Mysticbear
New member
Okay.....
I couldn't delete this file:
c:\documents and settings\default\start menu\programs\startup\winlogon.lnk (may not have that .lnk but delete if you find just winlogon)
I couldn't find it anywhere....
My sound was lost somethime in during the virus cleanup.
I don't know how to update my audio drivers so I have yet to try that, if you could give me some info that would be great!
Also here are the reports:
Logfile of HijackThis v1.99.1
Scan saved at 6:29:09 PM, on 1/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HJT\HJT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\WUTemp\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [AcctMgr] "C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe" /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.2480\GoogleToolbarNotifier.exe"
O4 - Startup: winlogon.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O23 - Service: 01Apache - Unknown owner - C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe" --ntservice (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
And the other:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:24:08 PM 1/19/2007
+ Scan result:
C:\Program Files\PeDevice\PeDev.dll -> Adware.Delfin : Cleaned.
C:\Documents and Settings\Mom and Dad\DoctorWeb\Quarantine\ipwins.dll -> Adware.Maxifiles : Cleaned.
C:\WINDOWS\system32\e9nrl8rc.exe -> Adware.SAHAgent : Cleaned.
C:\Documents and Settings\Mom and Dad\Local Settings\Temporary Internet Files\Content.IE5\FY5IS86J\callme.nm[1] -> Not-A-Virus.Exploit.HTML.VML.b : Cleaned.
C:\RECYCLER\NPROTECT\00136721.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00136729.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00136847.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00137686.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\RECYCLER\NPROTECT\00136835.TXT -> TrackingCookie.Atdmt : Cleaned.
C:\RECYCLER\NPROTECT\00137702.TXT -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\RECYCLER\NPROTECT\00136705.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136706.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136707.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136708.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136709.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136710.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136711.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136712.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136713.TXT -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136737.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136738.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136739.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136740.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136837.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136838.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136839.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00137689.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136899.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00136900.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00137684.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00136692.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136693.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136694.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136695.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136696.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136697.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136700.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136701.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136702.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136703.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136704.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136747.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136748.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136749.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136750.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136751.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136752.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136753.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136754.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136755.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136756.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136757.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136758.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136759.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136760.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136761.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136762.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136763.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136764.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136834.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00137691.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136805.TXT -> TrackingCookie.Sidefind : Cleaned.
C:\RECYCLER\NPROTECT\00137697.TXT -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\NPROTECT\00137696.TXT -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
THank you for you help I really appreciate it!!!!
I couldn't delete this file:
c:\documents and settings\default\start menu\programs\startup\winlogon.lnk (may not have that .lnk but delete if you find just winlogon)
I couldn't find it anywhere....
My sound was lost somethime in during the virus cleanup.
I don't know how to update my audio drivers so I have yet to try that, if you could give me some info that would be great!
Also here are the reports:
Logfile of HijackThis v1.99.1
Scan saved at 6:29:09 PM, on 1/19/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe
C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Java\jre1.5.0_04\bin\jucheck.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\HJT\HJT.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [OpwareSE2] "C:\Program Files\ScanSoft\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\WUTemp\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe"
O4 - HKLM\..\Run: [AcctMgr] "C:\Program Files\Norton SystemWorks\Password Manager\AcctMgr.exe" /startup
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.2480\GoogleToolbarNotifier.exe"
O4 - Startup: winlogon.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) - http://support.f-secure.com/ols/fscax.cab
O23 - Service: 01Apache - Unknown owner - C:\PROGRA~1\01COM~1\WEBSER~1\Apache.exe" --ntservice (file missing)
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~4\GHOSTS~2.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
And the other:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 6:24:08 PM 1/19/2007
+ Scan result:
C:\Program Files\PeDevice\PeDev.dll -> Adware.Delfin : Cleaned.
C:\Documents and Settings\Mom and Dad\DoctorWeb\Quarantine\ipwins.dll -> Adware.Maxifiles : Cleaned.
C:\WINDOWS\system32\e9nrl8rc.exe -> Adware.SAHAgent : Cleaned.
C:\Documents and Settings\Mom and Dad\Local Settings\Temporary Internet Files\Content.IE5\FY5IS86J\callme.nm[1] -> Not-A-Virus.Exploit.HTML.VML.b : Cleaned.
C:\RECYCLER\NPROTECT\00136721.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00136729.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00136847.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\RECYCLER\NPROTECT\00137686.TXT -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\RECYCLER\NPROTECT\00136835.TXT -> TrackingCookie.Atdmt : Cleaned.
C:\RECYCLER\NPROTECT\00137702.TXT -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\RECYCLER\NPROTECT\00136705.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136706.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136707.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136708.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136709.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136710.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136711.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136712.TXT -> TrackingCookie.Falkag : Cleaned.
C:\RECYCLER\NPROTECT\00136713.TXT -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136737.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136738.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136739.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136740.TXT -> TrackingCookie.Fastclick : Cleaned.
C:\RECYCLER\NPROTECT\00136837.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136838.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136839.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00137689.TXT -> TrackingCookie.Linksynergy : Cleaned.
C:\RECYCLER\NPROTECT\00136899.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00136900.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00137684.TXT -> TrackingCookie.Liveperson : Cleaned.
C:\RECYCLER\NPROTECT\00136692.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136693.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136694.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136695.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136696.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136697.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136700.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136701.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136702.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136703.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136704.TXT -> TrackingCookie.Paypopup : Cleaned.
C:\RECYCLER\NPROTECT\00136747.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136748.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136749.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136750.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136751.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136752.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136753.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136754.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136755.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136756.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136757.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136758.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136759.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136760.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136761.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136762.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136763.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136764.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136834.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00137691.TXT -> TrackingCookie.Shopathomeselect : Cleaned.
C:\RECYCLER\NPROTECT\00136805.TXT -> TrackingCookie.Sidefind : Cleaned.
C:\RECYCLER\NPROTECT\00137697.TXT -> TrackingCookie.Sidefind : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\RECYCLER\NPROTECT\00137696.TXT -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\Mom and Dad\Cookies\mom and dad@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
THank you for you help I really appreciate it!!!!
