Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: New thread as requested  (Read 8762 times)

0 Members and 1 Guest are viewing this topic.

Brian Keith

    Topic Starter


    Greenhorn

    • Computer: Specs
    • Experience: Beginner
    • OS: Windows XP
    New thread as requested
    « on: September 23, 2011, 01:08:38 PM »
    here is the new thread that you requested...I appreciate your assisitance very much

    SUPERAntiSpyware Scan Log
    http://www.superantispyware.com

    Generated 09/23/2011 at 02:07 PM

    Application Version : 5.0.1118

    Core Rules Database Version : 7719
    Trace Rules Database Version: 5531

    Scan type       : Complete Scan
    Total Scan Time : 01:51:24

    Operating System Information
    Windows XP Home Edition 32-bit, Service Pack 3 (Build 5.01.2600)
    Administrator

    Memory items scanned      : 549
    Memory threats detected   : 0
    Registry items scanned    : 37798
    Registry threats detected : 0
    File items scanned        : 98956
    File threats detected     : 254

    Adware.Tracking Cookie
       .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .imrworldwide.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       user.lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .specificmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .lfstmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       tracking.servedbyy.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.dealfind.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .dealfind.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .dealfind.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .dealfind.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .eyewonder.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .richmedia.yahoo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.clickmanage.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.clickmanage.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .technoratimedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .technoratimedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .technoratimedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .technoratimedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .technoratimedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adxpose.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .trafficregenerator.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .trafficregenerator.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.trackjax.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .vyvanseadult.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .vyvanseadult.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .vyvanseadult.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .vyvanseadult.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .lfstmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .kennedy.clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .kennedy.clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .kennedy.clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickbook.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .atdmt.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .atdmt.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .mediaplex.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .doubleclick.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .geconsumerfinance.112.2o7.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .trafficmp.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .specificclick.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .t.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adserver.adtechus.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .serving-sys.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .getclicky.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .static.getclicky.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .doubleclick.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       in.getclicky.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .legolas-media.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .bs.serving-sys.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .lfstmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .apmebf.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .pro-market.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .247realmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .traveladvertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .realmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .intermundomedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .intermundomedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .intermundomedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adserver.adtechus.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .collective-media.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .revsci.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .revsci.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .questionmarket.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .revsci.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .revsci.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .revsci.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ru4.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .content.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .casalemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .trafficmp.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .trafficmp.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .doubleclick.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       lyricfind.rotator.hadj7.adjuggler.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       lyricfind.rotator.hadj7.adjuggler.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       lyricfind.rotator.hadj7.adjuggler.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       lyricfind.rotator.hadj7.adjuggler.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       lyricfind.rotator.hadj7.adjuggler.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       rotator.adjuggler.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       rotator.adjuggler.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .clickfuse.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       statse.webtrendslive.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .mediaplex.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .questionmarket.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .questionmarket.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ads.bridgetrack.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ads.bridgetrack.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ads.bridgetrack.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .mediaplex.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .insightexpressai.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .eyewonder.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adtech.de [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .popcapgames.122.2o7.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .eyewonder.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .eyewonder.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .accounts.google.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .accounts.google.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .accounts.google.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       sales.liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .serving-sys.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .serving-sys.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .serving-sys.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .traveladvertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .traveladvertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adserver.adtechus.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .mediabrandsww.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .yieldmanager.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .r1-ads.ace.advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       www.googleadservices.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       sftrack.searchforce.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       sales.liveperson.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .lucidmedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .tribalfusion.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .zedo.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .content.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .fastclick.net [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .ads.pointroll.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .invitemedia.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .advertising.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       eas.apm.emediate.eu [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       eas.apm.emediate.eu [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       eas.apm.emediate.eu [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .media6degrees.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       ad.yieldmanager.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .a1.interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .interclick.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       .adbrite.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       accounts.google.com [ C:\DOCUMENTS AND SETTINGS\RACHEL\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\OKGVDO60.DEFAULT\COOKIES.SQLITE ]
       C:\DOCUMENTS AND SETTINGS\RACHEL\COOKIES\RACHEL@ACCOUNTS[2].TXT
       C:\DOCUMENTS AND SETTINGS\RACHEL\COOKIES\[email protected][1].TXT
       C:\DOCUMENTS AND SETTINGS\RACHEL\COOKIES\[email protected][1].TXT


    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 7765

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    9/23/2011 2:37:45 PM
    mbam-log-2011-09-23 (14-37-45).txt

    Scan type: Quick scan
    Objects scanned: 222077
    Time elapsed: 13 minute(s), 19 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    (No malicious items detected)

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 3:02:45 PM, on 9/23/2011
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    C:\Program Files\Common Files\Motive\McciCMService.exe
    C:\Program Files\Google\Update\GoogleUpdate.exe
    C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    C:\Program Files\McAfee Online Backup\MOBKbackup.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
    C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
    C:\Program Files\McAfee\VirusScan\mcods.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\WINDOWS\PixArt\PAC7302\Monitor.exe
    C:\Program Files\Dell Support Center\bin\sprtcmd.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\Common Files\Java\Java Update\jusched.exe
    C:\PROGRA~1\COMMON~1\AOL\120853~1\EE\AOLHOS~1.EXE
    C:\Program Files\ATT-SST\McciTrayApp.exe
    C:\PROGRA~1\COMMON~1\AOL\120853~1\EE\AOLServiceHost.exe
    C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
    C:\program files\real\realplayer\update\realsched.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
    C:\Program Files\McAfee\MAT\McPvTray.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
    c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Program Files\Mozilla Firefox\plugin-container.exe
    C:\Program Files\Internet Explorer\IEXPLORE.EXE
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://att.net
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://att.net
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.crawler.com/search/ie.aspx?tb_id=60347
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = http://dnl.crawler.com/support/sa_customize.aspx?TbId=60347
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://downloads.yahoo.com/p/att/ie/welcome
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: YSPManager - {25BC7718-0BFA-40EA-B381-4B2D9732D686} - C:\Program Files\Yahoo!\Search Protection\ysp.dll
    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
    O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20110919222229.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
    O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
    O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\YTSingleInstance.dll
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
    O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1208536966\EE\AOLHostManager.exe
    O4 - HKLM\..\Run: [PAC7302_Monitor] C:\WINDOWS\PixArt\PAC7302\Monitor.exe
    O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [ATT-SST_McciTrayApp] "C:\Program Files\ATT-SST\McciTrayApp.exe"
    O4 - HKLM\..\Run: [ISW.exe] "C:\Program Files\AT&T\Internet Security Wizard\ISW.exe" /AUTORUN
    O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
    O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe"  -osboot
    O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
    O4 - HKLM\..\Run: [McPvTray_exe] "C:\Program Files\McAfee\MAT\McPvTray.exe"
    O4 - HKLM\..\Run: [StartNowToolbarHelper] "C:\Program Files\StartNow Toolbar\ToolbarHelper.exe"
    O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
    O4 - HKCU\..\Run: [cdloader] "C:\Documents and Settings\Brian\Application Data\mjusbsp\cdloader2.exe" MAGICJACK
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    O8 - Extra context menu item: Google Sidewiki... - res://C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\WINDOWS\system32\shdocvw.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Rachel\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O15 - Trusted Zone: http://*.mcafee.com
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
    O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\mcsniepl.dll
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
    O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe
    O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files\McAfee Security Scan\2.0.181\McCHSvc.exe
    O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
    O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
    O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
    O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
    O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
    O23 - Service: McAfee Online Backup (MOBKbackup) - McAfee, Inc. - C:\Program Files\McAfee Online Backup\MOBKbackup.exe
    O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: Updater Service for StartNow Toolbar - Unknown owner - C:\Program Files\StartNow Toolbar\ToolbarUpdaterService.exe (file missing)
    O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

    --
    End of file - 13497 bytes

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: New thread as requested
    « Reply #1 on: September 23, 2011, 07:13:43 PM »
    Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

    1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
    2. The fixes are specific to your problem and should only be used for this issue on this machine.
    3. If you don't know or understand something, please don't hesitate to ask.
    4. Please DO NOT run any other tools or scans while I am helping you.
    5. It is important that you reply to this thread. Do not start a new topic.
    6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
    7. Absence of symptoms does not mean that everything is clear.

    If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
    *************************************************************************

    What sort of problems are you having?

    Open HijackThis and select Do a system scan only

    Place a check mark next to the following entries: (if there)

    O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - (no file)
    O2 - BHO: (no name) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - (no file)
    O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
    O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
    O4 - HKLM\..\Run: [TkBellExe] "C:\program files\real\realplayer\update\realsched.exe"  -osboot
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Rachel\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
    O15 - Trusted Zone: http://*.mcafee.com


    Important: Close all open windows except for HijackThis and then click Fix checked.

    Once completed, exit HijackThis.
    *****************************************

    Download DDS from HERE or HERE and save it to your desktop.

    Vista users right click on dds and select Run as administrator (you will receive a UAC prompt, please allow it)

    * XP users Double click on dds to run it.
    * If your antivirus or firewall try to block DDS then please allow it to run.
    * When finished DDS will open two (2) logs.
    * Save both reports to your desktop.
    * The instructions here ask you to attach the Attach.txt.



    1) DDS.txt
    2) Attach.txt
    Instead of attaching, please copy/past both logs into your Thread

    Note: DDS will instruct you to post the Attach.txt log as an attachment.
    Please just post it as you would any other log by copying and pasting it into the reply.

    •Close the program window, and delete the program from your desktop.

    Please note: You may have to disable any script protection running if the scan fails to run.
    After downloading the tool, disconnect from the internet and disable all antivirus protection.
    Run the scan, enable your A/V and reconnect to the internet.
    Information on A/V control HERE .Then post your DDS logs. (DDS.txt and Attach.txt )
    Windows 8 and Windows 10 dual boot with two SSD's

    Brian Keith

      Topic Starter


      Greenhorn

      • Computer: Specs
      • Experience: Beginner
      • OS: Windows XP
      Re: New thread as requested
      « Reply #2 on: September 24, 2011, 05:40:53 PM »
      Whats happening now is that when I use the search engine ....first it takes me to the directory and when I cliclk on the desired link I am redirected to a dangerous site , I close that window and click the link again and then I am taken to the correct place. it all began with a bogus Harddrive crash warning..I restored to the day before the infection .the tool bar kept reverting back to an unfamiliar setup, then i would reinstall foxfire again..same story..

      Thank you again...
      here are the recent logs requested

      DDS (Ver_2011-08-26.01) - NTFSx86
      Internet Explorer: 8.0.6001.18702  BrowserJavaVersion: 10.0.0
      Run by Brian at 15:33:03 on 2011-09-24
      Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1982.939 [GMT -4:00]
      .
      AV: McAfee Anti-Virus and Anti-Spyware *Enabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
      FW: McAfee Firewall *Enabled*
      .
      ============== Running Processes ===============
      .
      C:\WINDOWS\system32\svchost.exe -k DcomLaunch
      svchost.exe
      C:\WINDOWS\System32\svchost.exe -k netsvcs
      C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
      svchost.exe
      svchost.exe
      C:\WINDOWS\system32\spoolsv.exe
      svchost.exe
      C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
      C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
      C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
      C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
      C:\Program Files\Common Files\Motive\McciCMService.exe
      C:\Program Files\Google\Update\GoogleUpdate.exe
      C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
      C:\Program Files\McAfee Online Backup\MOBKbackup.exe
      C:\WINDOWS\system32\nvsvc32.exe
      C:\Program Files\Dell Support Center\bin\sprtsvc.exe
      C:\WINDOWS\system32\svchost.exe -k imgsvc
      C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
      C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe
      c:\PROGRA~1\mcafee\msc\mcupdmgr.exe
      C:\Program Files\McAfee Online Backup\MOBKbackup.exe
      C:\WINDOWS\Explorer.EXE
      C:\WINDOWS\system32\RUNDLL32.EXE
      C:\WINDOWS\RTHDCPL.EXE
      C:\WINDOWS\PixArt\PAC7302\Monitor.exe
      C:\Program Files\Dell Support Center\bin\sprtcmd.exe
      C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
      C:\Program Files\QuickTime\qttask.exe
      C:\Program Files\Common Files\Java\Java Update\jusched.exe
      C:\Program Files\ATT-SST\McciTrayApp.exe
      C:\Program Files\AT&T\Internet Security Wizard\ISW.exe
      C:\Program Files\McAfee.com\Agent\mcagent.exe
      C:\PROGRA~1\COMMON~1\AOL\120853~1\EE\AOLHOS~1.EXE
      C:\PROGRA~1\COMMON~1\AOL\120853~1\EE\AOLServiceHost.exe
      C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
      C:\Program Files\McAfee\MAT\McPvTray.exe
      C:\WINDOWS\system32\ctfmon.exe
      C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
      C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
      C:\Program Files\HP\hpcoretech\comp\hptskmgr.exe
      C:\Program Files\Mozilla Firefox\firefox.exe
      C:\Program Files\Mozilla Firefox\plugin-container.exe
      .
      ============== Pseudo HJT Report ===============
      .
      uStart Page = hxxp://att.net
      uSearch Page =
      uWindow Title = Windows Internet Explorer provided by Yahoo!
      uDefault_Page_URL = hxxp://att.net
      mSearch Bar = hxxp://www.google.com/ie
      uSearchAssistant =
      mSearchAssistant =
      uURLSearchHooks: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
      BHO: &Yahoo! Toolbar Helper: {02478d38-c3f9-4efb-9b51-7695eca05670} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
      BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
      BHO: Yahooo Search Protection: {25bc7718-0bfa-40ea-b381-4b2d9732d686} - c:\program files\yahoo!\search protection\ysp.dll
      BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\ie\rpbrowserrecordplugin.dll
      BHO: scriptproxy: {7db2d5a0-7241-4e79-b68d-6309f01c5231} - c:\program files\common files\mcafee\systemcore\ScriptSn.20110919222229.dll
      BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
      BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll
      BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre7\bin\jp2ssv.dll
      BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
      BHO: SingleInstance Class: {fdad4da1-61a2-4fd8-9c17-86f7ac245081} - c:\program files\yahoo!\companion\installs\cpn1\YTSingleInstance.dll
      TB: Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} - c:\program files\yahoo!\companion\installs\cpn1\yt.dll
      TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
      TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
      TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
      uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
      uRun: [cdloader] "c:\documents and settings\brian\application data\mjusbsp\cdloader2.exe" MAGICJACK
      uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
      uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe
      mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
      mRun: [nwiz] nwiz.exe /install
      mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
      mRun: [RTHDCPL] RTHDCPL.EXE
      mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
      mRun: [HostManager] c:\program files\common files\aol\1208536966\ee\AOLHostManager.exe
      mRun: [PAC7302_Monitor] c:\windows\pixart\pac7302\Monitor.exe
      mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter
      mRun: [HP Software Update] "c:\program files\hp\hp software update\HPWuSchd2.exe"
      mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
      mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
      mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
      mRun: [ATT-SST_McciTrayApp] "c:\program files\att-sst\McciTrayApp.exe"
      mRun: [ISW.exe] "c:\program files\at&t\internet security wizard\ISW.exe" /AUTORUN
      mRun: [mcui_exe] "c:\program files\mcafee.com\agent\mcagent.exe" /runkey
      mRun: [HP Component Manager] "c:\program files\hp\hpcoretech\hpcmpmgr.exe"
      mRun: [McPvTray_exe] "c:\program files\mcafee\mat\McPvTray.exe"
      StartupFolder: c:\docume~1\brian\startm~1\programs\startup\onenot~1.lnk - c:\program files\microsoft office\office12\ONENOTEM.EXE
      IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000
      IE: Google Sidewiki... - c:\program files\google\google toolbar\component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
      IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
      IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
      IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\progra~1\micros~3\office12\ONBttnIE.dll
      IE: {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}
      IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL
      Trusted Zone: 0.0.0.0
      Trusted Zone: internet
      Trusted Zone: mcafee.com
      Trusted Zone: motive.com\patttbc.att
      DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204
      DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - hxxp://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cab
      DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
      DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/polarbear/ultrashim.cab
      DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
      DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab
      DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
      TCP: DhcpNameServer = 192.168.1.254
      TCP: Interfaces\{CE3727FC-91A7-436C-97BD-52680745289A} : DhcpNameServer = 192.168.1.254
      Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\progra~1\mcafee\msc\McSnIePl.dll
      Handler: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - c:\program files\hp\hpcoretech\comp\hpuiprot.dll
      Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL
      SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
      SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL
      mASetup: {A509B1FF-37FF-4bFF-8CFF-4F3A747040FF} - c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,launchinfsectionex c:\program files\internet explorer\clrtour.inf,DefaultInstall.ResetTour,,12
      .
      ================= FIREFOX ===================
      .
      FF - ProfilePath - c:\documents and settings\brian\application data\mozilla\firefox\profiles\javjiaul.default\
      FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
      FF - prefs.js: browser.search.selectedEngine - Bing
      FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=Z192&install_date=20110921
      FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20110921&q=
      FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprpchromebrowserrecordext.dll
      FF - plugin: c:\documents and settings\all users\application data\real\realplayer\browserrecordplugin\mozillaplugins\nprphtml5videoshim.dll
      FF - plugin: c:\progra~1\mcafee\msc\npMcSnFFPl.dll
      FF - plugin: c:\program files\google\update\1.3.21.69\npGoogleUpdate3.dll
      FF - plugin: c:\program files\java\jre7\bin\new_plugin\npdeployJava1.dll
      FF - plugin: c:\program files\java\jre7\bin\new_plugin\npjp2.dll
      FF - plugin: c:\program files\microsoft silverlight\4.0.60531.0\npctrlui.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npCouponPrinter.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll
      FF - plugin: c:\program files\mozilla firefox\plugins\npMozCouponPrinter.dll
      FF - plugin: c:\program files\viewpoint\viewpoint experience technology\npViewpoint.dll
      FF - plugin: c:\program files\virtools\3d life player\npvirtools.dll
      .
      ============= SERVICES / DRIVERS ===============
      .
      R0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [2011-9-19 64048]
      R0 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2010-4-19 461864]
      R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [2010-4-19 89624]
      R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2011-2-8 54776]
      R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2011-7-22 12880]
      R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2011-7-12 67664]
      R2 !SASCORE;SAS Core Service;c:\program files\superantispyware\SASCore.exe [2011-8-11 116608]
      R2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-4-19 214904]
      R2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-4-19 214904]
      R2 McProxy;McAfee Proxy Service;c:\program files\common files\mcafee\mcsvchost\McSvHost.exe [2010-4-19 214904]
      R2 McShield;McAfee McShield;c:\program files\common files\mcafee\systemcore\mcshield.exe [2010-4-19 166024]
      R2 mfefire;McAfee Firewall Core Service;c:\program files\common files\mcafee\systemcore\mfefire.exe [2010-4-19 160344]
      R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\common files\mcafee\systemcore\mfevtps.exe [2010-4-19 148520]
      R2 MOBKbackup;McAfee Online Backup;c:\program files\mcafee online backup\MOBKbackup.exe [2010-4-13 229688]
      R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2010-4-19 57432]
      R3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2010-4-19 180072]
      R3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2010-4-19 59288]
      R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2010-4-19 338040]
      S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
      S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664]
      S2 srv388;srv388;c:\windows\system32\svchost.exe -k netsvcs [2004-8-10 14336]
      S2 Updater Service for StartNow Toolbar;Updater Service for StartNow Toolbar;c:\program files\startnow toolbar\toolbarupdaterservice.exe --> c:\program files\startnow toolbar\ToolbarUpdaterService.exe [?]
      S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-1-30 135664]
      S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\mcafee security scan\2.0.181\McCHSvc.exe [2010-1-15 227232]
      S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [2010-4-19 83688]
      S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2010-4-19 87808]
      S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
      .
      =============== Created Last 30 ================
      .
      2011-09-23 01:54:07   --------   d-sh--w-   c:\documents and settings\brian\PrivacIE
      2011-09-23 01:52:57   --------   d-sh--w-   c:\documents and settings\brian\IETldCache
      2011-09-23 01:47:48   --------   d-----w-   c:\windows\ie8updates
      2011-09-23 01:44:26   --------   dc-h--w-   c:\windows\ie8
      2011-09-22 00:39:38   --------   d-----w-   c:\program files\Trend Micro
      2011-09-22 00:24:31   --------   d-----w-   c:\documents and settings\brian\local settings\application data\Sun
      2011-09-21 23:14:50   611224   ----a-w-   c:\program files\mozilla firefox\plugins\npdeployJava1.dll
      2011-09-21 23:14:50   544656   ----a-w-   c:\windows\system32\deployJava1.dll
      2011-09-21 01:01:20   --------   d-----w-   c:\documents and settings\all users\Uniblue
      2011-09-20 22:36:52   --------   d-----w-   c:\documents and settings\brian\application data\SUPERAntiSpyware.com
      2011-09-20 22:35:59   --------   d-----w-   c:\program files\SUPERAntiSpyware
      2011-09-20 22:35:59   --------   d-----w-   c:\documents and settings\all users\application data\SUPERAntiSpyware.com
      2011-09-20 22:24:20   --------   d-----w-   c:\program files\CCleaner
      2011-09-20 02:16:26   64048   ----a-w-   c:\windows\system32\drivers\McPvDrv.sys
      2011-09-20 02:16:20   --------   d-----w-   c:\documents and settings\brian\local settings\application data\McAfee Anti-Theft
      2011-09-19 19:52:48   28504   ----a-w-   c:\program files\mozilla firefox\ScriptFF.dll
      2011-09-12 12:07:29   --------   d-----w-   c:\windows\LTZ6DKQX4BIOV29G
      2011-09-12 12:07:29   --------   d-----w-   c:\windows\9HOU18FMSZ6DJQX3
      2011-09-08 00:04:41   --------   d--h--w-   c:\documents and settings\all users\application data\McAfee Security Scan
      2011-09-08 00:04:38   --------   d-----w-   c:\program files\McAfee Security Scan
      2011-08-27 22:19:56   404640   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
      2011-08-27 22:11:02   625736   ----a-w-   c:\program files\common files\ZugoInstaller.exe
      2011-08-26 01:34:51   --------   d--h--w-   c:\documents and settings\brian\local settings\application data\Apple
      2011-08-26 01:32:31   --------   d--h--w-   c:\windows\PIF
      2011-08-25 23:17:18   --------   d--h--w-   c:\documents and settings\brian\application data\GlarySoft
      2011-08-25 23:14:30   --------   d-----w-   c:\program files\Glary Utilities
      .
      ==================== Find3M  ====================
      .
      2011-09-21 23:14:09   128000   ----a-w-   c:\windows\system32\javacpl.cpl
      2011-09-09 09:12:13   599040   ----a-w-   c:\windows\system32\crypt32.dll
      2011-08-31 21:00:50   22216   ----a-w-   c:\windows\system32\drivers\mbam.sys
      2011-08-18 20:17:46   12872   ----a-w-   c:\windows\system32\bootdelete.exe
      2011-08-18 20:01:19   20552   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
      2011-08-18 18:07:17   103784   ---ha-w-   c:\documents and settings\brian\GoToAssistDownloadHelper.exe
      2011-08-16 16:42:15   574   ----a-w-   C:\cleanup.bat
      2011-08-15 14:00:06   9344   ----a-w-   c:\windows\system32\drivers\mfeclnk.sys
      2011-08-15 14:00:06   89624   ----a-w-   c:\windows\system32\drivers\mfetdi2k.sys
      2011-08-15 14:00:06   87808   ----a-w-   c:\windows\system32\drivers\mferkdet.sys
      2011-08-15 14:00:06   83688   ----a-w-   c:\windows\system32\drivers\mfendisk.sys
      2011-08-15 14:00:06   59288   ----a-w-   c:\windows\system32\drivers\mfebopk.sys
      2011-08-15 14:00:06   57432   ----a-w-   c:\windows\system32\drivers\cfwids.sys
      2011-08-15 14:00:06   461864   ----a-w-   c:\windows\system32\drivers\mfehidk.sys
      2011-08-15 14:00:06   338040   ----a-w-   c:\windows\system32\drivers\mfefirek.sys
      2011-08-15 14:00:06   180072   ----a-w-   c:\windows\system32\drivers\mfeavfk.sys
      2011-08-15 14:00:06   119808   ----a-w-   c:\windows\system32\drivers\mfeapfk.sys
      2011-07-15 13:29:31   456320   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
      2011-07-08 14:02:00   10496   ----a-w-   c:\windows\system32\drivers\ndistapi.sys
      .
      ============= FINISH: 15: UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
      IF REQUESTED, ZIP IT UP & ATTACH IT
      .
      DDS (Ver_2011-08-26.01)
      .
      Microsoft Windows XP Home Edition
      Boot Device: \Device\HarddiskVolume2
      Install Date: 6/3/2008 9:49:43 PM
      System Uptime: 9/24/2011 2:09:32 PM (1 hours ago)
      .
      Motherboard: Dell Inc. |  | 0RY206
      Processor: AMD Sempron(tm) Processor LE-1300 | Socket AM2  | 2310/200mhz
      .
      ==== Disk Partitions =========================
      .
      C: is FIXED (NTFS) - 149 GiB total, 69.524 GiB free.
      D: is CDROM ()
      .
      ==== Disabled Device Manager Items =============
      .
      ==== System Restore Points ===================
      .
      RP997: 8/18/2011 4:32:38 PM - System Checkpoint
      RP998: 8/19/2011 4:38:34 PM - System Checkpoint
      RP999: 8/20/2011 4:59:34 PM - System Checkpoint
      RP1000: 8/21/2011 7:07:50 PM - System Checkpoint
      RP1001: 8/22/2011 9:19:15 PM - System Checkpoint
      RP1002: 8/23/2011 8:54:31 AM - Installed HP Unload DLL Patch
      RP1003: 8/24/2011 9:02:58 AM - System Checkpoint
      RP1004: 8/24/2011 12:24:27 PM - Software Distribution Service 3.0
      RP1005: 8/25/2011 5:14:56 PM - System Checkpoint
      RP1006: 8/26/2011 10:53:28 PM - System Checkpoint
      RP1007: 8/28/2011 10:01:35 AM - System Checkpoint
      RP1008: 8/29/2011 10:06:59 AM - System Checkpoint
      RP1009: 8/30/2011 4:43:19 PM - System Checkpoint
      RP1010: 8/31/2011 10:29:24 PM - System Checkpoint
      RP1011: 9/2/2011 5:14:42 PM - System Checkpoint
      RP1012: 9/3/2011 6:45:12 PM - System Checkpoint
      RP1013: 9/4/2011 7:08:26 PM - System Checkpoint
      RP1014: 9/6/2011 8:41:31 AM - System Checkpoint
      RP1015: 9/7/2011 9:53:25 AM - System Checkpoint
      RP1016: 9/8/2011 8:46:25 AM - Software Distribution Service 3.0
      RP1017: 9/9/2011 11:22:07 AM - System Checkpoint
      RP1018: 9/10/2011 11:22:20 AM - System Checkpoint
      RP1019: 9/11/2011 6:50:59 PM - System Checkpoint
      RP1020: 9/12/2011 9:36:00 PM - System Checkpoint
      RP1021: 9/13/2011 9:45:20 PM - System Checkpoint
      RP1022: 9/17/2011 9:45:24 AM - Software Distribution Service 3.0
      RP1023: 9/18/2011 12:27:59 PM - System Checkpoint
      RP1024: 9/19/2011 4:37:42 PM - System Checkpoint
      RP1025: 9/19/2011 10:40:23 PM - Restore Operation
      RP1026: 9/19/2011 10:49:54 PM - Restore Operation
      RP1027: 9/19/2011 10:56:12 PM - september 17,2011 12am
      RP1028: 9/19/2011 11:06:49 PM - Restore Operation
      RP1029: 9/19/2011 11:07:26 PM - Restore Operation
      RP1030: 9/19/2011 11:16:23 PM - Restore Operation
      RP1031: 9/21/2011 9:11:48 AM - System Checkpoint
      RP1032: 9/21/2011 7:13:58 PM - Installed Java(TM) 7
      RP1033: 9/22/2011 9:45:28 PM - Installed Windows Internet Explorer 8.
      RP1034: 9/22/2011 9:46:25 PM - Software Distribution Service 3.0
      RP1035: 9/22/2011 10:16:07 PM - Removed Ask Toolbar.
      RP1036: 9/22/2011 10:17:11 PM - Removed Bonjour
      RP1037: 9/23/2011 9:46:58 PM - Software Distribution Service 3.0
      .
      ==== Installed Programs ======================
      .
      3DVIA player 4.1
      Acrobat.com
      Adobe AIR
      Adobe Download Manager
      Adobe Flash Player 10 ActiveX
      Adobe Flash Player 10 Plugin
      Adobe Reader 9.1
      Adobe Shockwave Player 11.5
      AiO_Scan
      AiOSoftware
      America Online (Choose which version to remove)
      Apple Application Support
      Apple Mobile Device Support
      Apple Software Update
      ArcSoft Panorama Maker 4
      AT&T Internet Security Wizard 1.5.11
      AT&T Self Support Tool
      AusLogics Disk Defrag
      Bejeweled Deluxe 1.87
      Bejeweled® Deluxe
      Browser Address Error Redirector
      BufferChm
      CCleaner
      Cisco Connect
      Compatibility Pack for the 2007 Office system
      Conexant D850 56K V.9x DFVc Modem
      Copy
      Coupon Printer for Windows
      CreativeProjects
      CreativeProjectsTemplates
      Critical Update for Windows Media Player 11 (KB959772)
      CueTour
      Dell Support Center (Support Software)
      Destinations
      Director
      DocProc
      Documentation & Support Launcher
      DocumentViewer
      Dream Chronicles 3
      EarthLink Setup Files
      Fax
      Games, Music, & Photos Launcher
      Glary Utilities 2.36.0.1232
      Google Chrome
      Google Update Helper
      High Definition Audio Driver Package - KB835221
      HijackThis 2.0.2
      Hotfix for Windows Media Format 11 SDK (KB929399)
      Hotfix for Windows Media Player 11 (KB939683)
      Hotfix for Windows XP (KB2158563)
      Hotfix for Windows XP (KB2443685)
      Hotfix for Windows XP (KB2570791)
      Hotfix for Windows XP (KB952287)
      Hotfix for Windows XP (KB970653-v3)
      Hotfix for Windows XP (KB976098-v2)
      Hotfix for Windows XP (KB979306)
      Hotfix for Windows XP (KB981793)
      HP Diagnostic Assistant
      HP Software Update
      HP Unload DLL Patch
      HPSystemDiagnostics
      InstantShare
      iTunes
      J2SE Runtime Environment 5.0 Update 6
      Java Auto Updater
      Java(TM) 6 Update 13
      Java(TM) 7
      Logitech Webcam Software
      magicJack
      Malwarebytes' Anti-Malware version 1.51.2.1300
      McAfee Online Backup
      McAfee Security Scan Plus
      McAfee Total Protection
      Memorex exPressit Label Design Studio
      Microsoft .NET Framework 1.1
      Microsoft .NET Framework 1.1 Security Update (KB2416447)
      Microsoft .NET Framework 1.1 Security Update (KB979906)
      Microsoft .NET Framework 4 Client Profile
      Microsoft .NET Framework 4 Extended
      Microsoft Application Error Reporting
      Microsoft Compression Client Pack 1.0 for Windows XP
      Microsoft Office 2007 Service Pack 2 (SP2)
      Microsoft Office Excel MUI (English) 2007
      Microsoft Office File Validation Add-In
      Microsoft Office Home and Student 2007
      Microsoft Office OneNote MUI (English) 2007
      Microsoft Office PowerPoint MUI (English) 2007
      Microsoft Office PowerPoint Viewer 2007 (English)
      Microsoft Office Proof (English) 2007
      Microsoft Office Proof (French) 2007
      Microsoft Office Proof (Spanish) 2007
      Microsoft Office Proofing (English) 2007
      Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
      Microsoft Office Shared MUI (English) 2007
      Microsoft Office Shared Setup Metadata MUI (English) 2007
      Microsoft Office Word MUI (English) 2007
      Microsoft Silverlight
      Microsoft Software Update for Web Folders  (English) 12
      Microsoft User-Mode Driver Framework Feature Pack 1.0
      Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
      Microsoft Visual C++ 2005 Redistributable
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
      Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
      Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319
      Microsoft Works
      Modem Diagnostic Tool
      Mozilla Firefox 6.0.2 (x86 en-US)
      MSXML 4.0 SP2 (KB936181)
      MSXML 4.0 SP2 (KB954430)
      MSXML 4.0 SP2 (KB973688)
      MSXML 6.0 Parser (KB933579)
      NetWaiting
      Nikon Message Center
      Nikon Transfer
      NVIDIA Drivers
      Overland
      PhotoGallery
      PowerDVD
      PrintScreen
      QFolder
      QuickProjects
      QuickTime
      Readme
      RealNetworks - Microsoft Visual C++ 2008 Runtime
      RealPlayer
      Realtek High Definition Audio Driver
      RealUpgrade 1.1
      RegScrubXP 3.25
      Roxio Creator Audio
      Roxio Creator Copy
      Roxio Creator Data
      Roxio Creator DE
      Roxio Creator Tools
      Roxio Express Labeler 3
      Roxio Update Manager
      Scan
      SearchAssist
      Security Update for 2007 Microsoft Office System (KB2288621)
      Security Update for 2007 Microsoft Office System (KB2288931)
      Security Update for 2007 Microsoft Office System (KB2345043)
      Security Update for 2007 Microsoft Office System (KB2553074)
      Security Update for 2007 Microsoft Office System (KB2553089)
      Security Update for 2007 Microsoft Office System (KB2553090)
      Security Update for 2007 Microsoft Office System (KB2584063)
      Security Update for 2007 Microsoft Office System (KB969559)
      Security Update for 2007 Microsoft Office System (KB976321)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870)
      Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636)
      Security Update for Microsoft .NET Framework 4 Extended (KB2416472)
      Security Update for Microsoft .NET Framework 4 Extended (KB2487367)
      Security Update for Microsoft Office Excel 2007 (KB2553073)
      Security Update for Microsoft Office InfoPath 2007 (KB979441)
      Security Update for Microsoft Office PowerPoint 2007 (KB2535818)
      Security Update for Microsoft Office PowerPoint Viewer 2007 (KB2464623)
      Security Update for Microsoft Office system 2007 (972581)
      Security Update for Microsoft Office system 2007 (KB974234)
      Security Update for Microsoft Office Visio Viewer 2007 (KB973709)
      Security Update for Microsoft Office Word 2007 (KB2344993)
      Security Update for Step By Step Interactive Training (KB923723)
      Security Update for Windows Internet Explorer 8 (KB2510531)
      Security Update for Windows Internet Explorer 8 (KB2544521)
      Security Update for Windows Internet Explorer 8 (KB2559049)
      Security Update for Windows Internet Explorer 8 (KB982381)
      Security Update for Windows Media Player (KB2378111)
      Security Update for Windows Media Player (KB911564)
      Security Update for Windows Media Player (KB952069)
      Security Update for Windows Media Player (KB954155)
      Security Update for Windows Media Player (KB968816)
      Security Update for Windows Media Player (KB973540)
      Security Update for Windows Media Player (KB975558)
      Security Update for Windows Media Player (KB978695)
      Security Update for Windows Media Player 11 (KB936782)
      Security Update for Windows Media Player 11 (KB954154)
      Security Update for Windows Media Player 9 (KB936782)
      Security Update for Windows XP (KB2079403)
      Security Update for Windows XP (KB2115168)
      Security Update for Windows XP (KB2121546)
      Security Update for Windows XP (KB2160329)
      Security Update for Windows XP (KB2183461)
      Security Update for Windows XP (KB2229593)
      Security Update for Windows XP (KB2259922)
      Security Update for Windows XP (KB2279986)
      Security Update for Windows XP (KB2286198)
      Security Update for Windows XP (KB2296011)
      Security Update for Windows XP (KB2296199)
      Security Update for Windows XP (KB2347290)
      Security Update for Windows XP (KB2360131)
      Security Update for Windows XP (KB2360937)
      Security Update for Windows XP (KB2387149)
      Security Update for Windows XP (KB2393802)
      Security Update for Windows XP (KB2412687)
      Security Update for Windows XP (KB2416400)
      Security Update for Windows XP (KB2419632)
      Security Update for Windows XP (KB2423089)
      Security Update for Windows XP (KB2436673)
      Security Update for Windows XP (KB2440591)
      Security Update for Windows XP (KB2443105)
      Security Update for Windows XP (KB2476490)
      Security Update for Windows XP (KB2476687)
      Security Update for Windows XP (KB2478960)
      Security Update for Windows XP (KB2478971)
      Security Update for Windows XP (KB2479628)
      Security Update for Windows XP (KB2479943)
      Security Update for Windows XP (KB2481109)
      Security Update for Windows XP (KB2482017)
      Security Update for Windows XP (KB2483185)
      Security Update for Windows XP (KB2485376)
      Security Update for Windows XP (KB2485663)
      Security Update for Windows XP (KB2491683)
      Security Update for Windows XP (KB2497640)
      Security Update for Windows XP (KB2503658)
      Security Update for Windows XP (KB2503665)
      Security Update for Windows XP (KB2506212)
      Security Update for Windows XP (KB2506223)
      Security Update for Windows XP (KB2507618)
      Security Update for Windows XP (KB2507938)
      Security Update for Windows XP (KB2508272)
      Security Update for Windows XP (KB2508429)
      Security Update for Windows XP (KB2509553)
      Security Update for Windows XP (KB2510581)
      Security Update for Windows XP (KB2511455)
      Security Update for Windows XP (KB2524375)
      Security Update for Windows XP (KB2530548)
      Security Update for Windows XP (KB2535512)
      Security Update for Windows XP (KB2536276-v2)
      Security Update for Windows XP (KB2536276)
      Security Update for Windows XP (KB2544521)
      Security Update for Windows XP (KB2544893)
      Security Update for Windows XP (KB2555917)
      Security Update for Windows XP (KB2559049)
      Security Update for Windows XP (KB2562937)
      Security Update for Windows XP (KB2566454)
      Security Update for Windows XP (KB2567680)
      Security Update for Windows XP (KB2570222)
      Security Update for Windows XP (KB2570947)
      Security Update for Windows XP (KB923561)
      Security Update for Windows XP (KB938464)
      Security Update for Windows XP (KB941569)
      Security Update for Windows XP (KB946648)
      Security Update for Windows XP (KB950759)
      Security Update for Windows XP (KB950760)
      Security Update for Windows XP (KB950762)
      Security Update for Windows XP (KB950974)
      Security Update for Windows XP (KB951066)
      Security Update for Windows XP (KB951376-v2)
      Security Update for Windows XP (KB951376)
      Security Update for Windows XP (KB951698)
      Security Update for Windows XP (KB951748)
      Security Update for Windows XP (KB952004)
      Security Update for Windows XP (KB952954)
      Security Update for Windows XP (KB953838)
      Security Update for Windows XP (KB953839)
      Security Update for Windows XP (KB954211)
      Security Update for Windows XP (KB954459)
      Security Update for Windows XP (KB954600)
      Security Update for Windows XP (KB955069)
      Security Update for Windows XP (KB956390)
      Security Update for Windows XP (KB956391)
      Security Update for Windows XP (KB956572)
      Security Update for Windows XP (KB956744)
      Security Update for Windows XP (KB956802)
      Security Update for Windows XP (KB956803)
      Security Update for Windows XP (KB956841)
      Security Update for Windows XP (KB956844)
      Security Update for Windows XP (KB957095)
      Security Update for Windows XP (KB957097)
      Security Update for Windows XP (KB958215)
      Security Update for Windows XP (KB958644)
      Security Update for Windows XP (KB958687)
      Security Update for Windows XP (KB958690)
      Security Update for Windows XP (KB958869)
      Security Update for Windows XP (KB959426)
      Security Update for Windows XP (KB960225)
      Security Update for Windows XP (KB960714)
      Security Update for Windows XP (KB960715)
      Security Update for Windows XP (KB960803)
      Security Update for Windows XP (KB960859)
      Security Update for Windows XP (KB961371)
      Security Update for Windows XP (KB961373)
      Security Update for Windows XP (KB961501)
      Security Update for Windows XP (KB963027)
      Security Update for Windows XP (KB968537)
      Security Update for Windows XP (KB969059)
      Security Update for Windows XP (KB969897)
      Security Update for Windows XP (KB969898)
      Security Update for Windows XP (KB969947)
      Security Update for Windows XP (KB970238)
      Security Update for Windows XP (KB970430)
      Security Update for Windows XP (KB971468)
      Security Update for Windows XP (KB971486)
      Security Update for Windows XP (KB971557)
      Security Update for Windows XP (KB971633)
      Security Update for Windows XP (KB971657)
      Security Update for Windows XP (KB971961)
      Security Update for Windows XP (KB972260)
      Security Update for Windows XP (KB972270)
      Security Update for Windows XP (KB973346)
      Security Update for Windows XP (KB973354)
      Security Update for Windows XP (KB973507)
      Security Update for Windows XP (KB973525)
      Security Update for Windows XP (KB973869)
      Security Update for Windows XP (KB973904)
      Security Update for Windows XP (KB974112)
      Security Update for Windows XP (KB974318)
      Security Update for Windows XP (KB974392)
      Security Update for Windows XP (KB974455)
      Security Update for Windows XP (KB974571)
      Security Update for Windows XP (KB975025)
      Security Update for Windows XP (KB975467)
      Security Update for Windows XP (KB975560)
      Security Update for Windows XP (KB975561)
      Security Update for Windows XP (KB975562)
      Security Update for Windows XP (KB975713)
      Security Update for Windows XP (KB976325)
      Security Update for Windows XP (KB977165)
      Security Update for Windows XP (KB977816)
      Security Update for Windows XP (KB977914)
      Security Update for Windows XP (KB978037)
      Security Update for Windows XP (KB978251)
      Security Update for Windows XP (KB978262)
      Security Update for Windows XP (KB978338)
      Security Update for Windows XP (KB978542)
      Security Update for Windows XP (KB978601)
      Security Update for Windows XP (KB978706)
      Security Update for Windows XP (KB979309)
      Security Update for Windows XP (KB979482)
      Security Update for Windows XP (KB979559)
      Security Update for Windows XP (KB979683)
      Security Update for Windows XP (KB979687)
      Security Update for Windows XP (KB980195)
      Security Update for Windows XP (KB980218)
      Security Update for Windows XP (KB980232)
      Security Update for Windows XP (KB980436)
      Security Update for Windows XP (KB981322)
      Security Update for Windows XP (KB981349)
      Security Update for Windows XP (KB981852)
      Security Update for Windows XP (KB981957)
      Security Update for Windows XP (KB981997)
      Security Update for Windows XP (KB982132)
      Security Update for Windows XP (KB982214)
      Security Update for Windows XP (KB982381)
      Security Update for Windows XP (KB982665)
      Security Update for Windows XP (KB982802)
      SkinsHP1
      SUPERAntiSpyware
      The Sims Superstar
      TrayApp
      Uninstall Dual Mode Camera
      Unload
      Update for 2007 Microsoft Office System (KB967642)
      Update for Microsoft .NET Framework 4 Client Profile (KB2473228)
      Update for Microsoft Office 2007 System (KB2539530)
      Update for Microsoft Office OneNote 2007 (KB980729)
      Update for Windows Internet Explorer 8 (KB2447568)
      Update for Windows XP (KB2141007)
      Update for Windows XP (KB2345886)
      Update for Windows XP (KB2467659)
      Update for Windows XP (KB2541763)
      Update for Windows XP (KB2607712)
      Update for Windows XP (KB2616676)
      Update for Windows XP (KB951072-v2)
      Update for Windows XP (KB951978)
      Update for Windows XP (KB955759)
      Update for Windows XP (KB955839)
      Update for Windows XP (KB961503)
      Update for Windows XP (KB967715)
      Update for Windows XP (KB968389)
      Update for Windows XP (KB971029)
      Update for Windows XP (KB971737)
      Update for Windows XP (KB973687)
      Update for Windows XP (KB973815)
      Update for Windows XP (KB976749)
      Update for Windows XP (KB978207)
      Update for Windows XP (KB980182)
      VGA USB Camera
      Viewpoint Media Player
      WebFldrs XP
      WebReg
      Windows Installer 3.1 (KB893803)
      Windows Internet Explorer 8
      Windows Live Sign-in Assistant
      Windows Live Upload Tool
      Windows Media Format 11 runtime
      Windows Media Player 11
      Windows XP Service Pack 3
      Yahoo! Install Manager
      Yahoo! Internet Mail
      Yahoo! Messenger
      Yahoo! Search Protection
      Yahoo! Software Update
      Yahoo! Toolbar
      .
      ==== Event Viewer Messages From Past Week ========
      .
      9/21/2011 8:19:25 PM, error: sr [1]  - The System Restore filter encountered the unexpected error '0xC0000243' while processing the file 'Toolbar32.dll' on the volume 'HarddiskVolume2'.  It has stopped monitoring the volume.
      9/21/2011 7:24:19 PM, error: DCOM [10000]  - Unable to start a DCOM Server: {3C16E079-E4C7-493C-BE9F-E0F2BB0B7430}. The error: "%233" Happened while starting this command: "C:\Program Files\Yahoo!\Companion\Installs\cpn1\ytbb.exe" -Embedding
      9/21/2011 10:31:00 AM, error: DCOM [10001]  - Unable to start a DCOM Server: {6DFC2D17-579D-4C1C-93B7-B05B7DCCD766} as /. The error: "%233" Happened while starting this command: "c:\PROGRA~1\mcafee.com\agent\mcagent.exe" -Embedding
      9/17/2011 9:42:39 AM, error: Service Control Manager [7023]  - The srv388 service terminated with the following error:  The specified module could not be found.
      9/17/2011 9:42:15 AM, error: Dhcp [1002]  - The IP address lease 192.168.0.122 for the Network Card with network address 001EC96402DE has been denied by the DHCP server 192.168.0.1 (The DHCP Server sent a DHCPNACK message).
      9/17/2011 1:27:54 PM, error: DCOM [10001]  - Unable to start a DCOM Server: {211EBA3A-EA5A-496B-A021-5C6BEB365E4C} as /. The error: "%233" Happened while starting this command: c:\PROGRA~1\mcafee.com\agent\mcagent.exe -Embedding
      .
      ==== End Of File ===========================46:50.71 ===============


      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: New thread as requested
      « Reply #3 on: September 25, 2011, 12:30:40 PM »
      Download Security Check by screen317 from one of the following links and save it to your desktop.

      Link 1
      Link 2

      * Unzip SecurityCheck.zip and a folder named Security Check should appear.
      * Open the Security Check folder and double-click Security Check.bat
      * Follow the on-screen instructions inside of the black box.
      * A Notepad document should open automatically called checkup.txt
      * Post the contents of that document in your next reply.

      Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.
      ***********************************************************
      You have Viewpoint installed.

      Viewpoint Media Player/Manager/Toolbar is considered as Foistware instead of malware since it is installed without users approval but doesn't spy or do anything "bad".

      More information:

      * ViewMgr.exe - Useless
      * Viewpoint to Plunge Into Adware

      It is suggested to remove the program now. Go to Start > Control Panel > Add/Remove Programs - (Vista & Win7 is Programs and Features) and remove the following programs if present.

      * Viewpoint
      * Viewpoint Manager
      * Viewpoint Media Player
      * Viewpoint Toolbar
      * Viewpoint Experience Technology

      ****************************************************
      Update Your Java (JRE)

      Old versions of Java have vulnerabilities that malware can use to infect your system.


      First Verify your Java Version

      If there are any other version(s) installed then update now.

      Get the new version (if needed)

      If your version is out of date install the newest version of the Sun Java Runtime Environment.

      Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

      Be sure to close ALL open web browsers before starting the installation.

      Remove any old versions

      1. Download JavaRa and unzip the file to your Desktop.
      2. Open JavaRA.exe and choose Remove Older Versions
      3. Once complete exit JavaRA.

      Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
      *******************************************************
      Download OTL to your desktop.

      * Open OTL
      * Copy and Paste the following text in the codebox into the Custom Scans/Fixes window.

      Code: [Select]
      :OTL

      TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
      TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
      TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File
      Trusted Zone: 0.0.0.0
      Trusted Zone: internet
      Trusted Zone: mcafee.com
      Trusted Zone: motive.com\patttbc.att

      :COMMANDS
      [resethosts]
      [purity]
      [start explorer]

      * Click Run Fix
      * OTLI2 may ask to reboot the machine. Please do so if asked.
      * Click OK
      * A report will open. Copy and Paste that report in your next reply.
      ***************************************************************

      Please download ComboFix from BleepingComputer.com

      Alternate link: GeeksToGo.com

      and save it to your Desktop.
      It would be easiest to download using Internet Explorer.
      If you insist on using Firefox, make sure that your download settings are as follows:

      * Tools->Options->Main tab
      * Set to "Always ask me where to Save the files".

      Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools A guide to do this can be found here
      Double click ComboFix.exe & follow the prompts.
      As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
      Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console

      Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

      Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:


      Click on Yes, to continue scanning for malware.
      When finished, it shall produce a log for you.  Please include the contents of C:\ComboFix.txt in your next reply.

      If you have problems with ComboFix usage, see How to use ComboFix
      Windows 8 and Windows 10 dual boot with two SSD's

      Brian Keith

        Topic Starter


        Greenhorn

        • Computer: Specs
        • Experience: Beginner
        • OS: Windows XP
        Re: New thread as requested
        « Reply #4 on: September 25, 2011, 04:41:59 PM »
        here are the logs requested...Thanks again

        Results of screen317's Security Check version 0.99.18 
         Windows XP Service Pack 3 
         Internet Explorer 8 
        ``````````````````````````````
        Antivirus/Firewall Check:

         Windows Firewall Enabled! 
         McAfee Total Protection   
         McAfee Security Scan Plus   
         McAfee Online Backup   
        ```````````````````````````````
        Anti-malware/Other Utilities Check:

         Malwarebytes' Anti-Malware   
         HijackThis 2.0.2   
         CCleaner     
         Java(TM) 6 Update 13 
         Java(TM) 7   
         Out of date Java installed!
         Adobe Flash Player    10.3.183.7 
         Mozilla Firefox (x86 en-US..)
        ````````````````````````````````

        Process Check:  ========== OTL ==========
        ========== COMMANDS ==========
        C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
        HOSTS file reset successfully
         
        OTL by OldTimer - Version 3.2.29.1 log created on 09252011_161046
        objlist.exe by Laurent

         McAfee Online Backup MOBKbackup.exe   
        ``````````End of Log````````````
        ComboFix 11-09-24.04 - Brian 09/25/2011  17:33:29.2.1 - x86
        Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1982.1393 [GMT -4:00]
        Running from: c:\documents and settings\Brian\My Documents\Downloads\ComboFix.exe
        AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
        FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
        .
        .
        (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\iconfix.exe.1e178bd5.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\info.exe.c95fa770.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\regtweak.exe.dc1948c4.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\rename.exe.87e761aa.ini
        c:\documents and settings\Administrator\Local Settings\Application Data\ApplicationHistory\SL30.tmp.a406a4be.ini
        c:\documents and settings\Brian\GoToAssistDownloadHelper.exe
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\csc.exe.3e4ac0af.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\EULA.exe.e24c9112.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\EULALauncher.exe.3f62b452.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\hpqcopy.exe.720f7233.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\hpqgalry.exe.cf8dd223.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\HpqPhUnl.exe.e1eda619.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\hpqselsk.exe.a048b05c.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\hpqthb08.exe.a935d1e0.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\iconfix.exe.1e178bd5.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\info.exe.c95fa770.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\Launcher.exe.b7231ca1.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\MBKLAU~1.EXE.b4d4036d.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\MBKLaunch.exe.c9dac3cc.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\McAfeeDataBackup.exe.e548c4c.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\mcshell.exe.9039d39.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\regtweak.exe.dc1948c4.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\rename.exe.87e761aa.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\SL30.tmp.a406a4be.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\sprtcmd.exe.63e7480d.ini
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\sprtcmd.exe.63e7480d.ini.inuse
        c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\UninstallTB.exe.8dfaf78b.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\iconfix.exe.1e178bd5.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\info.exe.c95fa770.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\ngen.exe.2c05686e.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\regtweak.exe.dc1948c4.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\rename.exe.87e761aa.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\SL30.tmp.a406a4be.ini
        c:\documents and settings\Poppa\Local Settings\Application Data\ApplicationHistory\sprtcmd.exe.63e7480d.ini.inuse
        c:\windows\system32\d3d9caps.dat
        .
        .
        (((((((((((((((((((((((((((((((((((((((   Drivers/Services   )))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        -------\Legacy_Updater_Service_for_StartNow_Toolbar
        -------\Service_Updater Service for StartNow Toolbar
        .
        .
        (((((((((((((((((((((((((   Files Created from 2011-08-25 to 2011-09-25  )))))))))))))))))))))))))))))))
        .
        .
        2011-09-25 22:15 . 2011-09-25 22:16   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory
        2011-09-25 20:10 . 2011-09-25 20:10   --------   d-----w-   C:\_OTL
        2011-09-24 13:50 . 2011-09-24 13:50   --------   d-sh--w-   c:\documents and settings\Rachel\PrivacIE
        2011-09-24 13:47 . 2011-09-24 13:47   --------   d-sh--w-   c:\documents and settings\Rachel\IETldCache
        2011-09-23 12:53 . 2011-09-23 12:53   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
        2011-09-23 01:54 . 2011-09-23 01:54   --------   d-sh--w-   c:\documents and settings\Brian\PrivacIE
        2011-09-23 01:52 . 2011-09-23 01:52   --------   d-sh--w-   c:\documents and settings\Brian\IETldCache
        2011-09-23 01:51 . 2011-09-23 01:51   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache
        2011-09-23 01:44 . 2011-09-23 01:46   --------   dc-h--w-   c:\windows\ie8
        2011-09-22 03:14 . 2011-09-25 14:22   --------   d-----w-   c:\documents and settings\Poppa
        2011-09-22 00:39 . 2011-09-22 00:39   --------   d-----w-   c:\program files\Trend Micro
        2011-09-22 00:24 . 2011-09-22 00:24   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\Sun
        2011-09-21 23:14 . 2011-09-21 23:14   611224   ----a-w-   c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
        2011-09-21 23:14 . 2011-09-21 23:14   544656   ----a-w-   c:\windows\system32\deployJava1.dll
        2011-09-21 01:01 . 2011-09-21 01:01   --------   d-----w-   c:\documents and settings\All Users\Uniblue
        2011-09-20 22:36 . 2011-09-20 22:36   --------   d-----w-   c:\documents and settings\Brian\Application Data\SUPERAntiSpyware.com
        2011-09-20 22:35 . 2011-09-20 22:36   --------   d-----w-   c:\program files\SUPERAntiSpyware
        2011-09-20 22:35 . 2011-09-20 22:35   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
        2011-09-20 22:24 . 2011-09-20 22:24   --------   d-----w-   c:\program files\CCleaner
        2011-09-20 02:16 . 2011-04-11 18:29   64048   ----a-w-   c:\windows\system32\drivers\McPvDrv.sys
        2011-09-20 02:16 . 2011-09-20 02:16   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\McAfee Anti-Theft
        2011-09-19 19:52 . 2011-08-19 19:56   28504   ----a-w-   c:\program files\Mozilla Firefox\ScriptFF.dll
        2011-09-12 12:07 . 2011-09-12 12:07   --------   d-----w-   c:\windows\LTZ6DKQX4BIOV29G
        2011-09-12 12:07 . 2011-09-12 12:07   --------   d-----w-   c:\windows\9HOU18FMSZ6DJQX3
        2011-09-08 22:40 . 2011-09-08 22:40   --------   d-----w-   c:\documents and settings\LocalService\Application Data\McAfee
        2011-09-08 00:04 . 2011-09-08 00:04   --------   d--h--w-   c:\documents and settings\All Users\Application Data\McAfee Security Scan
        2011-09-08 00:04 . 2011-09-08 22:39   --------   d-----w-   c:\program files\McAfee Security Scan
        2011-08-27 22:19 . 2011-09-08 00:04   404640   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
        2011-08-27 22:11 . 2011-07-22 11:14   625736   ----a-w-   c:\program files\Common Files\ZugoInstaller.exe
        .
        .
        .
        ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        2011-09-21 23:14 . 2009-03-11 17:11   128000   ----a-w-   c:\windows\system32\javacpl.cpl
        2011-09-09 09:12 . 2004-08-10 17:50   599040   ----a-w-   c:\windows\system32\crypt32.dll
        2011-08-31 21:00 . 2011-08-25 03:51   22216   ----a-w-   c:\windows\system32\drivers\mbam.sys
        2011-08-18 20:17 . 2011-08-18 19:47   12872   ----a-w-   c:\windows\system32\bootdelete.exe
        2011-08-18 20:01 . 2011-08-18 19:36   20552   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
        2011-08-16 16:42 . 2011-08-16 16:42   574   ----a-w-   C:\cleanup.bat
        2011-08-15 14:00 . 2010-04-19 17:41   9344   ----a-w-   c:\windows\system32\drivers\mfeclnk.sys
        2011-08-15 14:00 . 2010-04-19 17:41   89624   ----a-w-   c:\windows\system32\drivers\mfetdi2k.sys
        2011-08-15 14:00 . 2010-04-19 17:41   87808   ----a-w-   c:\windows\system32\drivers\mferkdet.sys
        2011-08-15 14:00 . 2010-04-19 17:41   83688   ----a-w-   c:\windows\system32\drivers\mfendisk.sys
        2011-08-15 14:00 . 2010-04-19 17:41   59288   ----a-w-   c:\windows\system32\drivers\mfebopk.sys
        2011-08-15 14:00 . 2010-04-19 17:41   57432   ----a-w-   c:\windows\system32\drivers\cfwids.sys
        2011-08-15 14:00 . 2010-04-19 17:41   461864   ----a-w-   c:\windows\system32\drivers\mfehidk.sys
        2011-08-15 14:00 . 2010-04-19 17:41   338040   ----a-w-   c:\windows\system32\drivers\mfefirek.sys
        2011-08-15 14:00 . 2010-04-19 17:41   180072   ----a-w-   c:\windows\system32\drivers\mfeavfk.sys
        2011-08-15 14:00 . 2010-04-19 17:41   119808   ----a-w-   c:\windows\system32\drivers\mfeapfk.sys
        2011-07-15 13:29 . 2004-08-10 17:51   456320   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
        2011-07-08 14:02 . 2004-08-10 17:51   10496   ----a-w-   c:\windows\system32\drivers\ndistapi.sys
        2011-09-03 06:01 . 2011-09-03 01:43   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
        2011-04-14 18:01 . 2010-04-19 17:41   24376   ----a-w-   c:\program files\mozilla firefox\components\Scriptff.dll
        .
        .
        (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
        .
        .
        *Note* empty entries & legit default entries are not shown
        REGEDIT4
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
        @="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
        [HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
        2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
        @="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
        [HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
        2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
        @="{b4caf489-1eec-c617-49ad-8d7088598c06}"
        [HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
        2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
        .
        [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
        "cdloader"="c:\documents and settings\Brian\Application Data\mjusbsp\cdloader2.exe" [2010-09-09 50592]
        "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-08-12 4603264]
        .
        [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
        "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-07 8466432]
        "nwiz"="nwiz.exe" [2008-04-07 1626112]
        "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-07 81920]
        "RTHDCPL"="RTHDCPL.EXE" [2008-04-07 16859648]
        "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
        "HostManager"="c:\program files\Common Files\AOL\1208536966\EE\AOLHostManager.exe" [2004-11-03 125528]
        "PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
        "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
        "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
        "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
        "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
        "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
        "ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2008-09-19 1529856]
        "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
        "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-10 1317016]
        "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
        "McPvTray_exe"="c:\program files\McAfee\MAT\McPvTray.exe" [2011-04-08 419904]
        "TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-05-27 273544]
        .
        c:\documents and settings\Brian\Start Menu\Programs\Startup\
        OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
        .
        [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
        "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
        2011-05-04 17:54   551296   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
        .
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
        @=""
        .
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
        @=""
        .
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
        @=""
        .
        [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srv388]
        @="service"
        .
        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
        backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
        .
        [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
        backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
        .
        [HKLM\~\startupfolder\C:^Documents and Settings^Rachel^Start Menu^Programs^Startup^Nikon Monitor.lnk]
        backup=c:\windows\pss\Nikon Monitor.lnkStartup
        HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
        2011-04-20 16:48   58656   ----a-w-   c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
        2011-07-19 22:29   421736   ----a-w-   c:\program files\iTunes\iTunesHelper.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
        2009-10-14 18:36   2793304   ----a-w-   c:\program files\Logitech\Logitech WebCam Software\LWS.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
        2009-05-27 01:06   4351216   ----a-w-   c:\program files\Yahoo!\Messenger\YahooMessenger.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
        2008-04-14 00:12   1695232   ----a-w-   c:\program files\Messenger\msmsgs.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
        2007-09-17 16:56   124200   ------w-   c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
        2009-03-05 20:07   2260480   ------w-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
        "DisableMonitoring"=dword:00000001
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
        "DisableMonitoring"=dword:00000001
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
        "DisableMonitoring"=dword:00000001
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
        "DisableMonitoring"=dword:00000001
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
        "DisableMonitoring"=dword:00000001
        .
        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
        "%windir%\\system32\\sessmgr.exe"=
        "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
        "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
        "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
        "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
        "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
        "c:\\Documents and Settings\\Rachel\\Application Data\\mjusbsp\\magicJack.exe"=
        "c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
        "c:\\Documents and Settings\\Brian\\Application Data\\mjusbsp\\magicJack.exe"=
        "c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
        "c:\\Program Files\\iTunes\\iTunes.exe"=
        "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
        "c:\\Program Files\\Common Files\\AOL\\1208536966\\EE\\AOLServiceHost.exe"=
        "c:\\Program Files\\America Online 9.0\\waol.exe"=
        "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
        "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
        "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
        "c:\\Program Files\\FrostWire\\FrostWire.exe"=
        "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
        .
        [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
        "67:UDP"= 67:UDP:DHCP Server
        .
        R0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [9/19/2011 10:16 PM 64048]
        R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/19/2010 1:41 PM 89624]
        R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2/8/2011 10:18 PM 54776]
        R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 12:27 PM 12880]
        R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
        R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 7:38 PM 116608]
        R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/19/2010 1:40 PM 214904]
        R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/19/2010 1:40 PM 214904]
        R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/19/2010 1:41 PM 160344]
        R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/19/2010 1:41 PM 148520]
        R2 MOBKbackup;McAfee Online Backup;c:\program files\McAfee Online Backup\MOBKbackup.exe [4/13/2010 9:11 PM 229688]
        R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/19/2010 1:41 PM 57432]
        R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/19/2010 1:41 PM 338040]
        S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
        S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:06 PM 135664]
        S2 srv388;srv388;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 1:51 PM 14336]
        S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:06 PM 135664]
        S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
        S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/19/2010 1:41 PM 83688]
        S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/19/2010 1:41 PM 87808]
        S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
        .
        --- Other Services/Drivers In Memory ---
        .
        *Deregistered* - mfeavfk01
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
        getPlusHelper   REG_MULTI_SZ      getPlusHelper
        .
        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
        srv388
        .
        [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
        2009-03-08 08:32   128512   ----a-w-   c:\windows\system32\advpack.dll
        .
        Contents of the 'Scheduled Tasks' folder
        .
        2011-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
        - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
        .
        2011-09-25 c:\windows\Tasks\GlaryInitialize.job
        - c:\program files\Glary Utilities\initialize.exe [2011-08-25 22:47]
        .
        2011-09-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:06]
        .
        2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
        - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:06]
        .
        2011-09-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1006.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-09-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1007.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-08-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1008.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-09-25 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1010.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-09-25 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1006.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-09-24 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1007.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-08-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1008.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        2011-09-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1010.job
        - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
        .
        .
        ------- Supplementary Scan -------
        .
        uStart Page = hxxp://att.net
        mSearch Bar = hxxp://www.google.com/ie
        uSearchAssistant =
        IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
        IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
        Trusted Zone: 0.0.0.0
        Trusted Zone: internet
        Trusted Zone: mcafee.com
        Trusted Zone: motive.com\patttbc.att
        TCP: DhcpNameServer = 192.168.1.254
        FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\javjiaul.default\
        FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
        FF - prefs.js: browser.search.selectedEngine - Bing
        FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=Z192&install_date=20110921
        FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20110921&q=
        .
        - - - - ORPHANS REMOVED - - - -
        .
        WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
        .
        .
        .
        **************************************************************************
        .
        catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
        Rootkit scan 2011-09-25 18:15
        Windows 5.1.2600 Service Pack 3 NTFS
        .
        scanning hidden processes ... 
        .
        scanning hidden autostart entries ...
        .
        scanning hidden files ... 
        .
        .
        c:\docume~1\Brian\LOCALS~1\Temp\catchme.dll 53248 bytes executable
        .
        scan completed successfully
        hidden files: 1
        .
        **************************************************************************
        .
        [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srv388]
        "servicedll"="\\?\globalroot\Device\HarddiskVolume2\WINDOWS\Temp\srv388.tmp"
        .
        --------------------- LOCKED REGISTRY KEYS ---------------------
        .
        [HKEY_USERS\S-1-5-21-4024691547-1351141815-4135537623-1006\Software\Microsoft\SystemCertificates\AddressBook*]
        @Allowed: (Read) (RestrictedCode)
        @Allowed: (Read) (RestrictedCode)
        .
        --------------------- DLLs Loaded Under Running Processes ---------------------
        .
        - - - - - - - > 'winlogon.exe'(728)
        c:\program files\SUPERAntiSpyware\SASWINLO.DLL
        c:\windows\system32\WININET.dll
        .
        - - - - - - - > 'explorer.exe'(4064)
        c:\windows\system32\WININET.dll
        c:\windows\TEMP\logishrd\LVPrcInj01.dll
        c:\program files\McAfee Online Backup\MOBKshell.dll
        c:\windows\system32\ieframe.dll
        c:\windows\system32\webcheck.dll
        c:\windows\system32\WPDShServiceObj.dll
        c:\program files\Common Files\aolshare\aolshcpy.dll
        c:\windows\system32\PortableDeviceTypes.dll
        c:\windows\system32\PortableDeviceApi.dll
        .
        ------------------------ Other Running Processes ------------------------
        .
        c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
        c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
        c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
        c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
        c:\program files\Common Files\Motive\McciCMService.exe
        c:\windows\system32\nvsvc32.exe
        c:\program files\Dell Support Center\bin\sprtsvc.exe
        c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
        c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
        c:\windows\system32\wscntfy.exe
        c:\windows\system32\RUNDLL32.EXE
        c:\windows\RTHDCPL.EXE
        c:\progra~1\COMMON~1\AOL\120853~1\EE\AOLHOS~1.EXE
        c:\progra~1\COMMON~1\AOL\120853~1\EE\AOLServiceHost.exe
        c:\program files\Internet Explorer\IEXPLORE.EXE
        .
        **************************************************************************
        .
        Completion time: 2011-09-25  18:33:54 - machine was rebooted
        ComboFix-quarantined-files.txt  2011-09-25 22:33
        ComboFix2.txt  2011-08-18 18:05
        .
        Pre-Run: 74,548,928,512 bytes free
        Post-Run: 74,506,145,792 bytes free
        .
        - - End Of File - - 40B51F726DE01E3B225B5FEAC012FBB1



        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: New thread as requested
        « Reply #5 on: September 26, 2011, 05:54:54 PM »
        P2P - I see you have P2P software installed on your machine; (FrostWire). We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infections. It is certainly contributing to your current situation.

        Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are often infected. The bad guys use P2P filesharing as a major conduit to spread their wares.

        I would strongly recommend that you uninstall them, however that choice is up to you. If you choose to remove these programs, you can do so via Control Panel >> Add or Remove Programs.
        **************************************************
        ComboFix is running from the wrong location. Please uninstall/delete it, download a new one and install it on your desktop. Please run this CF script afterward you've downloaded a new CF.

        Re-running ComboFix to remove infections:

        • Close any open browsers.
        • Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
        • Open notepad and copy/paste the text in the quotebox below into it:
          Quote
          KillAll::
          DDS::
          Trusted Zone: 0.0.0.0
          Trusted Zone: internet
          Trusted Zone: mcafee.com
          Trusted Zone: motive.com\patttbc.att
          TB: {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - No File
          TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File
          TB: {D4027C7F-154A-4066-A1AD-4243D8127440} - No File

          DirLook::
          c:\windows\LTZ6DKQX4BIOV29G
          c:\windows\9HOU18FMSZ6DJQX3

        • Save this as CFScript.txt, in the same location as ComboFix.exe



        • Referring to the picture above, drag CFScript into ComboFix.exe
        • When finished, it shall produce a log for you at C:\ComboFix.txt
        • Please post the contents of the log in your next reply.
        Windows 8 and Windows 10 dual boot with two SSD's

        Brian Keith

          Topic Starter


          Greenhorn

          • Computer: Specs
          • Experience: Beginner
          • OS: Windows XP
          Re: New thread as requested
          « Reply #6 on: September 27, 2011, 07:12:57 PM »
          here is the corrected log that you requested...I cant find the Frostwire program ,otherwise it would be uninstalled in a flash.

          every time I open my desktop lately, there is a notepad thats pops up with some sort of message on it. wouold you care to see a copy of it...
          thank you, Sir, for all that you are doing....


          ComboFix 11-09-27.02 - Brian 09/27/2011  19:30:36.4.1 - x86
          Microsoft Windows XP Home Edition  5.1.2600.3.1252.1.1033.18.1982.1319 [GMT -4:00]
          Running from: c:\documents and settings\Brian\Desktop\ComboFix.exe
          Command switches used :: c:\documents and settings\Brian\Desktop\cfscript .txt
          AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
          FW: McAfee Firewall *Disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
          .
          .
          (((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory
          c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\dsca.exe.cf6b816f.ini
          c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory\sprtcmd.exe.63e7480d.ini.inuse
          .
          .
          (((((((((((((((((((((((((   Files Created from 2011-08-28 to 2011-09-28  )))))))))))))))))))))))))))))))
          .
          .
          2011-09-28 00:10 . 2011-09-28 00:12   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\ApplicationHistory
          2011-09-25 20:10 . 2011-09-25 20:10   --------   d-----w-   C:\_OTL
          2011-09-24 13:50 . 2011-09-24 13:50   --------   d-sh--w-   c:\documents and settings\Rachel\PrivacIE
          2011-09-24 13:47 . 2011-09-24 13:47   --------   d-sh--w-   c:\documents and settings\Rachel\IETldCache
          2011-09-23 12:53 . 2011-09-23 12:53   --------   d-sh--w-   c:\windows\system32\config\systemprofile\IETldCache
          2011-09-23 01:54 . 2011-09-23 01:54   --------   d-sh--w-   c:\documents and settings\Brian\PrivacIE
          2011-09-23 01:52 . 2011-09-23 01:52   --------   d-sh--w-   c:\documents and settings\Brian\IETldCache
          2011-09-23 01:51 . 2011-09-23 01:51   --------   d-sh--w-   c:\documents and settings\LocalService\IETldCache
          2011-09-23 01:44 . 2011-09-23 01:46   --------   dc-h--w-   c:\windows\ie8
          2011-09-22 03:14 . 2011-09-25 14:22   --------   d-----w-   c:\documents and settings\Poppa
          2011-09-22 00:39 . 2011-09-22 00:39   --------   d-----w-   c:\program files\Trend Micro
          2011-09-22 00:24 . 2011-09-22 00:24   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\Sun
          2011-09-21 23:14 . 2011-09-21 23:14   611224   ----a-w-   c:\program files\Mozilla Firefox\plugins\npdeployJava1.dll
          2011-09-21 23:14 . 2011-09-21 23:14   544656   ----a-w-   c:\windows\system32\deployJava1.dll
          2011-09-21 01:01 . 2011-09-21 01:01   --------   d-----w-   c:\documents and settings\All Users\Uniblue
          2011-09-20 22:36 . 2011-09-20 22:36   --------   d-----w-   c:\documents and settings\Brian\Application Data\SUPERAntiSpyware.com
          2011-09-20 22:35 . 2011-09-20 22:36   --------   d-----w-   c:\program files\SUPERAntiSpyware
          2011-09-20 22:35 . 2011-09-20 22:35   --------   d-----w-   c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
          2011-09-20 22:24 . 2011-09-20 22:24   --------   d-----w-   c:\program files\CCleaner
          2011-09-20 02:16 . 2011-04-11 18:29   64048   ----a-w-   c:\windows\system32\drivers\McPvDrv.sys
          2011-09-20 02:16 . 2011-09-20 02:16   --------   d-----w-   c:\documents and settings\Brian\Local Settings\Application Data\McAfee Anti-Theft
          2011-09-19 19:52 . 2011-08-19 19:56   28504   ----a-w-   c:\program files\Mozilla Firefox\ScriptFF.dll
          2011-09-12 12:07 . 2011-09-12 12:07   --------   d-----w-   c:\windows\LTZ6DKQX4BIOV29G
          2011-09-12 12:07 . 2011-09-12 12:07   --------   d-----w-   c:\windows\9HOU18FMSZ6DJQX3
          2011-09-08 22:40 . 2011-09-08 22:40   --------   d-----w-   c:\documents and settings\LocalService\Application Data\McAfee
          2011-09-08 00:04 . 2011-09-08 00:04   --------   d--h--w-   c:\documents and settings\All Users\Application Data\McAfee Security Scan
          2011-09-08 00:04 . 2011-09-08 22:39   --------   d-----w-   c:\program files\McAfee Security Scan
          .
          .
          .
          ((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          2011-09-21 23:14 . 2009-03-11 17:11   128000   ----a-w-   c:\windows\system32\javacpl.cpl
          2011-09-09 09:12 . 2004-08-10 17:50   599040   ----a-w-   c:\windows\system32\crypt32.dll
          2011-09-08 00:04 . 2011-08-27 22:19   404640   ----a-w-   c:\windows\system32\FlashPlayerCPLApp.cpl
          2011-08-31 21:00 . 2011-08-25 03:51   22216   ----a-w-   c:\windows\system32\drivers\mbam.sys
          2011-08-18 20:17 . 2011-08-18 19:47   12872   ----a-w-   c:\windows\system32\bootdelete.exe
          2011-08-18 20:01 . 2011-08-18 19:36   20552   ----a-w-   c:\windows\system32\drivers\hitmanpro35.sys
          2011-08-16 16:42 . 2011-08-16 16:42   574   ----a-w-   C:\cleanup.bat
          2011-08-15 14:00 . 2010-04-19 17:41   9344   ----a-w-   c:\windows\system32\drivers\mfeclnk.sys
          2011-08-15 14:00 . 2010-04-19 17:41   89624   ----a-w-   c:\windows\system32\drivers\mfetdi2k.sys
          2011-08-15 14:00 . 2010-04-19 17:41   87808   ----a-w-   c:\windows\system32\drivers\mferkdet.sys
          2011-08-15 14:00 . 2010-04-19 17:41   83688   ----a-w-   c:\windows\system32\drivers\mfendisk.sys
          2011-08-15 14:00 . 2010-04-19 17:41   59288   ----a-w-   c:\windows\system32\drivers\mfebopk.sys
          2011-08-15 14:00 . 2010-04-19 17:41   57432   ----a-w-   c:\windows\system32\drivers\cfwids.sys
          2011-08-15 14:00 . 2010-04-19 17:41   461864   ----a-w-   c:\windows\system32\drivers\mfehidk.sys
          2011-08-15 14:00 . 2010-04-19 17:41   338040   ----a-w-   c:\windows\system32\drivers\mfefirek.sys
          2011-08-15 14:00 . 2010-04-19 17:41   180072   ----a-w-   c:\windows\system32\drivers\mfeavfk.sys
          2011-08-15 14:00 . 2010-04-19 17:41   119808   ----a-w-   c:\windows\system32\drivers\mfeapfk.sys
          2011-07-22 11:14 . 2011-08-27 22:11   625736   ----a-w-   c:\program files\Common Files\ZugoInstaller.exe
          2011-07-15 13:29 . 2004-08-10 17:51   456320   ----a-w-   c:\windows\system32\drivers\mrxsmb.sys
          2011-07-08 14:02 . 2004-08-10 17:51   10496   ----a-w-   c:\windows\system32\drivers\ndistapi.sys
          2011-09-03 06:01 . 2011-09-03 01:43   134104   ----a-w-   c:\program files\mozilla firefox\components\browsercomps.dll
          2011-04-14 18:01 . 2010-04-19 17:41   24376   ----a-w-   c:\program files\mozilla firefox\components\Scriptff.dll
          .
          .
          ((((((((((((((((((((((((((((((((((((((((((((   Look   )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          ---- Directory of c:\windows\9HOU18FMSZ6DJQX3 ----
          .
          .
          ---- Directory of c:\windows\LTZ6DKQX4BIOV29G ----
          .
          .
          .
          (((((((((((((((((((((((((((((   SnapShot@2011-09-25_22.16.38   )))))))))))))))))))))))))))))))))))))))))
          .
          + 2011-09-28 00:05 . 2011-09-28 00:05   16384              c:\windows\temp\Perflib_Perfdata_d8.dat
          - 2008-06-04 01:45 . 2011-09-25 19:23   32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
          + 2008-06-04 01:45 . 2011-09-27 23:29   32768              c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
          - 2008-06-04 01:45 . 2011-09-25 19:23   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
          + 2008-06-04 01:45 . 2011-09-27 23:29   32768              c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
          + 2011-09-23 12:53 . 2011-09-27 18:01   16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
          - 2011-09-23 12:53 . 2011-09-25 19:23   16384              c:\windows\system32\config\systemprofile\IETldCache\index.dat
          + 2011-09-27 23:29 . 2011-09-27 23:29   16384              c:\windows\system32\config\systemprofile\Cookies\index.dat
          + 2011-09-28 00:05 . 2009-10-07 06:47   109080              c:\windows\temp\logishrd\LVPrcInj01.dll
          - 2011-09-25 22:14 . 2009-10-07 06:47   109080              c:\windows\Temp\logishrd\LVPrcInj01.dll
          .
          (((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
          .
          .
          *Note* empty entries & legit default entries are not shown
          REGEDIT4
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK]
          @="{3c3f3c1a-9153-7c05-f938-622e7003894d}"
          [HKEY_CLASSES_ROOT\CLSID\{3c3f3c1a-9153-7c05-f938-622e7003894d}]
          2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK2]
          @="{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}"
          [HKEY_CLASSES_ROOT\CLSID\{e6ea1d7d-144e-b977-98c4-84c53c1a69d0}]
          2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\MOBK3]
          @="{b4caf489-1eec-c617-49ad-8d7088598c06}"
          [HKEY_CLASSES_ROOT\CLSID\{b4caf489-1eec-c617-49ad-8d7088598c06}]
          2010-04-14 01:11   2872120   ----a-w-   c:\program files\McAfee Online Backup\MOBKshell.dll
          .
          [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
          "cdloader"="c:\documents and settings\Brian\Application Data\mjusbsp\cdloader2.exe" [2010-09-09 50592]
          "SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2011-08-12 4603264]
          .
          [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
          "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-04-07 8466432]
          "nwiz"="nwiz.exe" [2008-04-07 1626112]
          "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-04-07 81920]
          "RTHDCPL"="RTHDCPL.EXE" [2008-04-07 16859648]
          "dscactivate"="c:\program files\Dell Support Center\gs_agent\custom\dsca.exe" [2008-03-11 16384]
          "HostManager"="c:\program files\Common Files\AOL\1208536966\EE\AOLHostManager.exe" [2004-11-03 125528]
          "PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
          "DellSupportCenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
          "HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2004-02-12 49152]
          "QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-11-29 421888]
          "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-05-04 252136]
          "Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-27 35696]
          "ATT-SST_McciTrayApp"="c:\program files\ATT-SST\McciTrayApp.exe" [2008-09-19 1529856]
          "ISW.exe"="c:\program files\AT&T\Internet Security Wizard\ISW.exe" [2007-05-03 2061816]
          "mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2011-09-10 1317016]
          "HP Component Manager"="c:\program files\HP\hpcoretech\hpcmpmgr.exe" [2004-05-12 241664]
          "McPvTray_exe"="c:\program files\McAfee\MAT\McPvTray.exe" [2011-04-08 419904]
          "TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-05-27 273544]
          .
          c:\documents and settings\Brian\Start Menu\Programs\Startup\
          OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2009-2-26 97680]
          .
          [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
          "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-07-19 113024]
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
          2011-05-04 17:54   551296   ----a-w-   c:\program files\SUPERAntiSpyware\SASWINLO.DLL
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
          @=""
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
          @=""
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
          @=""
          .
          [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\srv388]
          @="service"
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
          backup=c:\windows\pss\HP Digital Imaging Monitor.lnkCommon Startup
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Image Zone Fast Start.lnk]
          backup=c:\windows\pss\HP Image Zone Fast Start.lnkCommon Startup
          .
          [HKLM\~\startupfolder\C:^Documents and Settings^Rachel^Start Menu^Programs^Startup^Nikon Monitor.lnk]
          backup=c:\windows\pss\Nikon Monitor.lnkStartup
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AppleSyncNotifier]
          2011-04-20 16:48   58656   ----a-w-   c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
          2011-07-19 22:29   421736   ----a-w-   c:\program files\iTunes\iTunesHelper.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
          2009-10-14 18:36   2793304   ----a-w-   c:\program files\Logitech\Logitech WebCam Software\LWS.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
          2009-05-27 01:06   4351216   ----a-w-   c:\program files\Yahoo!\Messenger\YahooMessenger.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
          2008-04-14 00:12   1695232   ----a-w-   c:\program files\Messenger\msmsgs.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDVDDXSrv]
          2007-09-17 16:56   124200   ------w-   c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
          2009-03-05 20:07   2260480   ------w-   c:\program files\Spybot - Search & Destroy\TeaTimer.exe
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
          "DisableMonitoring"=dword:00000001
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
          "DisableMonitoring"=dword:00000001
          .
          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
          "%windir%\\system32\\sessmgr.exe"=
          "c:\\Program Files\\CyberLink\\PowerDVD DX\\PowerDVD.exe"=
          "c:\\Program Files\\CyberLink\\PowerDVD DX\\PDVDDXSrv.exe"=
          "c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
          "%windir%\\Network Diagnostic\\xpnetdiag.exe"=
          "c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
          "c:\\Documents and Settings\\Rachel\\Application Data\\mjusbsp\\magicJack.exe"=
          "c:\\Program Files\\ATT-HSI\\McciBrowser.exe"=
          "c:\\Documents and Settings\\Brian\\Application Data\\mjusbsp\\magicJack.exe"=
          "c:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
          "c:\\Program Files\\iTunes\\iTunes.exe"=
          "c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
          "c:\\Program Files\\Common Files\\AOL\\1208536966\\EE\\AOLServiceHost.exe"=
          "c:\\Program Files\\America Online 9.0\\waol.exe"=
          "c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
          "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltpspd.exe"=
          "c:\\Program Files\\Common Files\\AOL\\TopSpeed\\2.0\\aoltsmon.exe"=
          "c:\\Program Files\\FrostWire\\FrostWire.exe"=
          "c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
          "c:\\Program Files\\Java\\jre7\\bin\\javaw.exe"=
          .
          [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
          "67:UDP"= 67:UDP:DHCP Server
          .
          R0 McPvDrv;McPvDrv Driver;c:\windows\system32\drivers\McPvDrv.sys [9/19/2011 10:16 PM 64048]
          R1 mfetdi2k;McAfee Inc. mfetdi2k;c:\windows\system32\drivers\mfetdi2k.sys [4/19/2010 1:41 PM 89624]
          R1 MOBKFilter;MOBKFilter;c:\windows\system32\drivers\MOBK.sys [2/8/2011 10:18 PM 54776]
          R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [7/22/2011 12:27 PM 12880]
          R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [7/12/2011 5:55 PM 67664]
          R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCore.exe [8/11/2011 7:38 PM 116608]
          R2 McMPFSvc;McAfee Personal Firewall Service;"c:\program files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [4/19/2010 1:40 PM 214904]
          R2 McNaiAnn;McAfee VirusScan Announcer;"c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [4/19/2010 1:40 PM 214904]
          R2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\mfefire.exe [4/19/2010 1:41 PM 160344]
          R2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [4/19/2010 1:41 PM 148520]
          R2 MOBKbackup;McAfee Online Backup;c:\program files\McAfee Online Backup\MOBKbackup.exe [4/13/2010 9:11 PM 229688]
          R3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [4/19/2010 1:41 PM 57432]
          R3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [4/19/2010 1:41 PM 338040]
          S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
          S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:06 PM 135664]
          S2 srv388;srv388;c:\windows\system32\svchost.exe -k netsvcs [8/10/2004 1:51 PM 14336]
          S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/30/2010 10:06 PM 135664]
          S3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [1/15/2010 8:49 AM 227232]
          S3 mfendisk;McAfee Core NDIS Intermediate Filter;c:\windows\system32\drivers\mfendisk.sys [4/19/2010 1:41 PM 83688]
          S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [4/19/2010 1:41 PM 87808]
          S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
          .
          --- Other Services/Drivers In Memory ---
          .
          *Deregistered* - mfeavfk01
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
          getPlusHelper   REG_MULTI_SZ      getPlusHelper
          .
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost  - NetSvcs
          srv388
          .
          [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
          2009-03-08 08:32   128512   ----a-w-   c:\windows\system32\advpack.dll
          .
          Contents of the 'Scheduled Tasks' folder
          .
          2011-09-23 c:\windows\Tasks\AppleSoftwareUpdate.job
          - c:\program files\Apple Software Update\SoftwareUpdate.exe [2011-06-01 21:57]
          .
          2011-09-28 c:\windows\Tasks\GlaryInitialize.job
          - c:\program files\Glary Utilities\initialize.exe [2011-08-25 22:47]
          .
          2011-09-28 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:06]
          .
          2011-09-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
          - c:\program files\Google\Update\GoogleUpdate.exe [2010-01-31 02:06]
          .
          2011-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1006.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1007.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-08-18 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1008.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-09-28 c:\windows\Tasks\RealUpgradeLogonTaskS-1-5-21-4024691547-1351141815-4135537623-1010.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-09-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1006.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-09-27 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1007.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-08-18 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1008.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          2011-09-22 c:\windows\Tasks\RealUpgradeScheduledTaskS-1-5-21-4024691547-1351141815-4135537623-1010.job
          - c:\program files\Real\RealUpgrade\realupgrade.exe [2011-03-29 14:47]
          .
          .
          ------- Supplementary Scan -------
          .
          uStart Page = hxxp://att.net
          mSearch Bar = hxxp://www.google.com/ie
          uSearchAssistant =
          IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
          IE: Google Sidewiki... - c:\program files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
          TCP: DhcpNameServer = 192.168.1.254
          FF - ProfilePath - c:\documents and settings\Brian\Application Data\Mozilla\Firefox\Profiles\javjiaul.default\
          FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?ei=UTF-8&fr=ytff-&p=
          FF - prefs.js: browser.search.selectedEngine - Bing
          FF - prefs.js: browser.startup.homepage - hxxp://www.msn.com/?pc=Z192&install_date=20110921
          FF - prefs.js: keyword.URL - hxxp://www.bing.com/search?pc=Z192&form=ZGAADF&install_date=20110921&q=
          .
          .
          **************************************************************************
          .
          catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
          Rootkit scan 2011-09-27 20:11
          Windows 5.1.2600 Service Pack 3 NTFS
          .
          scanning hidden processes ... 
          .
          scanning hidden autostart entries ...
          .
          scanning hidden files ... 
          .
          scan completed successfully
          hidden files: 0
          .
          **************************************************************************
          .
          [HKEY_LOCAL_MACHINE\System\ControlSet001\Services\srv388]
          "servicedll"="\\?\globalroot\Device\HarddiskVolume2\WINDOWS\Temp\srv388.tmp"
          .
          --------------------- LOCKED REGISTRY KEYS ---------------------
          .
          [HKEY_USERS\S-1-5-21-4024691547-1351141815-4135537623-1006\Software\Microsoft\SystemCertificates\AddressBook*]
          @Allowed: (Read) (RestrictedCode)
          @Allowed: (Read) (RestrictedCode)
          .
          --------------------- DLLs Loaded Under Running Processes ---------------------
          .
          - - - - - - - > 'winlogon.exe'(728)
          c:\program files\SUPERAntiSpyware\SASWINLO.DLL
          c:\windows\system32\WININET.dll
          .
          - - - - - - - > 'explorer.exe'(2616)
          c:\windows\system32\WININET.dll
          c:\windows\TEMP\logishrd\LVPrcInj01.dll
          c:\program files\McAfee Online Backup\MOBKshell.dll
          c:\windows\system32\ieframe.dll
          c:\windows\system32\webcheck.dll
          c:\windows\system32\WPDShServiceObj.dll
          c:\program files\Common Files\aolshare\aolshcpy.dll
          c:\windows\system32\PortableDeviceTypes.dll
          c:\windows\system32\PortableDeviceApi.dll
          .
          ------------------------ Other Running Processes ------------------------
          .
          c:\program files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
          c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
          c:\program files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe
          c:\program files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
          c:\program files\Common Files\Motive\McciCMService.exe
          c:\windows\system32\nvsvc32.exe
          c:\program files\Dell Support Center\bin\sprtsvc.exe
          c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
          c:\program files\Common Files\McAfee\SystemCore\mcshield.exe
          c:\windows\system32\wscntfy.exe
          c:\program files\Internet Explorer\IEXPLORE.EXE
          c:\windows\system32\RUNDLL32.EXE
          c:\windows\RTHDCPL.EXE
          c:\progra~1\COMMON~1\AOL\120853~1\EE\AOLHOS~1.EXE
          c:\progra~1\COMMON~1\AOL\120853~1\EE\AOLServiceHost.exe
          .
          **************************************************************************
          .
          Completion time: 2011-09-27  20:29:18 - machine was rebooted
          ComboFix-quarantined-files.txt  2011-09-28 00:28
          ComboFix2.txt  2011-09-27 22:46
          ComboFix3.txt  2011-09-25 22:34
          ComboFix4.txt  2011-08-18 18:05
          .
          Pre-Run: 74,407,120,896 bytes free
          Post-Run: 74,314,801,152 bytes free
          .
          - - End Of File - - 3EA495A3D7FE63C107C38A4E6540F5CD

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Re: New thread as requested
          « Reply #7 on: September 28, 2011, 04:35:25 PM »
          Quote
          I cant find the Frostwire program
          Please look for it using this:

          Delete An Uninstall Entry

          •Start HijackThis

          •Click on the Open the Misc Tools section

          •Click on the Open Uninstall Manager button.

          •Highlight the entry you want to remove.
          •Click Delete this entry
          **************************************************
          Quote
          every time I open my desktop lately, there is a notepad thats pops up with some sort of message on it. wouold you care to see a copy of it...
          Yes, please.

          SysProt Antirootkit

          Download
          SysProt Antirootkit from the link below (you will find it at the bottom
          of the page under attachments, or you can get it from one of the
          mirrors).

          http://sites.google.com/site/sysprotantirootkit/

          Unzip it into a folder on your desktop.
          • Double click Sysprot.exe to start the program.
          • Click on the Log tab.
          • In the Write to log box select the following items.
            • Process << Selected
            • Kernel Modules << Selected
            • SSDT << Selected
            • Kernel Hooks << Selected
            • IRP Hooks << NOT Selected
            • Ports << NOT Selected
            • Hidden Files << Selected
          • At the bottom of the page
            • Hidden Objects Only << Selected
          • Click on the Create Log button on the bottom right.
          • After a few seconds a new window should appear.
          • Select Scan Root Drive. Click on the Start button.
          • When it is complete a new window will appear to indicate that the scan is finished.
          • The log will be saved automatically in the same folder Sysprot.exe was extracted to. Open the text file and copy/paste the log here.
          Windows 8 and Windows 10 dual boot with two SSD's

          Brian Keith

            Topic Starter


            Greenhorn

            • Computer: Specs
            • Experience: Beginner
            • OS: Windows XP
            Re: New thread as requested
            « Reply #8 on: September 28, 2011, 07:11:29 PM »
            here is the log requested...I will post the ''Desktop note'' asap.....would frostwire be listed under any other name...
            As always....thank you



            SysProt AntiRootkit v1.0.1.0
            by swatkat

            ******************************************************************************************
            ******************************************************************************************

            No Hidden Processes found

            ******************************************************************************************
            ******************************************************************************************
            Kernel Modules:
            Module Name: \SystemRoot\System32\Drivers\dump_atapi.sys
            Service Name: ---
            Module Base: AD753000
            Module End: AD76B000
            Hidden: Yes

            Module Name: \SystemRoot\System32\Drivers\dump_WMILIB.SYS
            Service Name: ---
            Module Base: BA5DC000
            Module End: BA5DE000
            Hidden: Yes

            ******************************************************************************************
            ******************************************************************************************
            SSDT:
            Function Name: ZwTerminateProcess
            Address: B2880640
            Driver Base: B2876000
            Driver End: B2898000
            Driver Name: \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS

            ******************************************************************************************
            ******************************************************************************************
            Kernel Hooks:
            Hooked Function: ZwYieldExecution
            At Address: 8050225C
            Jump To: B9ED0314
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwUnmapViewOfSection
            At Address: 805A83DA
            Jump To: B9ED0340
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwTerminateProcess
            At Address: 805C8DA6
            Jump To: B9ED0354
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwSetValueKey
            At Address: 8061925E
            Jump To: B9ED02EA
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwSetSecurityObject
            At Address: 805B6114
            Jump To: B9ED0300
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwRenameKey
            At Address: 8061A70E
            Jump To: B9ED02BE
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwOpenThread
            At Address: 805C1684
            Jump To: B9ED026C
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwOpenProcess
            At Address: 805C13F8
            Jump To: B9ED0258
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwOpenKey
            At Address: 8061C0CA
            Jump To: B9ED0280
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwMapViewOfSection
            At Address: 805A75C4
            Jump To: B9ED032A
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwDeleteValueKey
            At Address: 8061B358
            Jump To: B9ED02D4
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwDeleteKey
            At Address: 8061B188
            Jump To: B9ED02A8
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            Hooked Function: ZwCreateKey
            At Address: 8061ACEC
            Jump To: B9ED0294
            Module Name: C:\WINDOWS\system32\drivers\mfehidk.sys

            ******************************************************************************************
            ******************************************************************************************
            Hidden files/folders:
            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Lyrics\6__Wordsmith_Feat_Ne_Yo_Keys__A_Night_to_Remember__Buzzworthy_Bangers_Vol_1_Mixtape__F
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Lyrics\7__Wordsmith__Flashbacks_of_Hope_and_Happiness__Buzzworthy_Bangers_Vol_1_Mixtape__Fros
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Lyrics\8__Wordsmith__Feat_Kontact_Whitefolkz_and_Black_Knight__The_Rigtheous_Path_Revo_Remix_
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\1__Wordsmith__Ground_Zero__Buzzworthy_Bangers_Vol_1_Mixtape__Produced_by_Streetrunner__
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\2__Wordsmith__Hear_The_Whispers__Buzzworthy_Bangers_Vol_1_Mixtape__Produced_by_Centric_
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\3__Wordsmith__In_This_Corner__Buzzworthy_Bangers_Vol_1_Mixtape__Produced_by_J-Mac__Fros
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\4__Wordsmith__Show_Me_the_Money__Buzzworthy_Bangers_Vol_1_Mixtape__Produced_by_Drum_Maj
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\5__Wordsmith_Feat_Jnes_Touch_BackDown__Buzzworthy_Bangers_Vol_1_Mixtape__Produced_by_St
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\6__Wordsmith_Feat_Ne_Yo_Keys__A_Night_to_Remember__Buzzworthy_Bangers_Vol_1_Mixtape__Pr
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\7__Wordsmith__Flashbacks_of_Hope_and_Happiness__Buzzworthy_Bangers_Vol_1_Mixtape__Produ
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\8__Wordsmith__Feat_Kontact_Whitefolkz_and_Black_Knight__The_Rigtheous_Path_Revo_Remix__
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\Bonus__The_NU_Revolution_Camp__Pressure_Cooker_Snippet__Buzzworthy_Bangers_Vol_1_Mixtap
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music\Bonus__Wordsmith_Feat_Kontact_&_Black_Knight_B_Boy_Boogiedown__Buzzwor thy_Bangers_Vol_1
            Status: Hidden

            Object: C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\Wordsmith__Buzzworthy_Bangers_Vol_1_Mixtape__FrostClick.com_FrostWire.com__MP3_VBR_256k__2010_11_25\Music_Videos\Wordsmith__and__Centric__Hear_the_Whispers__Directed_by_Funky_Monkey_Inc-Ramier_
            Status: Hidden

            Object: C:\Qoobox\BackEnv\AppData.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Cache.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Cookies.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Desktop.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Favorites.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\History.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\LocalAppData.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\LocalSettings.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Music.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\NetHood.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Personal.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Pictures.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\PrintHood.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Profiles.Folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Profiles.Folder.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Programs.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Recent.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\SendTo.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\SetPath.bat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\StartMenu.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\StartUp.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\SysPath.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\Templates.folder.dat
            Status: Access denied

            Object: C:\Qoobox\BackEnv\VikPev00
            Status: Access denied


            Brian Keith

              Topic Starter


              Greenhorn

              • Computer: Specs
              • Experience: Beginner
              • OS: Windows XP
              Re: New thread as requested
              « Reply #9 on: September 28, 2011, 07:26:39 PM »
              Here is what comes up everytime I log on... it didnt start till this unfortunate situation began....

              [.ShellClassInfo]
              LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

              Thanks Superdave

              SuperDave

              • Malware Removal Specialist


              • Genius
              • Thanked: 1020
              • Certifications: List
              • Experience: Expert
              • OS: Windows 10
              Re: New thread as requested
              « Reply #10 on: September 29, 2011, 04:43:24 PM »
              Quote
              would frostwire be listed under any other name...
              No. I see it listed under Program Files and a lot of the files you download are from FrostWire.
              Quote
              Here is what comes up everytime I log on... it didnt start till this unfortunate situation began....

              [.ShellClassInfo]
              LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21787

              Here's what I found about the problem.

              I'd like to scan your machine with ESET OnlineScan

              •Hold down Control and click on the following link to open ESET OnlineScan in a new window.
              ESET OnlineScan
              •Click the button.
              •For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
              • Click on to download the ESET Smart Installer. Save it to your desktop.
              • Double click on the icon on your desktop.
              •Check
              •Click the button.
              •Accept any security warnings from your browser.
              •Check
              •Push the Start button.
              •ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
              •When the scan completes, push
              •Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
              •Push the button.
              •Push
              A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
              Windows 8 and Windows 10 dual boot with two SSD's

              Brian Keith

                Topic Starter


                Greenhorn

                • Computer: Specs
                • Experience: Beginner
                • OS: Windows XP
                Re: New thread as requested
                « Reply #11 on: September 29, 2011, 11:04:19 PM »
                here is the log of the ESET scan
                all ok
                # version=7
                # OnlineScannerApp.exe=1.0.0.1
                # OnlineScanner.ocx=1.0.0.6528
                # api_version=3.0.2
                # EOSSerial=02412504ee340e44b297d9987a63692c
                # end=finished
                # remove_checked=true
                # archives_checked=true
                # unwanted_checked=true
                # unsafe_checked=false
                # antistealth_checked=true
                # utc_time=2011-09-30 04:45:00
                # local_time=2011-09-30 12:45:00 (-0500, Eastern Daylight Time)
                # country="United States"
                # lang=1033
                # osver=5.1.2600 NT Service Pack 3
                # compatibility_mode=512 16777215 100 0 0 0 0 0
                # compatibility_mode=5121 16777173 100 75 2986034 17728211 0 0
                # compatibility_mode=8192 67108863 100 0 0 0 0 0
                # scanned=156192
                # found=17
                # cleaned=17
                # scan_time=13170
                C:\Documents and Settings\Brian\My Documents\Downloads\cnet_jre-7-windows-i586_exe.exe   a variant of Win32/InstallCore.C application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\FrostWire\Saved\tonites gonna be good night new hot single.au   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\Preview-T-4070425-madad muhammed muner.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\Preview-T-4415841-madad muhammed muner [new album].au   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\Preview-T-5937977-3 words new single.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\T-1010769-dont think im not kandi.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\T-3545427-every rose has its thorns.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\T-5088466-didi milk honey.snd   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Incomplete\T-5937977-3 words new single.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Saved\Copy of Drop Kick Murphys - Beer in the Shower.wma   WMA/TrojanDownloader.Wimad.NAG trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Saved\Drop Kick Murpheys - Barroom Hero.wma   WMA/TrojanDownloader.Wimad.NAD trojan (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Saved\take me on florr veronicas.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Documents and Settings\Rachel\My Documents\LimeWire\Saved\wild at heart glorianna hot new track.mp3   a variant of WMA/TrojanDownloader.GetCodec.gen trojan (cleaned - quarantined)   00000000000000000000000000000000   C
                C:\Program Files\Common Files\ZugoInstaller.exe   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
                C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1006\A0371524.exe   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
                C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1006\A0371525.exe   a variant of Win32/InstallCore.B application (cleaned by deleting - quarantined)   00000000000000000000000000000000   C
                C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1042\A0426606.exe   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
                ESETSmartInstaller@High as downloader log:
                all ok


                IS IT SAFE TO FIX THE NOTEPAD SITUATION......

                thank you

                SuperDave

                • Malware Removal Specialist


                • Genius
                • Thanked: 1020
                • Certifications: List
                • Experience: Expert
                • OS: Windows 10
                Re: New thread as requested
                « Reply #12 on: September 30, 2011, 04:40:21 PM »
                Quote
                IS IT SAFE TO FIX THE NOTEPAD SITUATION......
                Yes, go ahead and fix it. We can also do some cleanup.

                To uninstall ComboFix

                • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
                • In the field, type in ComboFix /uninstall


                (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

                • Then, press Enter, or click OK.
                • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
                ***********************************************
                To remove all of the tools we used and the files and folders they created do the following:
                Double click OTL.exe.
                • Click the CleanUp button.
                • Select Yes when the "Begin cleanup Process?" prompt appears.
                • If you are prompted to Reboot during the cleanup, select Yes.
                • The tool will delete itself once it finishes.
                Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
                *********************************************
                Clean out your temporary internet files and temp files.

                Download TFC by OldTimer to your desktop.

                Double-click TFC.exe to run it.

                Note: If you are running on Vista, right-click on the file and choose Run As Administrator

                TFC will close all programs when run, so make sure you have saved all your work before you begin.

                * Click the Start button to begin the cleaning process.
                * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
                * Please let TFC run uninterrupted until it is finished.

                Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
                ***********************************************

                Go to Microsoft Windows Update and get all critical updates.

                ----------

                I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

                SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
                * Using SpywareBlaster to protect your computer from Spyware and Malware
                * If you don't know what ActiveX controls are, see here

                Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

                Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

                Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
                Safe Surfing!
                Windows 8 and Windows 10 dual boot with two SSD's