PDA

View Full Version : Persistant Pop-Ups



erccseal
2006-11-30, 19:15
Despite using Spybot, AVG, and the like, I haven't been able to get pop-ups to stop. Ran Panda Activescan and HijackThis. Any help you can offer would be greatly appreciated! Logs follow in subsequent posts, too long for C/P.

erccseal
2006-11-30, 19:39
Incident Status Location

Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{9AFB8248-617F-460d-9366-D71CDEDA3179}
Dialer:dialer.min Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB893839-10F0-4AF9-92FA-B23528F530AF}
Potentially unwanted tool:application/seekmo Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38}
Adware:adware/ieplugin Not disinfected Windows Registry
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.advertising.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.atwola.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.2o7.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@2o7[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@ad.yieldmanager[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@adrevolver[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@ads.pointroll[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@advertising[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@as-us.falkag[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@atwola[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@casalemedia[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@doubleclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@fastclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@media.fastclick[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@realmedia[2].txt

erccseal
2006-11-30, 19:41
Incident Status Location

Potentially unwanted tool:application/funweb Not disinfected c:\windows\downloaded program files\f3initialsetup1.0.0.15.inf
Potentially unwanted tool:application/mywebsearch Not disinfected hkey_classes_root\clsid\{9AFB8248-617F-460d-9366-D71CDEDA3179}
Dialer:dialer.min Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB893839-10F0-4AF9-92FA-B23528F530AF}
Potentially unwanted tool:application/seekmo Not disinfected HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{5929CD6E-2062-44A4-B2C5-2C7E78FBAB38}
Adware:adware/ieplugin Not disinfected Windows Registry
Adware:adware/exact.bargainbuddy Not disinfected Windows Registry
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.advertising.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.atwola.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.2o7.net/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.zedo.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[.perf.overture.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\vjp7bdvy.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@2o7[2].txt
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@ad.yieldmanager[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@adrevolver[1].txt
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@adrevolver[2].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@ads.pointroll[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@advertising[1].txt
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@as-us.falkag[1].txt
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@atdmt[2].txt
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@atwola[2].txt
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@casalemedia[2].txt
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@doubleclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@fastclick[2].txt
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@media.fastclick[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@realmedia[2].txt

erccseal
2006-11-30, 19:44
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@trafficmp[2].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\HP_Administrator\Local Settings\Temp\Cookies\hp_administrator@tribalfusion[2].txt
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.advertising.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.atwola.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.2o7.net/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[servedby.advertising.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.servedby.advertising.com/]
Spyware:Cookie/Coremetrics Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.data.coremetrics.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.as-us.falkag.net/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.adultfriendfinder.com/]
Spyware:Cookie/Sextracker Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.sextracker.com/]
Spyware:Cookie/Outster Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.outster.com/]
Spyware:Cookie/Falkag Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.as-eu.falkag.net/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.statse.webtrendslive.com/]
Spyware:Cookie/WebtrendsLive Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[statse.webtrendslive.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.hitbox.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.sexlist.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.com.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.serving-sys.com/]
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.bs.serving-sys.com/]
Spyware:Cookie/Adrevolver Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.adrevolver.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.overture.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.overture.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.burstnet.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.ad.yieldmanager.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.z1.adserver.com/]
Spyware:Cookie/WUpd Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.revenue.net/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Zedo Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.zedo.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.toplist.cz/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/Target Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.target.com/]
Spyware:Cookie/Statcounter Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.statcounter.com/]
Spyware:Cookie/Adtech Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.adtech.de/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[server.iad.liveperson.net/]
Spyware:Cookie/Hitslink Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[counter.hitslink.com/]
Spyware:Cookie/Server.iad.Liveperson Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[server.iad.liveperson.net/hc/90916754]
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.perf.overture.com/]

erccseal
2006-11-30, 19:46
Spyware:Cookie/Bridgetrack Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[citi.bridgetrack.com/]
Spyware:Cookie/onestat.com Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[stat.onestat.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Bfast Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.bfast.com/]
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.linksynergy.com/]
Spyware:Cookie/Hbmediapro Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.adopt.hbmediapro.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.bluestreak.com/]
Spyware:Cookie/CentrPort Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.centrport.net/]
Spyware:Cookie/WebPower Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.webpower.com/]
Spyware:Cookie/Weborama Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.weborama.fr/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[searchportal.information.com/]
Spyware:Cookie/BurstBeacon Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[www.burstbeacon.com/]
Spyware:Cookie/Hitbox Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.ehg-dig.hitbox.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.go.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.247realmedia.com/]
Spyware:Cookie/Valueclick Not disinfected C:\Documents and Settings\James\Application Data\Mozilla\Firefox\Profiles\tjslsmpp.default\cookies.txt[.valueclick.com/]
Spyware:Cookie/2o7 Not disinfected C:\Documents and Settings\James\Cookies\james@2o7[1].txt
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\James\Cookies\james@ads.pointroll[2].txt
Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\James\Cookies\james@com[1].txt
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\James\Cookies\james@cs.sexcounter[2].txt
Spyware:Cookie/360i Not disinfected C:\Documents and Settings\James\Cookies\james@ct.360i[2].txt
Spyware:Cookie/PayCounter Not disinfected C:\Documents and Settings\James\Cookies\james@paycounter[1].txt
Spyware:Cookie/Overture Not disinfected C:\Documents and Settings\James\Cookies\james@perf.overture[1].txt
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\James\Cookies\james@questionmarket[1].txt
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\James\Cookies\james@realmedia[2].txt
Spyware:Cookie/Serving-sys Not disinfected C:\Documents and Settings\James\Cookies\james@serving-sys[1].txt
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\James\Cookies\james@trafficmp[1].txt
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\James\Cookies\james@tribalfusion[1].txt
Potentially unwanted tool:Application/Zango Not disinfected C:\Documents and Settings\James\Local Settings\Temp\18029.tmp
Potentially unwanted tool:Application/KillApp.B Not disinfected C:\hp\bin\KillIt.exe
Potentially unwanted tool:Application/Zango Not disinfected C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
Potentially unwanted tool:Application/MyWebSearch Not disinfected C:\RECYCLER\S-1-5-21-2343245809-1059061656-4094759142-1008\Dc747.scr

Now, the truly frustrating part? I just cleared out my cookies.

erccseal
2006-11-30, 19:47
Logfile of HijackThis v1.99.1
Scan saved at 10:19:40 AM, on 11/30/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0011)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\ehome\RMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
c:\progra~1\intern~1\iexplore.exe
C:\WINDOWS\ehome\RMSysTry.exe
C:\Program Files\SBC Self Support Tool\bin\mpbtn.exe
C:\WINDOWS\system32\dwwin.exe
C:\WINDOWS\system32\dumprep.exe
C:\WINDOWS\system32\dwwin.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ycomp/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://yahoo.sbc.com/dsl
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ycomp/defaults/su/*http://www.yahoo.com
R3 - URLSearchHook: AOLTBSearch Class - {EA756889-2338-43DB-8F07-D1CA6FB9C90D} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: HP view - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\HPDTLK02.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [HP Component Manager] "c:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Grid Jump Cdrom Amen] C:\Documents and Settings\All Users\Application Data\DvdFlawGridJump\warnonce.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [ChicSpam] C:\DOCUME~1\HP_ADM~1\APPLIC~1\ADMINB~1\delete date pile.exe
O4 - Global Startup: AT&T Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: Extender Resource Monitor.lnk = C:\WINDOWS\ehome\RMSysTry.exe
O8 - Extra context menu item: &AOL Toolbar Search - res://c:\program files\aol\aol toolbar 2.0\aoltbhtml.dll/search.html
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJxdm035YYUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 2.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O16 - DPF: {01CA75F1-054B-4A63-9221-C6926369EC52} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/US/install.cab
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {3299935F-2C5A-499A-9908-95CFFF6EF8C1} (Quicksilver Class) - https://vapwda.ops.placeware.com/etc/place/DESK/VADpws-a3s/5.1.8.511/lib/quicksilver.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} (SysData Class) - http://ipgweb.cce.hp.com/rdqcpc/downloads/sysinfo.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by104fd.bay104.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {5AA5A569-F96F-4628-A528-8B3698F558BB} (HS_live Control) - http://install.homestead.com/~site/InstallFiles/SIFiles/lpxlive/HS_live.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1135103368468
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B49C4597-8721-4789-9250-315DFBD9F525} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/radio/ampx/ampx2.6.1.11_en_dl.cab
O16 - DPF: {D1ACD2D8-7312-4D06-BECD-90EB094D2277} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/aio/en/check/qdiagh.cab?326
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) - http://entimg.msn.com/client/msnmusax2622.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: hpdjaio - Unknown owner - C:\DOCUME~1\James\LOCALS~1\Temp\hpdjaio.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unknown owner - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Local Security Authority Subsystem Service (lsass) - Unknown owner - C:\WINDOWS\scvhost.exe (file missing)
O23 - Service: Pantech&Curitel Utility Service - Unknown owner - C:\Program Files\UTStarcom\Sprint\Sprint PCS Connection Manager\PnCUtilityService.exe (file missing)
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)

LonnyRJones
2006-12-06, 12:38
Welcome to the forum
Look in the windows control panel > addremove programs list for
"Search Plugin"
"Zone Media"
if either are there uninstall it then restart your PC

Post back with a new hijackthis log

LonnyRJones
2006-12-13, 13:30
Due to lack of responses this thread is closed
If you still need assistance a new log will be needed, send me or Tashi a PM (personal message) and we will re-open it.