Unsolved

This post is more than 5 years old

16 Posts

1951

December 26th, 2006 17:00

Best offer fustrations!

II continuously get "best offer" popups and when I access my webmail e-mail account and try to create a new message, the new message window pops up and then pops off very quickly. So I can't create any new messages.
 
 
Logfile of HijackThis v1.99.1
Scan saved at 1:41:32 PM, on 12/26/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Spyware Doctor\sdhelp.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\PRISMSVR.EXE
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\System32\CTHELPER.EXE
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Norton Password Manager\AcctMgr.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Ebates__MoeMoney__Maker\ebatesmmmv.exe
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
C:\PROGRA~1\SPYWAR~1\swdoctor.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Ebates__MoeMoney__Maker\eb.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\edfnewcjee.exe
C:\Program Files\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
F2 - REG:system.ini: Shell=Explorer.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [ebmmm] "C:\Program Files\Ebates__MoeMoney__Maker\ebatesmmmv.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Ebates - file://C:\Program Files\Ebates__MoeMoney__Maker\ebmmt\ebmmC5.htm
O8 - Extra context menu item: Ebates. - file://C:\Program Files\EbatesMoeMoneyMaker4\ebatessmmm\ebatestmmm\ebmmC0.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: Ebates - {F2B441CC-E026-47fb-BDC3-A07750FA3D2C} - file://C:\Program Files\Ebates__MoeMoney__Maker\ebmmt\ebmmC5.htm (HKCU)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://www.pswslaw.net/desktop/v3rdpchk.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.pswslaw.net/desktop/msrdp.cab
O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://ecampus.phoenix.edu/secure/PhxStudent15.CAB
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
 

569 Posts

December 26th, 2006 18:00

This is more than likely the Moe Money program installed on your computer. Try uninstalling this from Ad/Remove programs in Control Panel. You can read about it here:
     
                                     http://www.spywareguide.com/product_show.php?id=1028

10.4K Posts

December 26th, 2006 18:00

bzmama

Re Run Hijackthis
  • At the Main window select " Open the misc tool section"
    Then select " Open uninstall manager"
    Then " save list" and save it to your desktop
Copy and paste that list as a reply to this thread
 
bamajim   Graduate of MRU

 




16 Posts

December 26th, 2006 19:00

ok, now what?
 
3D Home Architect Home Design Deluxe 6
3D Home Architect(r) Deluxe 3.0
Adobe Download Manager 2.0 (Remove Only)
Adobe Reader 7.0
ArcSoft PhotoStudio 5.5
ATI Control Panel
ATI Display Driver
AutoCAD 2000
AutoCAD 2000 Migration Assistance
AX Remote Editor 1.0
Best of Poker
Broderbund Home Design 5.1
Cabela's Big Game Hunter 2004 Season
Cabela's Ultimate Deer Hunt
Canon CanoScan LiDE 600F User Registration
Canon CanoScan Toolbox 5.0
CanoScan LiDE 600F
Classic PhoneTools
Creative MediaSource
Dell Digital Jukebox Driver
Dell Media Experience
Dell ResourceCD
Dell Solution Center
Dell Support 5.0.0 (766)
DVDSentry
Easy CD & DVD Creator 6
Ebates Moe Money Maker
eGames Master's Edition 151
Galaxy of Games 201
Google Toolbar for Internet Explorer
HijackThis 1.99.1
Intel(R) 537EP V9x DFV PCI Modem
Intel(R) PRO Network Adapters and Drivers
Intel(R) PROSet
Internet Explorer Default Page
Jasc Paint Shop Photo Album
Jasc Paint Shop Pro 8 Dell Edition
Java 2 Runtime Environment, SE v1.4.2
Learn2 Player (Uninstall Only)
LiveReg (Symantec Corporation)
LiveUpdate 2.6 (Symantec Corporation)
MA111 Configuration Utility
Macromedia Flash Player 8
Marine Sharpshooter II: Jungle Warfare
MGI PhotoSuite 8.1 (Remove Only)
Microsoft .NET Framework 1.1
Microsoft Encarta Encyclopedia Standard 2004
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office XP Professional
Modem Event Monitor
Modem Helper
Modem On Hold
MSRedist
MUSICMATCH® Jukebox
MYOB Accounting Plus V10
Norton Password Manager
Norton Password Manager (Symantec Corporation)
Norton WMI Update
NPM_DRM_COLLECTION
PC Doc Pro 3.5
Pop-Up Stopper Free Edition
PowerDVD
Presto! PageManager 7.15.13
Quicken 2002 Home & Business
QuickTime
RealPlayer Basic
ScanSoft OmniPage SE 4.0
ScrewDrivers Client v3
Shockwave
Sonic DLA
Sonic MyDVD
Sonic RecordNow!
Sonic Update Manager
Sound Blaster Audigy 2
Spybot - Search & Destroy 1.3
Spyware Doctor 4.0
TrueMobile 1300 USB 2.0 WLAN
v3 RDP Only Web Push (nstl chk)
Viewpoint Media Player
Windows XP Hotfix - KB842773
WordPerfect Office 11
 

10.4K Posts

December 26th, 2006 20:00

bzmama

1. Go here and Download AVG Anti-Spyware
( 30 day free trial version) Save it to Your Desktop
 
Double Click AVG Anti-Spyware-setup
(It will create its own folder)
Once the program starts You will be at the Status menu
  • Under "Your computers Security"
    Click change status on Resident shield to inactive
    Click Update now (next to last update)
    After the update loads
    Under Automatic updates Uncheck download and install updates automatically(recommended)
    (you can always select maual updates the next day)
At the top toolbar Click Scanner Then the settings tab
  • Under How to act? Set default action for detected malwareTo Quarantine
    Under how to scan All boxes should be checked
    Under Possibly unwanted software All boxes should be checked
    Under reports Select Automatically generate report after every scan
    Uncheck Only if threats were found
    Under what to scan Scan every file should be highlited
Exit AVG ( But do not run it yet)
 
Reboot into Safe Mode
This can be done by
  • Restart your PC, and after it starts, but before you see the Windows Splash screen
    Begin tapping the F8 key twice a second untill you reach another menu screen (black background with white menu choices)
    Use your arrow keys and select Safe Mode and then Enter

2. Go To Add/Remove Programs (Click Start->>Control Panel->>Add/Remove Programs)
and Uninstall the following programs
  • Ebates Moe Money Maker
    Internet Explorer Default Page
Close Add/Remove Programs

3. Run AVG Anti-Spyware
  • Click scanner
    Select Complete system scan
Once the scan finishes
  • Select Apply all actions (The items found will be quarantined)
    Click save report as (Another window will open)
    Save it to your desktop
    (By default It will be saved in the AVG folder as)
    C:\Program Files\Grisoft\AVG anti-spyware 7.5\Reports
Exit AVG
 
Reboot your PC in Normal Mode->>Re run Hijackthis and post a fresh Hijackthis log.
  • Double click the report-scan txt. you saved to your desktop
    It will open in Notepad
    Copy and paste that report as a reply to this thread
Your reply should include
  • a fresh Hijackthis log
    your report_scan.txt log from AVG
    bamajim   Graduate of MRU
     

    16 Posts

    December 26th, 2006 22:00

    hijackthis log
    Logfile of HijackThis v1.99.1
    Scan saved at 6:52:58 PM, on 12/26/2006
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\System32\PRISMSVR.EXE
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\PROGRA~1\SPYWAR~1\swdoctor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
    C:\Program Files\HijackThis\HijackThis.exe
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Ebates. - file://C:\Program Files\EbatesMoeMoneyMaker4\ebatessmmm\ebatestmmm\ebmmC0.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {F2B441CC-E026-47fb-BDC3-A07750FA3D2C} - (no file) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://www.pswslaw.net/desktop/v3rdpchk.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.pswslaw.net/desktop/msrdp.cab
    O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://ecampus.phoenix.edu/secure/PhxStudent15.CAB
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: System Startup Service  (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
     
     

    16 Posts

    December 26th, 2006 23:00

    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------
     + Created at: 6:50:14 PM 12/26/2006
     + Scan result: 
     
    HKLM\SOFTWARE\180solutions -> Adware.180Solutions : No action taken.
    HKLM\SOFTWARE\msbb -> Adware.180Solutions : No action taken.
    HKU\S-1-5-21-1678034399-1757825659-2653423567-1007\Software\msbb -> Adware.180Solutions : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044048.dll -> Adware.ActivShopper : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044049.dll -> Adware.ActivShopper : No action taken.
    HKLM\SOFTWARE\Classes\CLSID\{3D782BB3-F2A5-11D3-BF4C-000000000000} -> Adware.ActivShopper : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Desktop\DrTemp\randreco.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI6DB1.tmp\adremtm3.cab/remtm3.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI6DB1.tmp\remtm3.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI77B.tmp\remtm3.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\rndrcus.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\aurareco.exe -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\rndrcus.exe -> Adware.BetterInternet : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043271.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\Nail.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\SYSTEM32\ln_reco.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\SYSTEM32\randreco.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\SYSTEM32\stmtreco.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\remtm3.exe -> Adware.BetterInternet : No action taken.
    C:\WINDOWS\svcproc.exe -> Adware.BetterInternet : No action taken.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bsto-1 -> Adware.BetterInternet : No action taken.
    HKLM\SYSTEM\CurrentControlSet\Services\SvcProc -> Adware.BetterInternet : No action taken.
    HKLM\SYSTEM\CurrentControlSet\Services\SvcProc\Enum -> Adware.BetterInternet : No action taken.
    HKLM\SYSTEM\CurrentControlSet\Services\SvcProc\Security -> Adware.BetterInternet : No action taken.
    HKU\S-1-5-21-1678034399-1757825659-2653423567-1007\Software\aurora -> Adware.BetterInternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI3002.tmp\localNRD.dll -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI3002.tmp\localNrd.cab/localNRD.dll -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI3002.tmp\localNrd.cab/preInsln.exe -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI3002.tmp\preInsln.exe -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\localNRD.dll -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\localNrd.cab/localNRD.dll -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\localNrd.cab/preInsln.exe -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\preInsln.exe -> Adware.BiSpy : No action taken.
    C:\WINDOWS\preInsln.exe -> Adware.BiSpy : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\Pynix.dll -> Adware.DlMax : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\pynix.cab/Pynix.dll -> Adware.DlMax : No action taken.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044063.dll -> Adware.ImiBar : No action taken.
    C:\WINDOWS\systb.dll_tobedeleted -> Adware.ImiBar : No action taken.
    HKLM\SOFTWARE\Avenue Media -> Adware.InternetOptimizer : No action taken.
    C:\Program Files\MBKWBar\IEToolBar.dll -> Adware.MBKWBar : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Start Menu\Programs\Power Scan -> Adware.PowerScan : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Start Menu\Programs\Power Scan\Power Scan.lnk -> Adware.PowerScan : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP527\A0043347.exe -> Adware.Rebates : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP527\A0043351.exe -> Adware.Rebates : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI509F.tmp\trebates.cab/trebates.exe -> Adware.WebRebates : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI509F.tmp\trebates.exe -> Adware.WebRebates : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\djtopr1150.exe -> Adware.WebRebates : No action taken.
    C:\WINDOWS\trebates.exe -> Adware.WebRebates : No action taken.

    16 Posts

    December 26th, 2006 23:00

    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-cafepress.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-ebsco.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-learningco.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-professionalequipment.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-traderelectronicmedia.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-traderpublishing.hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@hg1.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@hitbox[2].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@phg.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@counter.hitslink[2].txt -> TrackingCookie.Hitslink : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@counter2.hitslink[1].txt -> TrackingCookie.Hitslink : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@linksynergy[2].txt -> TrackingCookie.Linksynergy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@sales.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@mediaplex[1].txt -> TrackingCookie.Mediaplex : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@www.myaffiliateprogram[2].txt -> TrackingCookie.Myaffiliateprogram : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@data3.perf.overture[2].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@perf.overture[1].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@overture[2].txt -> TrackingCookie.Overture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ads.pointroll[2].txt -> TrackingCookie.Pointroll : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@ads.pointroll[1].txt -> TrackingCookie.Pointroll : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@c.porngraph[1].txt -> TrackingCookie.Porngraph : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@qksrv[1].txt -> TrackingCookie.Qksrv : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@questionmarket[2].txt -> TrackingCookie.Questionmarket : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@questionmarket[1].txt -> TrackingCookie.Questionmarket : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@web4.realtracker[1].txt -> TrackingCookie.Realtracker : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@revenue[2].txt -> TrackingCookie.Revenue : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@edge.ru4[1].txt -> TrackingCookie.Ru4 : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@edge.ru4[2].txt -> TrackingCookie.Ru4 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@.serving-sys[1].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@serving-sys[2].txt -> TrackingCookie.Serving-sys : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ads.specificpop[1].txt -> TrackingCookie.Specificpop : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@statcounter[2].txt -> TrackingCookie.Statcounter : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@statcounter[1].txt -> TrackingCookie.Statcounter : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@anad.tacoda[2].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@anat.tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@tacoda[1].txt -> TrackingCookie.Tacoda : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@login.tracking101[2].txt -> TrackingCookie.Tracking101 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@tradedoubler[2].txt -> TrackingCookie.Tradedoubler : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@trafficmp[2].txt -> TrackingCookie.Trafficmp : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@trafficmp[1].txt -> TrackingCookie.Trafficmp : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@hlwd.valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@oz.valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@valueclick[1].txt -> TrackingCookie.Valueclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@valueclick[2].txt -> TrackingCookie.Valueclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@webstat[2].txt -> TrackingCookie.Web-stat : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ads.x10[1].txt -> TrackingCookie.X10 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@install.xxxtoolbar[1].txt -> TrackingCookie.Xxxtoolbar : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@www.xxxtoolbar[1].txt -> TrackingCookie.Xxxtoolbar : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@xxxtoolbar[2].txt -> TrackingCookie.Xxxtoolbar : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@zedo[2].txt -> TrackingCookie.Zedo : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\pynix.cab/spike.exe -> Trojan.Agent.cb : No action taken.

    10.4K Posts

    December 26th, 2006 23:00

    bzmama

    We have a problem, that needs to be corrected: The results of the AVG scan shows
    • HKLM\SOFTWARE\180solutions -> Adware.180Solutions : No action taken.
      HKLM\SOFTWARE\msbb -> Adware.180Solutions : No action taken.
    It should show Quarantined

    I need you to Recheck the settings in AVG, and run it again. The critical ones are in red
    • Open AVG
      At the top toolbar Click Scanner Then the settings tab
      Under How to act? Set default action for detected malwareTo Quarantine


    Reboot into Safe Mode and Rerun it
    Once the scan finishes

    Select Apply all actions (The items found will be quarantined)

    There is no need ot repost the entire AVG log, Just post a couple of lines so I will know that it Quarantined the items
     
    thanks
    bamajim   Graduate of MRU
     

    16 Posts

    December 26th, 2006 23:00

    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP512\A0042045.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP512\A0042053.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP515\A0042089.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP515\A0042090.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP516\A0043089.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP516\A0043101.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP516\A0043102.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP517\A0043127.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP517\A0043141.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP517\A0043152.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP517\A0043153.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP518\A0043194.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP518\A0043195.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP518\A0043197.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP518\A0043198.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043243.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043244.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043267.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043269.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043285.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043286.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP520\A0043317.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP520\A0043318.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP530\A0043380.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP530\A0043381.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP530\A0043382.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP530\A0043383.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP534\A0043397.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP534\A0043398.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043427.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043428.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043438.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043439.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043448.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP535\A0043450.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP539\A0043609.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP539\A0043610.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP540\A0043626.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP540\A0043640.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP540\A0043641.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP540\A0043642.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP541\A0043645.exe -> Trojan.Agent.cp : No action taken.
    C:\WINDOWS\SYSTEM32\nhuahi.exe -> Trojan.Agent.cp : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP537\A0043589.dll -> Trojan.Agent.db : No action taken.
    C:\WINDOWS\wsem302.dll_tobedeleted -> Trojan.Dyfuca : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044061.exe -> Trojan.Imiserv.c : No action taken.
    C:\WINDOWS\systb.exe -> Trojan.Imiserv.c : No action taken.
    C:\WINDOWS\tdtb.exe -> Trojan.Imiserv.c : No action taken.

    ::Report end

    16 Posts

    December 26th, 2006 23:00

    HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Adware.WebRebates : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP527\A0043348.dll -> Adware.WebRebates ok : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI3002.tmp\localNrd.cab/polall1l.exe -> Downloader.Agent.ae : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\localNrd.cab/polall1l.exe -> Downloader.Agent.ae : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\polall1l.exe -> Downloader.Agent.ae : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\optimize.exe -> Downloader.Dyfuca.cy : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI6D44.tmp\wupdt.exe -> Downloader.Intexp.a : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\YSa03808\enhupdt.exe -> Downloader.Intexp.c : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\mynut2.exe/enhupdt.exe -> Downloader.Intexp.c : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\M4a02908\enhupdt.exe -> Downloader.Intexp.c : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\mynut2.exe/enhupdt.exe -> Downloader.Intexp.c : No action taken.
    C:\WINDOWS\LastGood.Tmp\enhupdt.exe -> Downloader.Intexp.c : No action taken.
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044062.exe -> Downloader.Intexp.d : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\iinstall.exe -> Downloader.IstBar.fp : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\conscorr.cab/conscorr.exe -> Downloader.Stubby.c : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\conscorr.exe -> Downloader.Stubby.c : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\conscorr.cab/conscorr.exe -> Downloader.Stubby.c : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\conscorr.exe -> Downloader.Stubby.c : No action taken.
    C:\WINDOWS\conscorr.exe -> Downloader.Stubby.c : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\satmat.cab/satmat.exe -> Downloader.Stubby.d : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\satmat.exe -> Downloader.Stubby.d : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\satmat.cab/satmat.exe -> Downloader.Stubby.d : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\satmat.exe -> Downloader.Stubby.d : No action taken.
    C:\WINDOWS\satmat.exe -> Downloader.Stubby.d : No action taken.
    C:\command.exe -> Dropper.Delf.ev : No action taken.
    C:\counter.cab/counter.exe -> Dropper.Small.ls : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ads.180solutions[1].txt -> TrackingCookie.180solutions : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@2o7[2].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@rbsinteractive.122.2o7[2].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@lightspeed.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@7search[2].txt -> TrackingCookie.7search : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@aavalue[2].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@reciperewards.aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@aavalue[2].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@paidmarketingpanel.aavalue[1].txt -> TrackingCookie.Aavalue : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@abetterinternet[1].txt -> TrackingCookie.Abetterinternet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@adbrite[2].txt -> TrackingCookie.Adbrite : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ads.addynamix[2].txt -> TrackingCookie.Addynamix : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@ads.addynamix[1].txt -> TrackingCookie.Addynamix : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@track.adrevolver[1].txt -> TrackingCookie.Adrevolver : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@z1.adserver[1].txt -> TrackingCookie.Adserver : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@z1.adserver[1].txt -> TrackingCookie.Adserver : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@advertising[1].txt -> TrackingCookie.Advertising : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@servedby.advertising[1].txt -> TrackingCookie.Advertising : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@atdmt[2].txt -> TrackingCookie.Atdmt : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@bestoffersnetworks[1].txt -> TrackingCookie.Bestoffersnetworks : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@bestoffersnetworks[3].txt -> TrackingCookie.Bestoffersnetworks : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@bfast[1].txt -> TrackingCookie.Bfast : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@bluestreak[1].txt -> TrackingCookie.Bluestreak : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@www.burstnet[1].txt -> TrackingCookie.Burstnet : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@casalemedia[2].txt -> TrackingCookie.Casalemedia : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@centrport[2].txt -> TrackingCookie.Centrport : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@clickagents[2].txt -> TrackingCookie.Clickagents : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@clickbank[2].txt -> TrackingCookie.Clickbank : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@cliks[1].txt -> TrackingCookie.Cliks : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@cliks[1].txt -> TrackingCookie.Cliks : No action taken.
    C:\Documents and Settings\LocalService\Cookies\kimberly honeycutt@cliks[2].txt -> TrackingCookie.Cliks : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@com[1].txt -> TrackingCookie.Com : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@com[1].txt -> TrackingCookie.Com : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@www.directnetadvertising[1].txt -> TrackingCookie.Directnetadvertising : No action taken.
    C:\Documents and Settings\Kimberly Honeycutt\Cookies\kimberly honeycutt@www.directnetadvertising[1].txt -> TrackingCookie.Directnetadvertising : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@doubleclick[1].txt -> TrackingCookie.Doubleclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@e-2dj6wfkyknczkgp.stats.esomniture[1].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@e-2dj6wjmyogczwlp.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@e-2dj6wjnyumdpmbo.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@y-1shz2prbmdj6wvny-1sez2pra2dj6wjmyuoajmkpqudj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnyeldzwfow6dj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@y-1shz2prbmdj6wvny-1sez2pra2dj6wjnygkazkhowydj6x9ny-1seq-2-2.stats.esomniture[2].txt -> TrackingCookie.Esomniture : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@estat[1].txt -> TrackingCookie.Estat : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@as-us.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@sel.as-us.falkag[2].txt -> TrackingCookie.Falkag : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@fastclick[1].txt -> TrackingCookie.Fastclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@media.fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\Cookies\daemon honeycutt@fastclick[2].txt -> TrackingCookie.Fastclick : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@findwhat[1].txt -> TrackingCookie.Findwhat : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@gator[1].txt -> TrackingCookie.Gator : No action taken.
    C:\Documents and Settings\Daemon Honeycutt\Cookies\daemon honeycutt@ehg-accuweather.hitbox[1].txt -> TrackingCookie.Hitbox : No action taken.

    16 Posts

    January 9th, 2007 22:00

    ok, how is this (sorry it took so long to get back)
     
    AVG:
    ---------------------------------------------------------
    AVG Anti-Spyware - Scan Report
    ---------------------------------------------------------
     + Created at: 5:44:30 PM 1/9/2007
     + Scan result: 
     
    HKLM\SOFTWARE\180solutions -> Adware.180Solutions : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\msbb -> Adware.180Solutions : Cleaned with backup (quarantined).
    HKU\S-1-5-21-1678034399-1757825659-2653423567-1007\Software\msbb -> Adware.180Solutions : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044048.dll -> Adware.ActivShopper : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP548\A0044049.dll -> Adware.ActivShopper : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Classes\CLSID\{3D782BB3-F2A5-11D3-BF4C-000000000000} -> Adware.ActivShopper : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Desktop\DrTemp\randreco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI6DB1.tmp\adremtm3.cab/remtm3.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI6DB1.tmp\remtm3.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\THI77B.tmp\remtm3.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\aurareco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Daemon Honeycutt\Local Settings\Temp\rndrcus.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\aurareco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\Documents and Settings\Kimberly Honeycutt\Local Settings\Temp\rndrcus.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\System Volume Information\_restore{987E0331-0F01-427C-A58A-7A2E4AABF84D}\RP519\A0043271.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\ln_reco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\randreco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\SYSTEM32\stmtreco.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\ounqof.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\remtm3.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    C:\WINDOWS\svcproc.exe -> Adware.BetterInternet : Cleaned with backup (quarantined).
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\bsto-1 -> Adware.BetterInternet : Cleaned with backup (quarantined).
    HKLM\SYSTEM\CurrentControlSet\Services\SvcProc -> Adware.BetterInternet : Cleaned with backup (quarantined).
    HKLM\SYSTEM\CurrentControlSet\Services\SvcProc\Enum -> Adware.BetterInternet : Cleaned with backup (quarantined).
     
     
    Hijck this:
     
    Logfile of HijackThis v1.99.1
    Scan saved at 5:47:33 PM, on 1/9/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\PRISMSVR.EXE
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\PROGRA~1\SPYWAR~1\swdoctor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
    C:\WINDOWS\System32\wbem\wmiprvse.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Ebates. - file://C:\Program Files\EbatesMoeMoneyMaker4\ebatessmmm\ebatestmmm\ebmmC0.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {F2B441CC-E026-47fb-BDC3-A07750FA3D2C} - (no file) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://www.pswslaw.net/desktop/v3rdpchk.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.pswslaw.net/desktop/msrdp.cab
    O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://ecampus.phoenix.edu/secure/PhxStudent15.CAB
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     

    10.4K Posts

    January 9th, 2007 23:00

    bzmama

    Though you had given up.
    We've picked up a new entry we need to deal with

    1. Please download Nailfix from

    HERE
    :
    • Save it to your Desktop
      Rt Click->> Extract All->>Extract it to your desktop
      But do not run it yet
    2. Reboot into Safe Mode
    This can be done by
    • Restart your PC, and after it starts, but before you see
      the Windows Splash screen
      Begin tapping the F8 key twice a second untill you reach another
      menu screen (black background with white menu choices)
      Use your arrow keys and select Safe Mode and then
      Enter
    Once in Safe Mode,
    • 3. Open the Nailfix folder.
      Double-click on Nailfix.cmd. Your desktop and icons will
      disappear and reappear,
      and a window should open and close very quickly --- this is
      normal.
    Reboot your PC into Normal Windows mode->>Rerun Hijackthis and post a fresh log.
     
    bamajim   Graduate of MRU

     



    16 Posts

    January 10th, 2007 01:00

    ok
     
    Logfile of HijackThis v1.99.1
    Scan saved at 9:27:35 PM, on 1/9/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\PRISMSVR.EXE
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\PROGRA~1\SPYWAR~1\swdoctor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\HijackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    F2 - REG:system.ini: Shell=Explorer.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O8 - Extra context menu item: Ebates. - file://C:\Program Files\EbatesMoeMoneyMaker4\ebatessmmm\ebatestmmm\ebmmC0.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {F2B441CC-E026-47fb-BDC3-A07750FA3D2C} - (no file) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://www.pswslaw.net/desktop/v3rdpchk.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.pswslaw.net/desktop/msrdp.cab
    O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://ecampus.phoenix.edu/secure/PhxStudent15.CAB
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     

    10.4K Posts

    January 10th, 2007 23:00

    bzmama

    Looking better.

    1. Rerun Hijackthis (scan only) and place checks beside the following entries
    • R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
      R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
      O4 - Startup: PowerReg Scheduler V3.exe
      O8 - Extra context menu item: Ebates. - file://C:\Program Files\EbatesMoeMoneyMaker4\ebatessmmm\ebatestmmm\ebmmC0.htm
      O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
    Close all other open windows except Hijackthis and Select " Fix checked" and close Hijackthis

    2. Using Windows Explorer
    • (Right click on "Start," select "Explore," and you will see the "tree' of file folders in the left side of the window. Click on the "+" next to any folder name to expand its contents)
    Locate and Delete the following folder
    • C:\Program Files\EbatesMoeMoneyMaker4
    Close windows explorer->>Reboot your PC ->>Rerun Hijackthis and post a fresh log
     
    bamajim   Graduate of MRU
     

    16 Posts

    January 11th, 2007 12:00

    ok.
    I could not find the ebates folder. I looked under program files as you suggested and then did a global search and still could not find it.
     
     
    Logfile of HijackThis v1.99.1
    Scan saved at 8:49:23 AM, on 1/11/2007
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\csrss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\System32\Ati2evxx.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\System32\alg.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\CTsvcCDA.exe
    C:\Program Files\Spyware Doctor\sdhelp.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    C:\WINDOWS\System32\MsPMSPSv.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\WINDOWS\Explorer.exe
    C:\WINDOWS\System32\PRISMSVR.EXE
    C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    C:\WINDOWS\system32\dla\tfswctrl.exe
    C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe
    C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    C:\WINDOWS\System32\CTHELPER.EXE
    C:\WINDOWS\System32\DSentry.exe
    C:\Program Files\Dell\Media Experience\PCMService.exe
    C:\Program Files\Real\RealPlayer\RealPlay.exe
    C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    C:\Program Files\Norton Password Manager\AcctMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
    C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
    C:\Program Files\Dell Support\DSAgnt.exe
    C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe
    C:\PROGRA~1\SPYWAR~1\swdoctor.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    C:\WINDOWS\System32\wuauclt.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg4.EXE
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis\HijackThis.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer Provided by Cox High Speed Internet
    F2 - REG:system.ini: Shell=Explorer.exe
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
    O2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
    O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
    O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\WINDOWS\System32\PRISMSVR.EXE" /APPLY
    O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
    O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
    O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
    O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
    O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
    O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [AcctMgr] C:\Program Files\Norton Password Manager\AcctMgr.exe /startup
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
    O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
    O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
    O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
    O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
    O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
    O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRA~1\PANICW~1\POP-UP~1\PSFree.exe"
    O4 - HKCU\..\Run: [Spyware Doctor] C:\PROGRA~1\SPYWAR~1\swdoctor.exe /Q
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: MA111 Configuration Utility.lnk = C:\Program Files\NETGEAR\MA111 Configuration Utility\wlancfg.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\shdocvw.dll
    O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dll
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {F2B441CC-E026-47fb-BDC3-A07750FA3D2C} - (no file) (HKCU)
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
    O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/LSSupCtl.cab
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {30439117-02CA-4FBA-ADAF-84C2D8E2004D} (v3 silent install) - http://www.pswslaw.net/desktop/v3rdpchk.cab
    O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/yinst20040510.cab
    O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {9059F30F-4EB1-4BD2-9FDC-36F43A218F4A} (Microsoft RDP Client Control (redist)) - http://www.pswslaw.net/desktop/msrdp.cab
    O16 - DPF: {A82C3A33-5C0E-466C-B020-71585433A7E4} (PhxStudent.OeSetup15) - https://ecampus.phoenix.edu/secure/PhxStudent15.CAB
    O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/SymAData.cab
    O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
    O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
    O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe
    O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
    O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
     
    No Events found!

    Top