-w 29,056 2004-08-10 10:00:00 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C2E5D27-A17C-4D89-85DD-3553C189380D}]
2008-01-30 14:02 414992 –a—— C:\Program Files\RABCO\RABCO.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E318F07-66B7-4BAE-BD71-DD272CC18AAF}]
C:\Program Files\MSN Gaming Zone\wybyjini89104.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{267C3A0E-E472-4541-BCD5-779D33707A88}]
C:\WINDOWS\system32\pmnno.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3465CE95-5B75-4E95-0662-5A00CCC78996}]
C:\WINDOWS\system32\ptymtlf.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{587E60A8-4852-4476-A68B-B255D5D1E5F9}]
C:\WINDOWS\system32\vturr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2037DAD-0A95-42C6-109B-4642C86CC14F}]
C:\Program Files\Movie Maker\vihiwyky.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{965B54B0-71E0-4611-8DE7-F73FA0B20E26}

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]
[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 14:42 267488]

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]
[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 17:18 68856]
"Uaol"="C:\DOCUME~1\DONALD~1\MYDOCU~1\YSTEM3~1\explorer.exe" [ ]
"Dogr"="C:\Program Files\??sks\?hkdsk.exe" [ ]
"ofwm"="C:\PROGRA~1\COMMON~1\ofwm\ofwmm.exe" [ ]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-06 02:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-06 02:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-06 02:23 114688]
"SunJavaUpdateSched"="C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 17:48 32881]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 00:20 339968 C:\WINDOWS\stsystra.exe]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 20:12 221184]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19 53248]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2004-09-14 08:50 131072]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 08:50 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-26 19:39 98304]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"HostManager"="C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-20 13:36 185896]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-12-18 14:42 3116768]
"rydo"="C:\Program Files\Messenger\rydo77798.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 13:38 69632]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 17:18 68856]

C:\Documents and Settings\Donald Scanlon\Start Menu\Programs\Startup\
RABCO - Auto Update.lnk - C:\Program Files\RABCO\RABCOse.exe [2008-02-16 11:36:26 183216]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-09-26 19:38:48 156784]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 14:04:48 176128]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08 16423]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36 806912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qakjeigc]
qakjeigc.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Common Files\\AOL\\1168439324\\ee\\aolsoftware.exe"=

R0 spywarebot;spywarebot;C:\WINDOWS\system32\DRIVERS\spywarebot.sys [2008-02-06 11:45]
R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 15:12]

.
Contents of the 'Scheduled Tasks' folder
"2008-02-24 13:31:19 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.ex
- C:\Program Files\SpywareBot
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-24 08:45:54
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jucheck.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\RABCO\X_RABCOse.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-02-24 8:47:37 - machine was rebooted
ComboFix-quarantined-files.txt 2008-02-24 13:47:33
.
2008-02-14 08:02:01 — E O F —
Hi :)

Step 1

Click on Start, then Control Panel. Double click on Add or Remove Programs.

Please remove the following program(s):

Java 2 Runtime Environment, SE v1.4.2_03
MyWay Search Assistant
RABCO
SpywareBot
WinTouch


Then download and install Java Runtime Environment (JRE) 6 Update 4.

Step 2

Open Notepad (Go to Start > Run, type Notepad and hit Enter), and copy/paste the text in the quotebox below into it:

File::

C:\WINDOWS\system32\ccbauedf.ini
C:\WINDOWS\BM036314aa.xml
C:\WINDOWS\pskt.ini
C:\WINDOWS\system32\spippxqh.ini
C:\WINDOWS\system32\DRIVERS\spywarebot.sys

Folder::

C:\Program Files\RABCO
C:\Program Files\SpywareBot

Registry::

[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1C2E5D27-A17C-4D89-85DD-3553C189380D}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E318F07-66B7-4BAE-BD71-DD272CC18AAF}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{267C3A0E-E472-4541-BCD5-779D33707A88}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3465CE95-5B75-4E95-0662-5A00CCC78996}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{587E60A8-4852-4476-A68B-B255D5D1E5F9}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2037DAD-0A95-42C6-109B-4642C86CC14F}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Uaol"=-
"Dogr"=-
"ofwm"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"rydo"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qakjeigc]

Driver::

spywarebot

Click on File > Save as….

In the File Name box, copy/paste CFScript.txt (Note: Do not change the filename!)

Click Save (Save the CFScript in the same location as Combofix.exe)

Close any open windows.

Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix.

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe.
It will create a log. Be sure to save it to a convenient location.

Step 3

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • You can also access the log by doing the following:

  • Click on the Malwarebytes' Anti-Malware icon to launch the program.
  • Click on the Logs tab.
  • Click on the log at the bottom of those listed to highlight it.
  • Click Open.

Step 4

In your next reply, please post:

  • the Combofix log (C:\Combofix.txt)
  • the Malwarebytes' Anti-Malware log
  • a new HijackThis log
Removed the programs copied the notepad info Could not download the JRE 6 update 4 Got this message: Your download transaction cannot be approved. Contact Customer Service. Any suggestions?

Could not download the JRE 6 update 4
Got this message:
Your download transaction cannot be approved. Contact Customer Service.

Any suggestions?

I suggest you try again in a few days, I think it's a temporary problem.
Yes, I just got back to the computer and got the JRE downloaded. I will follow the other instructions and get back to you with the results shortly.
Will send the three logs separately.
Combo Fix Log:

ComboFix 08-02-24.2 - Donald Scanlon 2008-02-27 15:22:22.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.560 [GMT -5:00]
Running from: C:\Documents and Settings\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\WINDOWS\Prefetch\CFScript.txt
* Created a new restore point
.

((((((((((((((((((((((((( Files Created from 2008-01-27 to 2008-02-27 )))))))))))))))))))))))))))))))
.

2008-02-27 15:21 . 2007-12-14 01:59 69,632 –a—— C:\WINDOWS\system32\javacpl.cpl
2008-02-27 15:20 . 2008-02-27 15:21 d——– C:\Program Files\Java
2008-02-27 15:20 . 2008-02-27 15:20 d——– C:\Program Files\Common Files\Java
2008-02-24 08:35 . 2008-02-24 08:35 d——– C:\Program Files\Viewpoint
2008-02-24 08:35 . 2008-02-24 08:35 d——– C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-02-23 07:54 . 2008-02-23 07:54 d——– C:\Program Files\CCleaner
2008-02-22 11:26 . 2008-02-23 07:52 2,190,930 –ahs—- C:\WINDOWS\system32\ccbauedf.ini
2008-02-22 08:26 . 2008-02-24 08:32 70,824 –a—— C:\WINDOWS\BM036314aa.xml
2008-02-22 08:26 . 2008-02-24 08:35 22 –a—— C:\WINDOWS\pskt.ini
2008-02-21 08:29 . 2008-02-22 08:03 2,202,367 –ahs—- C:\WINDOWS\system32\spippxqh.ini
2008-02-19 16:14 . 2008-02-19 16:14 d——– C:\Documents and Settings\All Users\Application Data\SupportSoft
2008-02-19 16:13 . 2008-02-19 16:14 d——– C:\Program Files\Dell Support Center
2008-02-19 16:13 . 2008-02-19 16:13 d——– C:\Program Files\Common Files\supportsoft
2008-02-19 00:23 . 2008-02-19 00:23 9,662 –a—— C:\WINDOWS\system32\ZoneAlarmIconUS.ico
2008-02-18 18:37 . 2007-12-04 07:54 95,608 –a—— C:\WINDOWS\system32\AvastSS.scr
2008-02-18 18:37 . 2007-12-04 09:51 42,912 –a—— C:\WINDOWS\system32\drivers\aswTdi.sys
2008-02-18 18:37 . 2007-12-04 09:49 26,624 –a—— C:\WINDOWS\system32\drivers\aavmker4.sys
2008-02-18 18:37 . 2007-12-04 09:53 23,152 –a—— C:\WINDOWS\system32\drivers\aswRdr.sys
2008-02-18 18:36 . 2008-02-18 18:36 d——– C:\Program Files\Alwil Software
2008-02-18 18:36 . 2007-12-04 08:04 837,496 –a—— C:\WINDOWS\system32\aswBoot.exe
2008-02-18 18:36 . 2004-01-09 04:13 380,928 –a—— C:\WINDOWS\system32\actskin4.ocx
2008-02-18 18:36 . 2007-12-04 09:55 94,544 –a—— C:\WINDOWS\system32\drivers\aswmon2.sys
2008-02-18 18:36 . 2007-12-04 09:56 93,264 –a—— C:\WINDOWS\system32\drivers\aswmon.sys
2008-02-18 18:19 . 2008-02-24 09:24 d—-c— C:\WINDOWS\system32\DRVSTORE
2008-02-18 18:19 . 2008-02-06 11:45 19,696 –a—— C:\WINDOWS\system32\drivers\spywarebot.sys
2008-02-18 16:49 . 2008-02-22 03:00 d——– C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot
2008-02-18 16:42 . 2008-02-18 16:42 d——– C:\WINDOWS\system32\NtmsData
2008-02-18 05:04 . 2008-02-18 05:05 d——– C:\WINDOWS\ofwm
2008-02-18 05:04 . 2008-02-18 18:48 d——– C:\Program Files\Common Files\ofwm
2008-02-16 11:39 . 2008-02-16 11:39 d——– C:\Documents and Settings\All Users\Application Data\Rabio
2008-02-16 11:36 . 2008-02-18 19:05 d–hs—- C:\WINDOWS\RG9uYWxkIFNjYW5sb24
2008-01-28 08:42 . 2008-02-19 16:17 d——– C:\Documents and Settings\All Users\Application Data\Dell

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-27 01:37 ——— d—–w C:\Program Files\Dl_cats
2008-02-20 14:00 812,344 —-a-w C:\Program Files\HJTInstall
2008-02-19 23:14 ——— d—–w C:\Program Files\GemMaster
2008-02-19 18:49 ——— d—–w C:\Documents and Settings\All Users\Application Data\Babylon
2008-02-15 15:45 20,800 —-a-w C:\Documents and Settings\Donald Scanlon\Application Data\wklnhst.dat
2008-01-09 23:10 ——— d—–w C:\Documents and Settings\Donald Scanlon\Application Data\Babylon
2008-01-09 02:13 ——— d—–w C:\Program Files\Babylon
2007-12-27 01:06 ——— d—–w C:\Documents and Settings\All Users\Application Data\Kodak
2007-12-18 09:51 179,584 ——w C:\WINDOWS\system32\dllcache\mrxdav.sys
2007-12-07 14:37 3,059,200 ——w C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 13:07 18,432 ——w C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-04 18:38 550,912 —-a-w C:\WINDOWS\system32\oleaut32.dll
2007-12-04 18:38 550,912 ——w C:\WINDOWS\system32\dllcache\oleaut32.dll
2007-04-20 02:54 75,200 —-a-w C:\Documents and Settings\Donald Scanlon\Application Data\GDIPFONTCACHEV1.DAT
.

——- Sigcheck ——-

"C:\WINDOWS\system32\svchost.exe"
—-a-w 14,336 2004-08-10 10:00:00 C:\WINDOWS\system32\svchost.exe

"C:\WINDOWS\system32\ws2_32.dll"
—-a-w 82,944 2004-08-10 10:00:00 C:\WINDOWS\system32\ws2_32.dll

"C:\WINDOWS\system32\winlogon.exe"
—-a-w 502,272 2004-08-10 10:00:00 C:\WINDOWS\system32\winlogon.exe

"C:\WINDOWS\system32\drivers\ndis.sys"
—-a-w 182,912 2004-08-10 10:00:00 C:\WINDOWS\system32\drivers\ndis.sys

"C:\WINDOWS\system32\drivers\ip6fw.sys"
—-a-w 29,056 2004-08-10 10:00:00 C:\WINDOWS\system32\drivers\ip6fw.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{1E318F07-66B7-4BAE-BD71-DD272CC18AAF}]
C:\Program Files\MSN Gaming Zone\wybyjini89104.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{267C3A0E-E472-4541-BCD5-779D33707A88}]
C:\WINDOWS\system32\pmnno.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3465CE95-5B75-4E95-0662-5A00CCC78996}]
C:\WINDOWS\system32\ptymtlf.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{587E60A8-4852-4476-A68B-B255D5D1E5F9}]
C:\WINDOWS\system32\vturr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E2037DAD-0A95-42C6-109B-4642C86CC14F}]
C:\Program Files\Movie Maker\vihiwyky.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88}
{0BF43445-2F28-4351-9252-17FE6E806AA0}
{2318C2B1-4965-11D4-9B18-009027A5CD4F}
{965B54B0-71E0-4611-8DE7-F73FA0B20E26}

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]
[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
"{965B54B0-71E0-4611-8DE7-F73FA0B20E26}"= C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll [2007-12-18 14:42 267488]

[HKEY_CLASSES_ROOT\clsid\{965b54b0-71e0-4611-8de7-f73fa0b20e26}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB.1]
[HKEY_CLASSES_ROOT\TypeLib\{162484B8-B114-453f-A344-C0B24B0F1D99}]
[HKEY_CLASSES_ROOT\BabylonTBLib.BabylonTB]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 11:24 1694208]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2007-03-15 10:09 460784]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 17:18 68856]
"Uaol"="C:\DOCUME~1\DONALD~1\MYDOCU~1\YSTEM3~1\explorer.exe" [ ]
"Dogr"="C:\Program Files\??sks\?hkdsk.exe" [ ]
"ofwm"="C:\PROGRA~1\COMMON~1\ofwm\ofwmm.exe" [ ]
"DellSupportCenter"="C:\Program Files\Dell Support Center\bin\sprtcmd.exe" [2007-11-15 09:23 202544]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2004-08-10 04:04 59392]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-04-06 02:22 94208]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-04-06 02:19 77824]
"Persistence"="C:\WINDOWS\system32\igfxpers.exe" [2005-04-06 02:23 114688]
"SigmatelSysTrayApp"="stsystra.exe" [2005-03-23 00:20 339968 C:\WINDOWS\stsystra.exe]
"IntelMeM"="C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 20:12 221184]
"DVDLauncher"="C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" [2005-02-23 16:19 53248]
"MMTray"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [2004-09-14 08:50 131072]
"mmtask"="C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe" [2004-09-14 08:50 53248]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2005-09-26 19:39 98304]
"ISUSPM Startup"="C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-07-27 16:50 221184]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2004-07-27 16:50 81920]
"dla"="C:\WINDOWS\system32\dla\tfswctrl.exe" [2005-05-31 05:33 122941]
"AOLDialer"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 07:50 71216]
"HostManager"="C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe" [2006-09-25 19:52 50736]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2007-06-20 13:36 185896]
"Babylon Client"="C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" [2007-12-18 14:42 3116768]
"rydo"="C:\Program Files\Messenger\rydo77798.exe" [ ]
"avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2007-12-04 08:00 79224]
"dscactivate"="C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" [2007-11-15 09:24 16384]
"DLCCCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll" [2005-06-07 13:38 69632]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe" [2007-12-14 03:42 144784]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-25 17:18 68856]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2004-12-14 03:44:06 29696]
America Online 9.0 Tray Icon.lnk - C:\Program Files\America Online 9.0\aoltray.exe [2005-09-26 19:38:48 156784]
Kodak EasyShare software.lnk - C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2005-11-04 14:04:48 176128]
KODAK Software Updater.lnk - C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-02-13 13:12:08 16423]
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2004-11-11 11:59:36 806912]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\qakjeigc]
qakjeigc.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\America Online 9.0\\waol.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"C:\\Program Files\\Common Files\\AOL\\ACS\\AOLAcsd.exe"=
"C:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE"=
"C:\\Program Files\\Kodak\\KODAK Software Updater\\7288971\\Program\\Kodak Software Updater.exe"=
"C:\\Program Files\\Kodak\\Kodak EasyShare software\\bin\\EasyShare.exe"=
"C:\\Program Files\\Common Files\\AOL\\1168439324\\ee\\aolsoftware.exe"=

R2 sprtsvc_dellsupportcenter;SupportSoft Sprocket Service (dellsupportcenter);C:\Program Files\Dell Support Center\bin\sprtsvc.exe /service []
R4 spywarebot;spywarebot;C:\WINDOWS\system32\DRIVERS\spywarebot.sys [2008-02-06 11:45]
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2004-11-02 15:12]

*Newly Created Service* - APPMGMT
.
Contents of the 'Scheduled Tasks' folder
"2008-02-27 08:00:00 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job"
- C:\Program Files\SpywareBot\SpywareBot.ex
- C:\Program Files\SpywareBot
.
**************************************************************************

catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-02-27 15:23:43
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
Completion time: 2008-02-27 15:24:25
ComboFix-quarantined-files.txt 2008-02-27 20:24:23
ComboFix2.txt 2008-02-24 13:47:37
.
2008-02-14 08:02:01 — E O F —
My Malware file is too large. I will try to upload it in sections. Section 1: Malwarebytes' Anti-Malware 1.05 Database version: 416 Scan type: Quick Scan Objects scanned: 26566 Time elapsed: 1 hour(s), 38 minute(s), 56 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 5 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 126 Files Infected: 3939 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\SpywareBot (Rogue.SpywareBot) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Log (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Settings (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-29-10 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-44-51 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-48-13 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\19-02-2008-08-08-25 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18 (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\11.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\12.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\138.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\156.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\178.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\202.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\225.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\227.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\228.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\229.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\231.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\233.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\234.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\235.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\236.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\264.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\265.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\266.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\272.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\276.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\277.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\278.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\279.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\419.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\484.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\486.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\488.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\586.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\588.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\590.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\593.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\595.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\596.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\597.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\685.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\687.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-29-10\31.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\101.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\102.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\105.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\63.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\64.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\66.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\67.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\69.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\71.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\73.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\74.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\75.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-43-58\76.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-48-13\0.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-20-48-13\1.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\46.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\48.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\51.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\53.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\55.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\57.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\59.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\60.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\61.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\62.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\87.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\88.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\20-02-2008-08-43-09\91.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\46.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\48.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\51.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\53.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\55.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\57.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\59.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\60.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\61.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\62.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\87.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\88.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-07-05-41\91.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\10.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\11.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\12.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\13.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\14.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\3.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\5.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\7.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\22-02-2008-08-02-23\9.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\27.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\29.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\30.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\31.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\32.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\36.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\37.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\23-02-2008-07-51-49\61.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\48.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\50.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\53.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\55.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\57.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\59.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\61.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\62.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\63.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\64.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\88.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\89.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\92.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\95.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\24-02-2008-08-34-18\96.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Rabio\Search Enhancer (Adware.SearchEnhancer) -> Quarantined and deleted successfully.
Section 2: (This goes on forever!!!!) Please let me know if you need the entire list of infected files… Files Infected: C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\rs.dat (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Log\2008 Feb 24 - 08_31_09 AM_171.log (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\0.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\1.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\10.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\10.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\100.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\100.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\101.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\101.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\102.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\102.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\103.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\103.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\104.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\104.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\105.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\105.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\106.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\106.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\107.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\107.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\108.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\108.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\109.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\109.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\11.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\110.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\110.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\111.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\111.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\112.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\112.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\113.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\113.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\114.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\114.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\115.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\115.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\116.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\116.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\117.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\117.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\118.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\118.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\119.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\119.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\12.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\120.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\120.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\121.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\121.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\122.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\122.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\123.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\123.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\124.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\124.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\125.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\125.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\126.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\126.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\127.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\127.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\128.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\128.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\129.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\129.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\13.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\13.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\130.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\130.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\131.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\131.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\132.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\132.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\133.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\133.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\134.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\135.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\135.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\136.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\136.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\137.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\137.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\138.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\139.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\139.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\14.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\14.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\140.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\140.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\141.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\141.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\142.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\142.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\143.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\143.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\144.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\144.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\145.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\145.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\146.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\146.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\147.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\147.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\148.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\148.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\149.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\149.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\15.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\15.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\150.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\150.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\151.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\151.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\152.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\152.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\153.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\153.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\154.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\154.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\155.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\155.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\156.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\157.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\157.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\158.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\158.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\159.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\159.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\16.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\16.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\160.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\160.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\161.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\161.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\162.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\162.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\163.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\163.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\164.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\164.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\165.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\165.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\166.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\166.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\167.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\167.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\168.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\168.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\169.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\169.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\17.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\17.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\170.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\170.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\171.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\171.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\172.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\172.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\173.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\173.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\174.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\174.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\175.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\175.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\176.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\176.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\177.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\177.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\178.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\179.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\179.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\18.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\18.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\180.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\180.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\181.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\181.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\182.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\182.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\183.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\183.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\184.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\184.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\185.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\185.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\186.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\186.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\187.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\187.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\188.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\188.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\189.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\189.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\19.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\19.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\190.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\190.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\191.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\191.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\192.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\192.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\193.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\193.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\194.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\194.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\195.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\195.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\196.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\196.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\197.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\197.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\198.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\198.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\199.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\199.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\2.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\20.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\20.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\200.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\200.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\201.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\201.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\202.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\203.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\203.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\204.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\204.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\205.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\205.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\206.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\206.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\207.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\207.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\208.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\208.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\209.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\209.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\21.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\21.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\210.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\210.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\211.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\211.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\212.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\212.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\213.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\213.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\214.qit (Rogue.SpywareBot) -> Quarantined and deleted successfully. C:\Documents and Settings\Donald Scanlon\Application Data\SpywareBot\Quarantine\18-02-2008-18-25-07\214.qnf (Rogue.SpywareBot) -> Quarantined and deleted successfully.
The Latest Hijack this log:

Logfile of HijackThis v1.99.1
Scan saved at 7:39:33 PM, on 2/27/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\dlcccoms.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
c:\progra~1\common~1\instal~1\update~1\isuspm.exe
C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Common Files\Aol\aoltpspd.exe
C:\Program Files\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.earthlink.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E318F07-66B7-4BAE-BD71-DD272CC18AAF} - C:\Program Files\MSN Gaming Zone\wybyjini89104.dll (file missing)
O2 - BHO: (no name) - {267C3A0E-E472-4541-BCD5-779D33707A88} - C:\WINDOWS\system32\pmnno.dll (file missing)
O2 - BHO: (no name) - {3465CE95-5B75-4E95-0662-5A00CCC78996} - C:\WINDOWS\system32\ptymtlf.dll (file missing)
O2 - BHO: (no name) - {587E60A8-4852-4476-A68B-B255D5D1E5F9} - C:\WINDOWS\system32\vturr.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.1121.2472\swg.dll
O2 - BHO: 0 - {E2037DAD-0A95-42C6-109B-4642C86CC14F} - C:\Program Files\Movie Maker\vihiwyky.dll (file missing)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: Babylon - {965B54B0-71E0-4611-8DE7-F73FA0B20E26} - C:\Program Files\Babylon\Babylon Toolbar\BabylonIEToolBar.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [MMTray] C:\Program Files\Musicmatch\Musicmatch Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [mmtask] C:\Program Files\Musicmatch\Musicmatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1168439324\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Babylon Client] C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart
O4 - HKLM\..\Run: [rydo] C:\Program Files\Messenger\rydo77798.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [DLCCCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCCtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_04\bin\jusched.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [Uaol] "C:\DOCUME~1\DONALD~1\MYDOCU~1\YSTEM3~1\explorer.exe" -vt ndrv
O4 - HKCU\..\Run: [Dogr] "C:\Program Files\??sks\?hkdsk.exe"
O4 - HKCU\..\Run: [ofwm] C:\PROGRA~1\COMMON~1\ofwm\ofwmm.exe
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: Kodak EasyShare software.lnk = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe
O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O8 - Extra context menu item: Translate with &Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Translate.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_04\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photos.walmart.com/WalmartActivia.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/m…99/mcinsctl.cab
O16 - DPF: {A8683C98-5341-421B-B23C-8514C05354F1} (FujifilmUploader Class) - http://photo.walmart.com/photo/uploads/Fuj…ploadClient.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m…,26/mcgdmgr.cab
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} (Virtools WebPlayer Class) - http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{34BF1BEB-7003-4BBC-8E7F-D9F08B63417B}: NameServer = 205.188.146.145
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O20 - Winlogon Notify: qakjeigc - qakjeigc.dll (file missing)
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\PROGRA~1\COMMON~1\AOL\ACS\AOLacsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: dlcc_device - Unknown owner - C:\WINDOWS\system32\dlcccoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Kodak Camera Connection Software (KodakCCS) - Unknown owner - C:\WINDOWS\system32\drivers\KodakCCS.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI