Command Service help

Oh, nevermind. I was able to locate the backup files that each program saves on default. Here's the AVG log:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 11:19:42 PM 10/24/2006

+ Scan result:



C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054049.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\aff_0006.exe/AutoSearch.dll -> Adware.AutoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054076.dll -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054294.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP361\A0054688.exe -> Adware.CASClient : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\BattyRun2.dll -> Adware.CASClient : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054288.exe -> Adware.CommAd : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054620.dll -> Adware.CommAd : Cleaned with backup (quarantined).
C:\Program Files\DeluxeCommunications -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
C:\Program Files\DeluxeCommunications\bak -> Adware.DeluxeCommunications : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0052781.dll -> Adware.EZula : Cleaned with backup (quarantined).
C:\WINDOWS\motorsix.ocx -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\WINDOWS\unstall.exe -> Adware.MediaMotor : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054053.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP361\A0054685.dll -> Adware.Mirar : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0052814.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054042.exe -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINDOWS\MirarSetup_876057.exe -> Adware.SaveNow : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP363\A0055028.exe -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP363\A0055029.dll -> Adware.SurfSide : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP363\A0055025.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0052357.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053855.dll -> Adware.TrafficSol : Cleaned with backup (quarantined).
C:\WINDOWS\SYSTEM32\iifgfcd.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0052782.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0052783.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053841.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053844.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053845.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053846.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053847.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053848.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053850.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053851.exe -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053861.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP358\A0053862.dll -> Adware.WebHancer : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054065.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054067.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054068.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\WINDOWS\TIELT001.exe -> Adware.ZenoSearch : Cleaned with backup (quarantined).
C:\Documents and Settings\cheryl\Local Settings\Temporary Internet Files\Content.IE5\VLQULHAY\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Ignored.
C:\System Volume Information\_restore{46DE8921-1D39-44D2-A9E9-64119261F211}\RP359\A0054062.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Ignored.
C:\Documents and Settings\cheryl\Cookies\cheryl@247realmedia[1].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@247realmedia[2].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@247realmedia[3].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@247realmedia[4].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@247realmedia[5].txt -> TrackingCookie.247realmedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[10].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[11].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[12].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[13].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[14].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[15].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[16].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[17].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[18].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[19].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[20].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[21].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[22].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[23].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[24].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[25].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[26].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[27].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[28].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[29].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[30].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[31].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[32].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[33].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[34].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[35].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[36].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[37].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[38].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[3].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[4].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[5].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[6].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[7].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[8].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@2o7[9].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@americanexpress.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bookspan.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cnn.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cnn.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@coxhsi.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@dealnews.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@entrepreneur.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@harpo.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@highbeam.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hollywoodentertainment.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ldproducts.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@msnportal.112.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@nbcuniversal.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@nbcuniversal.122.2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@partygaming.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tcompany.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@wastatedor.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[3].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[4].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[5].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.addynamix[6].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@rotator.dex.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@rotator.dex.adjuggler[3].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@thunderbolt.adjuggler[1].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@thunderbolt.adjuggler[3].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@thunderbolt.adjuggler[4].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[10].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[12].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[5].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adrevolver[9].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[10].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[1].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[2].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[4].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[5].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[6].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[7].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[8].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@z1.adserver[9].txt -> TrackingCookie.Adserver : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adtech[2].txt -> TrackingCookie.Adtech : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[10].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[11].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[12].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[13].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[14].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[15].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[16].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[17].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[18].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[19].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[20].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[21].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[3].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[4].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[5].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[6].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[7].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[8].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@advertising[9].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@atdmt[4].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bfast[2].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bfast[3].txt -> TrackingCookie.Bfast : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[3].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[4].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[5].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[6].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bluestreak[7].txt -> TrackingCookie.Bluestreak : Cleaned.

Continued on next post:
 
C:\Documents and Settings\cheryl\Cookies\cheryl@citi.bridgetrack[1].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@citi.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@citi.bridgetrack[4].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@citi.bridgetrack[5].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[10].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[11].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[12].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[1].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[3].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[4].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[5].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[6].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[7].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[8].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstbeacon[9].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[10].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[12].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[4].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[5].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[6].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[7].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[8].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@burstnet[9].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[3].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[4].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[5].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[6].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[7].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[8].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@www.burstnet[9].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[10].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[11].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[1].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[3].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[4].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[5].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[6].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[7].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@casalemedia[8].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@com[1].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@com[3].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@commission-junction[2].txt -> TrackingCookie.Commission-junction : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@data.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@twci.coremetrics[1].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@twci.coremetrics[2].txt -> TrackingCookie.Coremetrics : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bilbo.counted[1].txt -> TrackingCookie.Counted : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bilbo.counted[2].txt -> TrackingCookie.Counted : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cpvfeed[3].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@doubleclick[3].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@c.enhance[1].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@c.enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.euroclick[1].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.euroclick[3].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@as-us.falkag[2].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[3].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[4].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[5].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[6].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[7].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@fastclick[8].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@media.fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@media.fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@media.fastclick[3].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@media.fastclick[4].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@media.fastclick[5].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@cityclub.gamingpromo[2].txt -> TrackingCookie.Gamingpromo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@gamingpromo[1].txt -> TrackingCookie.Gamingpromo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@c.goclick[1].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@c.goclick[3].txt -> TrackingCookie.Goclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-bestwestern.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-bestwestern.hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-bizjournals.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-comcast.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-comcast.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-darden.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-dig.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-dig.hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-hollywood.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-medtronic.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-pcsecurityshield.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-vigetlabs.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-vmware.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg.hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ehg.hitbox[4].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hg1.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[10].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[11].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[12].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[13].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[14].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[16].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[3].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[4].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[5].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[6].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[7].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[8].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@hitbox[9].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@counter.hitslink[1].txt -> TrackingCookie.Hitslink : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@linksynergy[1].txt -> TrackingCookie.Linksynergy : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@server.iad.liveperson[1].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@server.iad.liveperson[2].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@server.iad.liveperson[3].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@server.iad.liveperson[4].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@server.iad.liveperson[5].txt -> TrackingCookie.Liveperson : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@mediaplex[3].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@mediaplex[4].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@stat.onestat[2].txt -> TrackingCookie.Onestat : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@data2.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@data2.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@overture[3].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@overture[4].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@overture[6].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[10].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[11].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[12].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[13].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[14].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[15].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[16].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[17].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[18].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[19].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[20].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[21].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[22].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[23].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[24].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[26].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[3].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[4].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[5].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[6].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[7].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[8].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ads.pointroll[9].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@pro-market[2].txt -> TrackingCookie.Pro-market : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@qksrv[1].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@qksrv[2].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@qksrv[3].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@qksrv[4].txt -> TrackingCookie.Qksrv : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[10].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[11].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[12].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[13].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[14].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[15].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[16].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[17].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[18].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[19].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@questionmarket[20].txt -> TrackingCookie.Questionmarket : Cleaned.

Continued:
 
C:\Documents and Settings\cheryl\Cookies\cheryl@revenue[1].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@revenue[3].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[2].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[3].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[4].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[5].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[6].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[7].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[8].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@edge.ru4[9].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[3].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[4].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[5].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@bs.serving-sys[6].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[3].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[4].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[5].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[6].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[7].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[8].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@serving-sys[9].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[3].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[4].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[5].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[6].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[7].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@adopt.specificclick[8].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@h.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@try.starware[1].txt -> TrackingCookie.Starware : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[10].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[1].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[3].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[4].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[5].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[6].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[7].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statcounter[9].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anad.tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anad.tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anat.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@anat.tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[10].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[11].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[12].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[13].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[14].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[15].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[16].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[17].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[18].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[19].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[20].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[21].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[22].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[5].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[6].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[7].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[8].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tacoda[9].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@targetnet[2].txt -> TrackingCookie.Targetnet : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@trafficmp[3].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@trafficmp[5].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@trafficmp[6].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[10].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[11].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[3].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[4].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[5].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[6].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[7].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[8].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@tribalfusion[9].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@reduxads.valuead[1].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[10].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[11].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[12].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[13].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[14].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[3].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[4].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[5].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[6].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[7].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[8].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@statse.webtrendslive[9].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[3].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[4].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[5].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[6].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@ad.yieldmanager[8].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@c1.zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[10].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[11].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[12].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[13].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[14].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[15].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[16].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[17].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[18].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[20].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[21].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[22].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[23].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[24].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[3].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[4].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[5].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[6].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[7].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[8].txt -> TrackingCookie.Zedo : Cleaned.
C:\Documents and Settings\cheryl\Cookies\cheryl@zedo[9].txt -> TrackingCookie.Zedo : Cleaned.


::Report end
 
And here's the HJT log:

Logfile of HijackThis v1.99.1
Scan saved at 11:27:05 PM, on 10/24/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
c:\windows\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\hijackthis\Sunflash2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dell.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\mbjcohlm.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: (no name) - {4d62db20-b5ff-4199-9666-b44e12c67d6a} - C:\WINDOWS\system32\CSS591.dll
O2 - BHO: (no name) - {5CBE8308-7437-4218-9EDF-76B0CC9A0D05} - C:\WINDOWS\system32\jkklj.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [CW] "C:\Program Files\CW4\cw4.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [venf449c] RUNDLL32.EXE w19b254e.dll,n 005f44970000001219b254e
O4 - HKLM\..\Run: [{68-81-17-7E-ZN}] C:\windows\system32\ojdsregm.exe ELT001
O4 - HKLM\..\Run: [ms05605186-1338] C:\WINDOWS\ms05605186-1338.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} - http://vs.mcafeeasap.com/MC/ENU/VS40/bin/myCioAgt.20060504175614.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = KitsapPayroll.local
O17 - HKLM\Software\..\Telephony: DomainName = KitsapPayroll.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = KitsapPayroll.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.0.0792.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.0.0792.00.dll
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: awvtr - awvtr.dll (file missing)
O20 - Winlogon Notify: CSS591 - C:\WINDOWS\SYSTEM32\CSS591.dll
O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkklj - C:\WINDOWS\system32\jkklj.dll (file missing)
O21 - SSODL: B0DGIBHE - {1431317B-4B9E-24A3-6AF8-0CBB4E634506} - C:\WINDOWS\system32\Lkkbda32.dll (file missing)
O21 - SSODL: mtklefap - {1522EB60-18DF-4E9A-4993-92BAA694032F} - (no file)
O21 - SSODL: mtklefa - {333A83B4-46A3-472B-C684-46DC29992870} - C:\WINDOWS\system32\ormhm32.dll (file missing)
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINDOWS\system32\gnbfgbei.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe
 
Thanks for returning the information, however we have these two problems.

1) The log was run in safe mode, post all logs in Normal Mode unless I request otherwise.

2) You are running MSCONFIG in Selective Startup. I must see the logs with everything enabled. Return to MSConfig (Start > Run > type msconfig then ok. Click the Startup tab, then the Enable All button. Then Apply and OK your way out. You can return to Selective Startup to save your resources when your computer is clean.

**we have a lot of work to do, I am choosing the less complex methods to make it easier on you. You must read the instructions and follow it carefully, print the instructions if it helps. If there is something you do not understand, post to ask. Anything you think I should know, post it for me.
You need to keep this infected machine offline until we get it cleaned up, the junk will attract more. Let's proceed like this.

3) How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

4) Please download ATF Cleaner by Atribune
http://www.atribune.org/content/view/25/2/
Save it to your Desktop. We will use this later.

5) Thanks to Atribune and any others who helped with this fix. You may have to run this fix several times, you wat all of the files it located to be deleted.

Please download VundoFix.exe to your desktop
  • Double-click VundoFix.exe to run it.
  • Click the Scan for Vundo button.
  • Once it's done scanning, click the Remove Vundo button.
  • You will receive a prompt asking if you want to remove the files, click YES
  • Once you click yes, your desktop will go blank as it starts removing Vundo.
  • When completed, it will prompt that it will reboot your computer, click OK.
  • Please post the contents of C:\vundofix.txt and a new HiJackThis log in a reply to this thread.
Note: It is possible that VundoFix encountered a file it could not remove. In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button" when VundoFix appears upon rebooting.

If there is a file VundoFix doesn't find we need it submitted. Please submit
the files to upload malware http://www.uploadmalware.com

(Save the reports until you are finished the instructions)

6) Start > Control Panel > Add Remove programs and uninstall VSToolbar and MyWaySearch if there. Also uninstall any other program you know do not belong there. If you are not sure, let me know and I will look.

7) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: (no name) - {1DAEFCB9-06C8-47c6-8F20-3FB54B244DAA} - C:\WINDOWS\system32\mbjcohlm.dll
O2 - BHO: (no name) - {4d62db20-b5ff-4199-9666-b44e12c67d6a} - C:\WINDOWS\system32\CSS591.dll
O2 - BHO: (no name) - {5CBE8308-7437-4218-9EDF-76B0CC9A0D05} - C:\WINDOWS\system32\jkklj.dll (file missing)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll
O4 - HKLM\..\Run: [venf449c] RUNDLL32.EXE w19b254e.dll,n 005f44970000001219b254e
O4 - HKLM\..\Run: [{68-81-17-7E-ZN}] C:\windows\system32\ojdsregm.exe ELT001 G
O4 - HKLM\..\Run: [ms05605186-1338] C:\WINDOWS\ms05605186-1338.exe
O20 - AppInit_DLLs: dxclib303562752.dll
O20 - Winlogon Notify: awvtr - awvtr.dll (file missing)
O20 - Winlogon Notify: CSS591 - C:\WINDOWS\SYSTEM32\CSS591.dll
O20 - Winlogon Notify: dvd4free - dvd4free.dll (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: jkklj - C:\WINDOWS\system32\jkklj.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

8) RIGHT Click on Start then click on Explore. Locate and delete these itemsif they are there. Do not miss them.

C:\windows\system32\ojdsregm.exe <<< delete that file

C:\WINDOWS\ms05605186-1338.exe <<< delete that file

C:\Program Files\MyWaySearch\ <<< delete that folder

C:\Program Files\VSToolbar\ <<< delete that folder

9) Run ATF Cleaner
Double-click ATF-Cleaner.exe to run the program.
Click Select All found at the bottom of the list.
Click the Empty Selected button.
Click Exit on the Main menu to close the program.

Restart the computer and post the vundofix.txt, a new HJT log and any comments you think will help. Make sure that HJT log is posted with everything enabled in MSConfig and in Normal Mode.

Thanks
 
Ok, I've finished it all. Tell me if this works.

NOTES:

1) When removing the items you told me with Hijackthis.exe, I didn't find the following:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://bfc.myway.com/search/de_srchlft.html
R3 - URLSearchHook: (no name) - {4D25F926-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O3 - Toolbar: &VSToolBar - {821F87FF-8245-4972-9E28-732E92EC2F51} - C:\Program Files\VSToolbar\VSToolBar.dll

2) When deleting the 2 files and 2 folders you told me to get, I only found the two folders. I couldn't locate either of the files.

3) When removing the programs, I successfully uninstalled VSToolbar, however, When I tried to delete the program MyWay Search Assistant Windows returned an error saying "Error: [path]. Module could not be located." So that application hasn't been removed.



Here is the VundoFix.exe log:


VundoFix V6.2.6

Checking Java version...

Java version is 1.4.2.3

Java version is 1.5.0.6

Scan started at 19:08:58 06-10-25

Listing files found while scanning....

C:\WINDOWS\SYSTEM32\mbjcohlm.dll
C:\WINDOWS\SYSTEM32\adqibqai.exe
C:\WINDOWS\system32\jkklj.dll
C:\WINDOWS\system32\jlkkj.ini
C:\WINDOWS\system32\jlkkj.bak1
C:\WINDOWS\system32\jlkkj.bak2

Beginning removal...

Attempting to delete C:\WINDOWS\SYSTEM32\mbjcohlm.dll
C:\WINDOWS\SYSTEM32\mbjcohlm.dll Has been deleted!

Attempting to delete C:\WINDOWS\SYSTEM32\adqibqai.exe
C:\WINDOWS\SYSTEM32\adqibqai.exe Has been deleted!

Attempting to delete C:\WINDOWS\system32\jlkkj.ini
C:\WINDOWS\system32\jlkkj.ini Has been deleted!

Attempting to delete C:\WINDOWS\system32\jlkkj.bak1
C:\WINDOWS\system32\jlkkj.bak1 Has been deleted!

Attempting to delete C:\WINDOWS\system32\jlkkj.bak2
C:\WINDOWS\system32\jlkkj.bak2 Has been deleted!

Performing Repairs to the registry.
Done!


The HJT log is in the next post:
 
Logfile of HijackThis v1.99.1
Scan saved at 19:47, on 06-10-25
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\WINDOWS\system32\imapi.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTBCM\Binn\sqlservr.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijackthis\Sunflash4.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: (no name) - {4d62db20-b5ff-4199-9666-b44e12c67d6a} - C:\WINDOWS\system32\CSS591.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.03.0000.1005\en-xu\stmain.dll
O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.5000.1021\en-us\msntb.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKLM\..\Run: [CW] "C:\Program Files\CW4\cw4.exe"
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [QBReminderFlash] "C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe"
O4 - HKLM\..\Run: [OSCD_Creator] c:\Dell\PreODM.EXE
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\RunOnce: [OSCD_Creator] C:\Dell\PreODM.EXE /2
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: UPS OnLine PLD Reminder Utility.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.mcafeeasap.com
O15 - Trusted Zone: *.sxload.com
O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://www.drivecleaner.com/.freeware/installdrivecleanerstart.cab
O16 - DPF: {40C83AF8-FEA7-4A6A-A470-431EE84A0886} - http://vs.mcafeeasap.com/MC/ENU/VS40/bin/myCioAgt.20060504175614.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = KitsapPayroll.local
O17 - HKLM\Software\..\Telephony: DomainName = KitsapPayroll.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = KitsapPayroll.local
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.0.0792.00.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSN Messenger\msgrapp.8.0.0792.00.dll
O20 - Winlogon Notify: CSS591 - C:\WINDOWS\SYSTEM32\CSS591.dll
O21 - SSODL: B0DGIBHE - {1431317B-4B9E-24A3-6AF8-0CBB4E634506} - C:\WINDOWS\system32\Lkkbda32.dll (file missing)
O21 - SSODL: mtklefap - {1522EB60-18DF-4E9A-4993-92BAA694032F} - (no file)
O21 - SSODL: mtklefa - {333A83B4-46A3-472B-C684-46DC29992870} - C:\WINDOWS\system32\ormhm32.dll (file missing)
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINDOWS\system32\gnbfgbei.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LicCtrl Service (LicCtrlService) - Unknown owner - C:\WINDOWS\runservice.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\Mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\VsTskMgr.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe



Thanks for your help:-)
-Sunflash
 
Thanks for the feedback, I notice you are running old versions of Java and if I mentioned this earlier, I apologize, I am helping a let of folks. See this information:
http://forums.spybot.info/showpost.php?p=12880&postcount=2
Follow those instructions to uninstall all old versons of Java, they will get you infected, make sure you are running the newest version.
http://javatester.org/version.html
http://www.java.com/en/download/installed.jsp

Having a look at the HJT log, do you have anyone in the house that can help you with this job? I have had issues with you being able to use the tools and follow the directions. I am going to attempt to continue, but things are not going real well at present.

The first thing I want you to do is follow the directions in item number three (3) It appears the Guard function is running in AVG Anti-Spyware:
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe and that is blocking the registry changes we must make.

http://www.virusvault.co.uk/fusionbb/showtopic.php?tid/33/

Deactivate the Resident Shield
- Before proceeding, deactivate the "Resident Shield" as this may prevent changes to the registry.
- To do this, click "Change State" to the right of the Resident Shield option in the main window.
- You will clearly see the status change to Inactive if you have done this correctly.
If we have to we will uninstall the program later. Look at a HJT log and make sure that Guard.exe is no longer running.
____________________________________________________

Next we have this that looks like it is a Vundo trojan:
O2 - BHO: (no name) - {4d62db20-b5ff-4199-9666-b44e12c67d6a} - C:\WINDOWS\system32\CSS591.dll
O20 - Winlogon Notify: CSS591 - C:\WINDOWS\SYSTEM32\CSS591.dll
We will tackle it in a bit, but I want to be sure that file: CSS591.dll gets uploaded to Atribune, follow these instructions:

If there is a file VundoFix doesn't find we need it submitted. Please submit
the files to upload malware http://www.uploadmalware.com

Make sure your hidden files and folders are showing:
How to make files and folders visible:
Click Start > Open My Computer.
Select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, select Show hidden files and folders.
Uncheck: Hide file extensions for known file types
Uncheck the Hide protected operating system files (recommended) option.
Click Yes to confirm.
Click OK.

Understand that HJT will remove about all of this junk if you have followed the directions. If it does not, then Uninstall AVG Anti-Spyware and try again.

Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

O2 - BHO: (no name) - {4D25F921-B9FE-4682-BF72-8AB8210D6D75} - C:\Program Files\MyWaySA\SrchAsDe\1.bin\deSrcAs.dll (file missing)
O2 - BHO: (no name) - {4d62db20-b5ff-4199-9666-b44e12c67d6a} - C:\WINDOWS\system32\CSS591.dll
O4 - Startup: TA_Start.lnk = C:\WINDOWS\SYSTEM32\dwdsregt.exe
O15 - Trusted Zone: *.dollarrevenue.com
O15 - Trusted Zone: *.elitemediagroup.net
O15 - Trusted Zone: *.mcafeeasap.com
O15 - Trusted Zone: *.sxload.com
O20 - Winlogon Notify: CSS591 - C:\WINDOWS\SYSTEM32\CSS591.dll
O21 - SSODL: B0DGIBHE - {1431317B-4B9E-24A3-6AF8-0CBB4E634506} - C:\WINDOWS\system32\Lkkbda32.dll (file missing)
O21 - SSODL: mtklefap - {1522EB60-18DF-4E9A-4993-92BAA694032F} - (no file)
O21 - SSODL: mtklefa - {333A83B4-46A3-472B-C684-46DC29992870} - C:\WINDOWS\system32\ormhm32.dll (file missing)
O21 - SSODL: SysTray.Exmr - {73F8D5FF-6F5C-4f5b-B964-E6F214F6F852} - C:\WINDOWS\system32\gnbfgbei.dll (file missing)

Close all programs but HJT and all browser windows, then click on "Fix Checked"

Look for these files and delete them if you find them. They may be gone just DO NOT miss them.

C:\WINDOWS\SYSTEM32\dwdsregt.exe <<< delete this file
C:\WINDOWS\system32\CSS591.dll <<< delete this file, if you can not, tell me why.

Run ATF-Cleaner and then restart the computer. Post a new HJT log.

Thanks
 
Ok, I'll do that when I get home from school. In regard to the Gaurd.exe program running, I have deactivated the Shield, but it must have ben reactivated when I restarted the computer.
 
Due to lack of responses this thread is closed
If you still need assistance a new log will be needed, send me or Tashi a PM (personal message) and we will re-open it.
 
Back
Top