
UNSOLVED
AVG Resident virus popups
:smileymad:
I have had this particular problem since the first part of Oct.(2004). Everytime I log on and go to homepage, I immediately receive virus popups from AVG Resident Shield such as: AE Collect? and Win32/Parite.It says to run AVG which I do and it either heals the virus or I move it to virus vault. Unfortunately, within maybe 10 minutes or so the same popup comes up again immediately after I just ran the AVG virus scan. Why do the viruses keep coming up so many times while online? Any help with this would be much appreciated.
Thanks in advance~
Responses (44)
Solutions (0)
- Mike..I was amazed at how many more files the "trendmicro" scanned. Only found one virus and I am so mad at myself because I didn't write down or clik to see info about the virus. I do appreciate so much your help!! Think I'll be uninstalling AVG, because it obviously isn't catching everything!Hopefully this took care of things.Again, thanks so much...
Reply Midnight Star
4791 Posts
885
0
Posted December 10th, 2004 17:00
ATIR,Your more than welcome, but we need to look more closely - there could be other 'problems' lurking about still.Download HiJackThis, unzip it, then click " Scan", then " Save log" (same button). When Notepad comes up with a log for your computer, select all the text, and copy/paste it back to this thread. We'll use that to see if there's more; it's best to be safe. Don't try to 'fix' anything with it just yet, as most of what it will report is 'good'. Close both Notepad and HijackThis.AVG, Norton's and Symantec among just a few, usually do miss something that the other one will pick up. There's still a few more programs that we might need to download, but first, let's take a look at your system log.Mike.Reply Logfile of HijackThis v1.98.2
Scan saved at 9:07:38 PM, on 12/10/2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG6\avgserv.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe
C:\Program Files\Lexmark X74-X75\lxbbbmon.exe
C:\Documents and Settings\Rita\My Documents\My Music\iTunesHelper.exe
C:\WINDOWS\System32\hkcmd.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Grisoft\AVG6\avgcc32.exe
C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe
C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
C:\snd.exe
C:\Program Files\Windows AdControl\WinAdCtl.exe
C:\Program Files\Windows AdControl\WinAdAlt.exe
C:\windows\system32\rk.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\WinMX\WinMX.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Exif Launcher\QuickDCF.exe
C:\Program Files\CallWave\IAM.exe
C:\Program Files\Web_Rebates\WebRebates1.exe
C:\Program Files\EarthLink TotalAccess\FastLane\IPClient.exe
C:\Program Files\EarthLink TotalAccess\Accelerator\ElinkAcc.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Web_Rebates\WebRebates0.exe
C:\DOCUME~1\Rita\LOCALS~1\Temp\Temporary Directory 1 for hijackthis[1].zip\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://start.earthlink.net/AL/Search
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://start.earthlink.net/AL/Search
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8080
R3 - URLSearchHook: SrchHook Class - {44F9B173-041C-4825-A9B9-D914BD9DCBB3} - C:\Program Files\EarthLink TotalAccess\ElnIE.dll
R3 - URLSearchHook: (no name) - ~CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - ~00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\6.bin\MWSSRCAS.DLL
O2 - BHO: My Search BHO - {014DA6C1-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\6.bin\MWSBAR.DLL
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\System32\nvms.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\System32\mscb.dll
O2 - BHO: (no name) - {EA78DBF8-C669-4093-4A03-672AC177C848} - C:\PROGRA~1\CURBEG~1\Bags Software.exe (file missing)
O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll
O3 - Toolbar: My &Search Bar - {014DA6C9-189F-421a-88CD-07CFE51CFF10} - C:\Program Files\MySearch\bar\1.bin\S4BAR.DLL
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: EarthLink Toolbar - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: &My Way Speedbar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Program Files\MyWay\myBar\1.bin\MYBAR.DLL
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [Lexmark X74-X75] "C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Documents and Settings\Rita\My Documents\My Music\iTunesHelper.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [gwsrhathjgk] C:\WINDOWS\System32\etogqke.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [AVG_CC] C:\Program Files\Grisoft\AVG6\avgcc32.exe /startup
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [does hole pure loud] C:\Documents and Settings\All Users\Application Data\FaceBoltDoesHole\DupeOkay.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKLM\..\Run: [MSNMaSRR5] MSNMaSGRS.exe
O4 - HKLM\..\Run: [WIN32SNDAX] C:\snd.exe
O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe
O4 - HKLM\..\Run: [OSS] c:\windows\system32\rk.exe -boot
O4 - HKLM\..\Run: [WebRebates0] "C:\Program Files\Web_Rebates\WebRebates0.exe"
O4 - HKLM\..\RunServices: [MSNMaSRR5] MSNMaSGRS.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\PROGRA~1\SYSTEM~1\soap.exe min
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\6.bin\mwsoemon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [WinMX] C:\Program Files\WinMX\WinMX.exe -m
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\Exif Launcher\QuickDCF.exe
O4 - Global Startup: Internet Answering Machine.lnk = C:\Program Files\CallWave\IAM.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\6.bin\MWSOEMON.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZC
O8 - Extra context menu item: Refresh Pa&ge with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-page.html
O8 - Extra context menu item: Refresh Pi&cture with Full Quality - C:\Program Files\EarthLink TotalAccess\Accelerator\\pac-image.html
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_file.php?bt=ie&p=21a47cb4fd3122a6c3b1f5580f17b8b59065ba8dc993db3650e231915933b4ea0ae75250a6014043e7ea5e6e4a7fc4049f20ee666f814bce72fdad330c01fc0bc3:631cd4669b71c6b0897750224652ac34
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/ei/MySignatureFWBInitialSetup1.0.0.8.cab
O16 - DPF: {2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} (MiniBugTransporterX Class) - http://download.weatherbug.com/minibug/tricklers/AWS/MiniBugTransporter.cab?
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {72770C4F-967D-4517-982B-92D6B9015649} (DigWebHelper Class) - http://photos.msn.com/resources/neutral/controls/DigWebX.cab?9,0,712,0
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {79B96C72-C0D0-4DC8-BC7E-9F314A918228} - http://ak.imgfarm.com/images/nocache/myspeedbar/myinitialsetup1.0.0.7.cab
O16 - DPF: {89D75D39-5531-47BA-9E4F-B346BA9C362C} (CWDL_DownLoadControl Class) - http://www.callwave.com/include/cab/CWDL_DownLoad.CAB
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1437/ftp.coupons.com/v3123/cpbrkpie.cab
O16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB} (iTunesDetector Class) - http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://sea2fd.sea2.hotmail.msn.com/activex/HMAtchmt.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{4346BABD-6B8C-472D-AFDB-EE0CC45E03FF}: NameServer = 207.69.188.185 207.69.188.186
O17 - HKLM\System\CS2\Services\Tcpip\..\{4346BABD-6B8C-472D-AFDB-EE0CC45E03FF}: NameServer = 207.69.188.185 207.69.188.186Reply Midnight Star
4791 Posts
886
0
Posted December 11th, 2004 07:00
ATIR,
And boy did it have friends!
Ok, let's enlist the help of some free programs and see what they can do for us. You'll need to save this webpage to your harddrive for reference, since we're going to be rebooting your computer into a mode where the internet isn't available, or just print it out.
If you have any questions before you begin, don't hesitate to post back.
Let's download two free tools that when we're completely done cleaning off your pc, you'll be able to use on a regular basis to help keep your computer 'tidy'.
- Download and install AdAware SE Personal; be sure to "Check for updates now", then exit the program (we're going to run it later).
- Download and install Spybot S&D; be sure to "Search for Updates", download any that are available, then exit the program (we're going to run it later).
Reboot your computer into "Safe Mode"
Now, let's run the two free programs we've downloaded from above step, to help us remove some of that 'junk', one at a time...- Run AdAware SE Personal, then click "Start", then check(tick) "perform a full system scan", then click "Next". Allow it to remove all that it finds.
- Run Spybot S&D, then click "Check for Problems". Allow it to remove all tht it finds.
Next, go to Add/Remove programs, and remove the following, if present:
- Windows AdControl
- WebRebates
- MyWebSearch
- MyBar
- MySearchBar
Reboot your computer normally.
Post back a new log, and let's see what we've got.
Mike.
Message Edited by Midnight Star on 12-11-2004 03:45 AM
Reply :smileyhappy:Mike..just wanted to be sure and let you know I'm working on it. I've done the scanning, rebooting, scanning and removing problems with ADWareSE and SpyBot. Now I'm going to remove from the Add/Remove program. I will keep you informed on my progress. Thank you~
Atir
Reply Midnight Star
4791 Posts
886
0
Posted December 12th, 2004 05:00
ATIR,I know. There was so much on that system, that there's almost no way of getting it off in one pass. Let's see what we have left. Go ahead and post up a new log and let me look it over.Hang in there.Mike.Reply Definitions File Loaded:
Reference Number : SE1R21 03.12.2004
Internal build : 26
File location : C:\Program Files\Lavasoft\Ad-Aware SE Personal\defs.ref
File size : 407954 Bytes
Total size : 1292266 Bytes
Signature data size : 1262795 Bytes
Reference data size : 28959 Bytes
Signatures total : 35914
Fingerprints total : 577
Fingerprints size : 21902 Bytes
Target categories : 15
Target families : 625
Mike..wasn't sure if this would be any help. If not, let me know how to proceed. Sorry it's such a long page. I'm still getting the AVG popups..darn!
Thanks~
Target families : 625ArchiveData(auto-quarantine- 2004-12-11 22-47-59.bckp)
Referencefile : SE1R21 03.12.2004
======================================================MRU LIST
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\applets\wordpad\recent file list
obj[1]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\applets\paint\recent file list
obj[2]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\runmru
obj[3]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\search assistant\acmru\5001
obj[4]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\*
obj[5]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru\AAC
obj:emotion-14:=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.blg
obj[7]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.bmp
obj:emotion-29:=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.css
obj[9]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.eml
obj[10]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.gif
obj[11]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.hlp
obj[12]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.htm
obj[13]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.inf
obj[14]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.itl
obj[15]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.jpg
obj[16]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.js
obj[17]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.LOG
obj[18]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.m3u
obj[19]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.m4a
obj[20]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.mp3
obj[21]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.pdf
obj[22]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.png
obj[23]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.pps
obj[24]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.rtf
obj[25]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.theme
obj[26]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.txt
obj[27]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.wav
obj[28]=MRU RegReference : S-1-5-21-1606980848-162531612-725345543-1004\software\microsoft\windows\currentversion\explorer\recentdocs\.wma
obj[29]=MRU FileReference : C:\Documents and Settings\Rita\recent\05 How Far.lnk
obj[30]=MRU FileReference : C:\Documents and Settings\Rita\recent\08-16-2004 10;22;50AM.lnk
obj[31]=MRU FileReference : C:\Documents and Settings\Rita\recent\11-18-2004 10;13;08PM.lnk
obj[32]=MRU FileReference : C:\Documents and Settings\Rita\recent\2004-01-26, Mom and Dad (Baker) Jan 2004.lnk
obj[33]=MRU FileReference : C:\Documents and Settings\Rita\recent\48D3M-thumb-N08004-91.lnk
obj[34]=MRU FileReference : C:\Documents and Settings\Rita\recent\48D5V-smaller-N08004-156.lnk
obj[35]=MRU FileReference : C:\Documents and Settings\Rita\recent\6.bin.lnk
obj[36]=MRU FileReference : C:\Documents and Settings\Rita\recent\Aaron Neville & Linda Ronstadt - I Don't Know Much.lnk
obj[37]=MRU FileReference : C:\Documents and Settings\Rita\recent\Acknowledgements.lnk
obj[38]=MRU FileReference : C:\Documents and Settings\Rita\recent\aleabanr.lnk
obj[39]=MRU FileReference : C:\Documents and Settings\Rita\recent\amaizrul.lnk
obj[40]=MRU FileReference : C:\Documents and Settings\Rita\recent\Amerie All I Have 10 Show Me.lnk
obj[41]=MRU FileReference : C:\Documents and Settings\Rita\recent\Amy and Jenna.lnk
obj[42]=MRU FileReference : C:\Documents and Settings\Rita\recent\Andrew & Miciah Hagan (pegs grandsons).lnk
obj[43]=MRU FileReference : C:\Documents and Settings\Rita\recent\August 2004.lnk
obj[44]=MRU FileReference : C:\Documents and Settings\Rita\recent\AUTORUN.lnk
obj[45]=MRU FileReference : C:\Documents and Settings\Rita\recent\AVG6.lnk
obj[46]=MRU FileReference : C:\Documents and Settings\Rita\recent\Avrll Lavigne-Dont Tell Me.lnk
obj[47]=MRU FileReference : C:\Documents and Settings\Rita\recent\Blood Sweat and Tears - Eli's Coming.lnk
obj[48]=MRU FileReference : C:\Documents and Settings\Rita\recent\Btzhsepa.lnk
obj[49]=MRU FileReference : C:\Documents and Settings\Rita\recent\Callie and Isa 005.lnk
obj[50]=MRU FileReference : C:\Documents and Settings\Rita\recent\CD Drive.lnk
obj[51]=MRU FileReference : C:\Documents and Settings\Rita\recent\Chely Wright - bumper of my SUV story.lnk
obj[52]=MRU FileReference : C:\Documents and Settings\Rita\recent\chimes.lnk
obj[53]=MRU FileReference : C:\Documents and Settings\Rita\recent\chord.lnk
obj[54]=MRU FileReference : C:\Documents and Settings\Rita\recent\cirkel_bliksem.lnk
obj[55]=MRU FileReference : C:\Documents and Settings\Rita\recent\Corys address.lnk
obj[56]=MRU FileReference : C:\Documents and Settings\Rita\recent\Country Music - Emmy Lou Harris-Don Williams-Duets-If I Needed You.lnk
obj[57]=MRU FileReference : C:\Documents and Settings\Rita\recent\DaD(1).wps.lnk
obj[58]=MRU FileReference : C:\Documents and Settings\Rita\recent\Default Playlist.lnk
obj[59]=MRU FileReference : C:\Documents and Settings\Rita\recent\Dell.lnk
obj[60]=MRU FileReference : C:\Documents and Settings\Rita\recent\dellbutn.lnk
obj[61]=MRU FileReference : C:\Documents and Settings\Rita\recent\Desktop.ini
obj[62]=MRU FileReference : C:\Documents and Settings\Rita\recent\Digital Camera Photos.lnk
obj[63]=MRU FileReference : C:\Documents and Settings\Rita\recent\ding.lnk
obj[64]=MRU FileReference : C:\Documents and Settings\Rita\recent\Document.lnk
obj[65]=MRU FileReference : C:\Documents and Settings\Rita\recent\DSCF0037.lnk
obj[66]=MRU FileReference : C:\Documents and Settings\Rita\recent\Dusty Springfield - Wishin' And Hopin'(1).lnk
obj[67]=MRU FileReference : C:\Documents and Settings\Rita\recent\English.lnk
obj[68]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric & Sam.lnk
obj[69]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 006.lnk
obj[70]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 008.lnk
obj[71]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123rd Batallion 011.lnk
obj[72]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123rd Batallion 012.lnk
obj[73]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric 123th Batallion.lnk
obj[74]=MRU FileReference : C:\Documents and Settings\Rita\recent\Eric.lnk
obj[75]=MRU FileReference : C:\Documents and Settings\Rita\recent\errorlog.lnk
obj[76]=MRU FileReference : C:\Documents and Settings\Rita\recent\F3BKGERR.lnk
obj[77]=MRU FileReference : C:\Documents and Settings\Rita\recent\fieruled.lnk
obj[78]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib (2).lnk
obj[79]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib (3).lnk
obj[80]=MRU FileReference : C:\Documents and Settings\Rita\recent\filelib.lnk
obj[81]=MRU FileReference : C:\Documents and Settings\Rita\recent\FINAL_Winter_Pack_Readme.lnk
obj[82]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 048.lnk
obj[83]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 050.lnk
obj[85]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 052.lnk
obj[84]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 051.lnk
obj[86]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 053.lnk
obj[87]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix 055.lnk
obj[88]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePix.lnk
obj[89]=MRU FileReference : C:\Documents and Settings\Rita\recent\FinePixViewer.lnk
obj[90]=MRU FileReference : C:\Documents and Settings\Rita\recent\FW Miciah part 2.lnk
obj[91]=MRU FileReference : C:\Documents and Settings\Rita\recent\Glacier.lnk
obj[92]=MRU FileReference : C:\Documents and Settings\Rita\recent\Gretchen Wilson - When I Think About Cheatin'.lnk
obj[93]=MRU FileReference : C:\Documents and Settings\Rita\recent\hijackthis.lnk
obj[94]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hotbar (2).lnk
obj[95]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hotbar.lnk
obj[96]=MRU FileReference : C:\Documents and Settings\Rita\recent\Hurricane Charley.lnk
obj[97]=MRU FileReference : C:\Documents and Settings\Rita\recent\imesh.lnk
obj[98]=MRU FileReference : C:\Documents and Settings\Rita\recent\incubus_3323@hotmail.com.lnk
obj[99]=MRU FileReference : C:\Documents and Settings\Rita\recent\infupd.lnk
obj[100]=MRU FileReference : C:\Documents and Settings\Rita\recent\insert[1].lnk
obj[101]=MRU FileReference : C:\Documents and Settings\Rita\recent\INSTALL.lnk
obj[102]=MRU FileReference : C:\Documents and Settings\Rita\recent\ISamples.lnk
obj[103]=MRU FileReference : C:\Documents and Settings\Rita\recent\iTunes 4 Music Library.lnk
obj[104]=MRU FileReference : C:\Documents and Settings\Rita\recent\iTunes Music Library.lnk
obj[105]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna 10-2004 (2).lnk
obj[106]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna and Callie.lnk
obj[107]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna October 2004.lnk
obj[108]=MRU FileReference : C:\Documents and Settings\Rita\recent\Jenna Pre-School Pic 2004.lnk
obj[109]=MRU FileReference : C:\Documents and Settings\Rita\recent\juggler.lnk
obj[110]=MRU FileReference : C:\Documents and Settings\Rita\recent\Katie.lnk
obj[111]=MRU FileReference : C:\Documents and Settings\Rita\recent\Lexmark X74-X75.lnk
obj[112]=MRU FileReference : C:\Documents and Settings\Rita\recent\Library.lnk
obj[113]=MRU FileReference : C:\Documents and Settings\Rita\recent\login[2].lnk
obj[114]=MRU FileReference : C:\Documents and Settings\Rita\recent\lthtt[1].lnk
obj[115]=MRU FileReference : C:\Documents and Settings\Rita\recent\lxbbvb.lnk
obj[116]=MRU FileReference : C:\Documents and Settings\Rita\recent\Martina McBride - How Far.lnk
obj[117]=MRU FileReference : C:\Documents and Settings\Rita\recent\Martina.lnk
obj[118]=MRU FileReference : C:\Documents and Settings\Rita\recent\Media.lnk
obj[119]=MRU FileReference : C:\Documents and Settings\Rita\recent\mmdriver.lnk
obj[120]=MRU FileReference : C:\Documents and Settings\Rita\recent\montesscarlo@hotmail.com.lnk
obj[121]=MRU FileReference : C:\Documents and Settings\Rita\recent\msoe.lnk
obj[122]=MRU FileReference : C:\Documents and Settings\Rita\recent\My Chat Logs.lnkReply Midnight Star
4791 Posts
368
0
Posted December 12th, 2004 18:00
ATIR,
While your running those programs, post back a HiJackThis log, just like you did previously and i'll look that over at the same time.
Some 'problems' could be persistant beyond AdAware and Spybot.
Mike.
Reply ArchiveData(AD-Aware SE.bckp)
Referencefile : SE1R21 03.12.2004
======================================================
BLAZEFIND
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[0]=RegValue : software\microsoft\windows\currentversion\run "Windows AdControl"
obj[5]=File : C:\System Volume Information\_restore{B59D285F-D4E8-4F0B-8C15-ECAD980571E6}\RP238\A0139257.dll
TRACKING COOKIE
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
obj[1]=IECache Entry : Cookie:rita@questionmarket.com/
obj[2]=IECache Entry : Cookie:rita@apmebf.com/
obj[3]=IECache Entry : C:\Documents and Settings\Rita\Cookies\rita@apmebf[1].txt
obj[4]=IECache Entry : C:\Documents and Settings\Rita\Cookies\rita@questionmarket[2].txt
Hoping this is some more help to you...I'm going to run SpyBot again.Reply

Midnight Star
4791 Posts
885
0
Posted December 10th, 2004 07:00
First, start by going to www.trendmicro.com and click "Free Online Scan". It'll take a few minutes to download and install. When it's done, select all available drives, then click "Scan".
Post back the results.
Mike.