1.

Solve : Trojan,Adware,Malware?

Answer»

Thank you for your time in advance. I just got this computer from another person, and I followed the Malware Removal Guide on this website to a T. I have fully updated versions of AVG, Online Armor, SUPER Anti-Spyware, Malwarebytes anti-malware. Again I've followed that guide to a T. Since I am not an expert at this, how do I know if my computer is 100% clean and safe to use? I have sensitive data that I need this computer for, but I'm not going to start until I know it is 100% clean. I also have the logs for anti-spyware, MBAM, and hijackthis ready and waiting on my desktop. Thank you for your time and help.If you don't know the history of the computer, the only way to know that it is absolutely clean is to do a re-format and re-install the Operating System. The computer may have had some serious infections that may have compromised the security of the machine. I've included the warning below that we give to those whose computers have been affected. This is very important especially if you're going to use this computer for financial transactions. We can run scans and check the logs but we can't guarantee it's security.

A backdoor trojan.

This allows hackers to remotely control your computer, steal critical system information and Download and Execute files

Read this article: Danger: Remote Access Trojans.

If your computer was used for online banking, has credit card information or other sensitive data on it, all passwords should be changed immediately to include those used for banking, email, eBay and forums. You should consider them to be compromised. They should be changed by using a different computer and not the infected one! If not, an attacker may get the new passwords and transaction information. Banking and credit card institutions should be notified of the possible security breach.

I would counsel you to disconnect this PC from the Internet immediately.

Though the Trojan has been identified and can be killed, because of it's backdoor functionality, your PC is very LIKELY compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of Trojan, the best course of action would be a reformat and reinstall of the OS. Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?

When Should I Format, How Should I Reinstall?

We can attempt to clean this machine but i can't guarantee that it will be 100% secure afterwards.

Should you have any questions, please feel free to ask.

Please let us know what you have decided to do in your next postI don't have any personally or financially identifiable information on this computer. And I won't start either. This is a home PC with Windows XP service pack 2 running. I use this computer for surfing the internet/watching movies/video games/ and music. Nothing else. I would like to go ahead and try to secure/clean this computer as much as possible. Unfortunately this is my father's PC who passed away a few months ago, and all of the XP re-install discs are missing. So re-installing isn't much of an option. Any help would be great, thank you.First of all, my sincere condolences. Let's run some scans to see what we have. Could you please copy and paste the logs that you have from the different scans that you've run already

Download Security Check by screen317 from one of the following links and save it to your desktop.

Link 1
Link 2

* Unzip SecurityCheck.zip and a folder named Security Check should appear.
* Open the Security Check folder and double-click Security Check.bat
* Follow the on-screen instructions inside of the black box.
* A Notepad document should open automatically called checkup.txt
* Post the contents of that document in your next reply.

Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

If I'm reading this correctly then this is uglier than I thought.

SUPERAntiSpyware Scan Log
http://www.superantispyware.com

Generated 06/03/2010 at 07:28 AM

Application Version : 4.38.1004

Core Rules Database Version : 5024
Trace Rules Database Version: 2836

Scan type : Complete Scan
Total Scan Time : 03:37:45

Memory items scanned : 489
Memory threats detected : 0
Registry items scanned : 6314
Registry threats detected : 0
File items scanned : 158689
File threats detected : 220

Adware.HotBar/SpamBlockerUtility (Low Risk)
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\3_Shot Gun.wav
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\ASAPCom.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\Redemption.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBClientSinkPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBInst.exe
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBOLExp.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBOLExt.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBSrvPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBTrayAppPS.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBUIRes.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SBUISkin.dll
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SpamBlocker.exe
C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0
C:\Program Files\SpamBlockerUtility\Bin\SbUninst.exe
C:\Program Files\SpamBlockerUtility\Bin
C:\Program Files\SpamBlockerUtility\SBTV\sbtvau.dat
C:\Program Files\SpamBlockerUtility\SBTV\sbtv_hpk.dat
C:\Program Files\SpamBlockerUtility\SBTV\sbtv_kyf.dat
C:\Program Files\SpamBlockerUtility\SBTV
C:\Program Files\SpamBlockerUtility

Trojan.Media-Codec
C:\Program Files\Perfect Codec

Adware.Tracking Cookie
.2o7.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.aprilteens.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigbanners.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bigfreesex.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bravenet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.bs.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.burstnet.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.cs.sexcounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.discount-cigarettes-store.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.e-2dj6wfmyaiajagp.stats.esomniture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.edge.ru4.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.elitematureporn.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.estat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.fortunecity.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.fortunecity.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.freefind.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.funwebproducts.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.gostats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hairypornpics.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hairypornpics.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.hurricanedigitalmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.icc.intellisrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.imrworldwide.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpressai.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.insightexpresserdd.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.internet-*adult URL* [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.kanoodle.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.locator.metadata.windowsmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.maxserving.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.metareward.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.mywebsearch.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.naked-celebrityes.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.onlinerewardcenter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.paycounter.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.perf.overture.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.*censored*-paradise.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qksrv.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.qnsr.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.realmedia.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.revenue.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.roiservice.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sav.coolsavings.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.serving-sys.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sex-superstore.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.sex-superstore.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.smileycentral.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.stat.onestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tacoda.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.tribalfusion.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.uk.sitestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.uk.sitestat.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valuead.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.valueclick.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.webpower.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.webpower.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wetrack.it [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.wvw.silkroadtech.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.3dstats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.bigtitpornstars.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dapornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dialysisfinder.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.dialysisfinder.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.girlsfuckinghard.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.internet-*adult URL* [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.jimmyspornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.jimmyspornstars.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.porninspector.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.*censored*-galleries.net [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.sexsweety.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www.toyboxxx.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www1.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www3.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www4.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.www5.addfreestats.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xiti.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xxxcreatures.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
.xxxcreatures.com [ C:\Documents and Settings\HP_Owner\Application Data\Mozilla\Firefox\Profiles\i0o7rq8j.default\cookies.txt ]
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected].bridgetrack[2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][1].txt
C:\Documents and Settings\HP_Owner\Cookies\[emailprotected][2].txt

Trojan.Agent/Gen-Tmp[27]
C:\DOCUMENTS AND SETTINGS\HP_OWNER\LOCAL SETTINGS\TEMP\1E.TMP

Rootkit.TDSServ/Fake
C:\DOCUMENTS AND SETTINGS\HP_OWNER\LOCAL SETTINGS\TEMP\TDSS6B19.TMP

Unclassified.Unknown Origin
C:\PYTHON22\NMSKSSRVC.EXE

MBAM

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4168

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

6/3/2010 4:14:36 PM
mbam-log-2010-06-03 (16-14-36).txt

Scan type: Quick scan
Objects scanned: 164981
Time elapsed: 33 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry VALUES Infected: 0
Registry Data Items Infected: 0
Folders Infected: 42
Files Infected: 1165

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
C:\Documents and Settings\HP_Owner\Application Data\SpamBlocker (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\eskin (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\IESkins (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0 (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\dynamic (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOL\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\344stat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML (Adware.Hotbar) -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\TooltipXML (Adware.Hotbar) -> Files: 1569 -> Delete on reboot.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\dynamic\ustat (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\1 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\2 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static\DownLoad (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0 (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\LocalService\Application Data\SpamBlockerUtility\v3.0\SpamBlockerUtility\static (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility_Icons (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0 (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\repair-bar (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\scan-bar-100 (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\Angle Interactive\RD Platinum v5.0\scan-bar-pulse (Rogue.RegistryDefender) -> Quarantined and deleted successfully.
C:\Program Files\MySearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Cache (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\MySearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully.
C:\Program Files\VVSN (Adware.WhenU) -> Quarantined and deleted successfully.
C:\Program Files\VVSN\URL2 (Adware.WhenU) -> Quarantined and deleted successfully.

Files Infected:
C:\Documents and Settings\HP_Owner\Local Settings\Temp\TDSS6bf3.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1184993395.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185048657.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185206559.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185223343.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185241841.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185399928.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185426751.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1185723951.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1186768111.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1187659084.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1188678814.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1189729597.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1190862601.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1191729391.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1193332121.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1194987890.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1196740502.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1199730375.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1202187586.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1204482847.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1205864239.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1208402346.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1210353729.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1212436305.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1215273810.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1217300433.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1218306053.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1219938068.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1222282807.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1224267785.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1226642864.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1227767493.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1229060932.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1230267080.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1232946843.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1240201362.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1246971787.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1251334694.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1252165073.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1252853416.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\SpamBlockerUtility_1254280043.log (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte10_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte11_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte12_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte13_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte14_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte19_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte20_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte21_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030104_emte9_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\030203lib_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102angel_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102bigluf_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102bigsmile_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102birthday_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102cheers_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102flo_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102good_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102jump_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102king_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102lough_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102luf_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102smiled_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102smile_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102sor_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102thanx_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\033102uhu_1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040103ahh_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040103wow_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\040104_emi2_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\042102_1134_112_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103big_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103gig_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103hm_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103nomail_emoti_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\050103norm_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema15_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema16_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema17_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema18_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema19_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema20_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema21_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema24_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema25_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema26_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema30_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema33_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\060104_ema34_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\062802hippi_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\062802jumpie_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402argh_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402oops_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\080402ouch_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\082502no_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\082502yes_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_boring1_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_confused_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_crying_ugly_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_fantastic_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_feel_better_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_gimme_break_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_heehee_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_hlopaet_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_ign_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_lol_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_no_comment_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_peace_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_smashing_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\110103_talk2thehand_prv.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\blocked.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\blocked2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_sm.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_sm2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_smli.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\block_smli2.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_add-but.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_back-but.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_cut_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_left_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_middle_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_middle_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_cut_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_enabled_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\btn_right_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\business_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\buttondir.txt (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\components.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_main.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_pagingmodule.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css2_topbuttons.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css_cattree.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\css_flashpreview.css (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\delete.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_clear_sound.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_fs.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\edit_select.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-511724-549108.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-511724-9595.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-backgrounds.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-bcards.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-ecards.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-emoticons.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-estationery.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-funny.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-help.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-images.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-info.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-more.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-my.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-new.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-new2.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-options.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-people.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-photo.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-SpamBlocked.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-tell.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-temp.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-text.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def-email-voice.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-def.cdf (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-premium-email-premium.mnu (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-t7-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\email-temp-bg.res (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\estatationery.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\flashpatch.js (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\flashpreview.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\fs3.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\hotbar_promo.htm (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_checked_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_close_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_close_pressed_1.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_edit_preview.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_edit_send.gif (Adware.Hotbar) -> Quarantined and deleted successfully.
C:\Documents and Settings\HP_Owner\Application Data\SpamBlockerUtility\v3.0\HostOI\static\1\icon_flash_preview.gif (Adware.Hotbar) -> QuarantinDo you have a HJT log and the Security Check log?Sorry I completely spaced it .

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:02:30 PM, on 6/3/2010
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Tall Emu\Online Armor\OAcat.exe
C:\Program Files\Tall Emu\Online Armor\oasrv.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\Program Files\AVG\AVG9\avgam.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\ps2.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Napster\napster.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Tall Emu\Online Armor\oaui.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Tall Emu\Online Armor\OAhlp.exe
C:\Program Files\AVG\AVG9\Identity Protection\agent\bin\avgidsmonitor.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HiJackThis\sniper.exe.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MSN Toolbar BHO - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: MSN Toolbar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\npwinext.dll
O4 - HKLM\..\Run: [HPHUPD06] c:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [IS CfgWiz] c:\Program Files\Common Files\Symantec Shared\cfgwiz.exe /GUID NIS /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb10.exe
O4 - HKLM\..\Run: [MSN Toolbar] "C:\Program Files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe"
O4 - HKLM\..\Run: [Microsoft Default Manager] "C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" -resume
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKLM\..\Run: [@OnlineArmor GUI] "C:\Program Files\Tall Emu\Online Armor\oaui.exe"
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [YSearchProtection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [DriverUpdaterPro] C:\Program Files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe -t
O4 - Global Startup: WinCinema Manager.lnk = C:\Program Files\Sandisk\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\309731\Program\Updates from HP.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra BUTTON: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O16 - DPF: {A9F8D9EC-3D0A-4A60-BD82-FBD64BAD370D} (DDRevision Class) - http://h20264.www2.hp.com/ediags/dd/install/HPDriverDiagnosticsxp2k.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: AVG WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: AVG9IDSAgent (AVGIDSAgent) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Online Armor Helper Service (OAcat) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\OAcat.exe
O23 - Service: Online Armor (SvcOnlineArmor) - Unknown owner - C:\Program Files\Tall Emu\Online Armor\oasrv.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe

--
End of file - 10098 BYTES



Results of screen317's Security Check version 0.99.4
Windows XP Service Pack 2
Out of date service pack!!
Internet Explorer 8
``````````````````````````````
Antivirus/Firewall Check:

Windows Firewall Enabled!
AVG 9.0
Norton Personal Firewall
Online Armor 4.0
```````````````````````````````
Anti-malware/Other Utilities Check:

Malwarebytes' Anti-Malware
CCleaner
Java(TM) 6 Update 20
Adobe Flash Player 10.0.45.2
Adobe Reader 6.0.1
Out of date Adobe Reader installed!
Mozilla Firefox (3.6.3)
````````````````````````````````
Process Check:
objlist.exe by Laurent

AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgrsx.exe
AVG avgnsx.exe
AVG avgemc.exe
Tall Emu Online Armor OAcat.exe
````````````````````````````````
DNS Vulnerability Check:

REQUEST Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)

``````````End of Log````````````
Download Disable/Remove Windows Messenger to the desktop to remove Windows Messenger.

Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

Unzip the file on the desktop. Open the MessengerDisable.exe and choose the bottom box - Uninstall Windows Messenger and click Apply.

Exit out of MessengerDisable then delete the two files that were put on the desktop.

==============================

Open HijackThis and select Open the Misc Tools section. Select open process manager. select
C:\WINDOWS\ALCXMNTR.EXE

and click on kill process. Exit HJT.
----------------------------------------------

Click Start, Search, select All Files and Folders. Copy and paste
Code: [Select]C:\WINDOWS\ALCXMNTR.EXE and click search. Delete this file.

=================================

Please download the newest version of Adobe Acrobat Reader from Adobe.com

Be sure to uncheck the Free McAfee Security Scan so it isn't installed.

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==================================

The Security Check shows that you are running more than one Firewall which is a no-no. Windows Firewall Enabled
Norton Personal Firewall Online Armor 4.0 . Two of them should be disabled and removed. The Windows Firewall is not very good because it only protects against incoming traffic and not against out-going traffic which can be most harmful. Windows Firewall can't be uninstall. It's intergrated with XP. It can only be disabled.

==============================

Open HijackThis and select Do a system scan only

Place a check mark next to the following entries: (if there)

R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe


Important: Close all open windows except for HijackThis and then click Fix checked.

Once completed, exit HijackThis.

=================================

Download ComboFix by sUBs from one of the below links.

Important! You MUST save ComboFix to your desktop

link # 1
Link # 2

Temporarily disable your Anti-virus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

Double click on ComboFix.exe & follow the prompts.

Vista users Right-Click on ComboFix.exe and select Run as administrator (you will receive a UAC prompt, please allow it)

Do not mouse-click ComboFix's window while it is running. That may cause it to stall.

When the scan completes it will open a text window.

Post the contents of that log in your next reply.

Remember to re-enable your Anti-virus and Antispyware protection when ComboFix is complete.

ComboFix 10-06-05.01 - HP_Owner 06/05/2010 23:58:45.1.1 - x86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.383.172 [GMT -7:00]
Running from: c:\documents and settings\HP_Owner.RACER\Desktop\ComboFix.exe
AV: AVG Internet Security *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
FW: Online Armor Firewall *disabled* {B797DAA0-7E2E-4711-8BB3-D12744F1922A}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\LocalService\Application Data\alot
c:\program files\alot
c:\program files\alot\alotUninst.exe
c:\program files\alot\bin\alot.dll
c:\program files\Mozilla Firefox\plugins\NPMorpBr.dll
c:\windows\Downloaded Program Files\f3initialsetup1.0.0.15.inf
c:\windows\Fonts\acrsec.fon
c:\windows\system32\drivers\etc\lmhosts
c:\windows\system32\pthreadVC.dll
D:\Autorun.inf

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

-------\Legacy_NPF


((((((((((((((((((((((((( Files Created from 2010-05-06 to 2010-06-06 )))))))))))))))))))))))))))))))
.

2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Malwarebytes
2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\documents and settings\All Users\Application Data\Malwarebytes
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\SUPERAntiSpyware.com
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-06-02 19:56 . 2010-06-02 19:56--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\AVG9
2010-06-01 03:44 . 2010-06-01 03:49--------d-----w-c:\documents and settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-05-31 10:37 . 2010-05-31 11:27--------d-----w-c:\documents and settings\All Users\Application Data\OnlineArmor
2010-05-31 10:37 . 2010-05-31 10:37--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\OnlineArmor
2010-05-31 05:56 . 2010-05-31 05:56--------d-----w-c:\documents and settings\All Users\Application Data\avg9
2010-05-30 06:25 . 2010-05-30 06:25--------d-----w-c:\documents and settings\All Users\Application Data\Qwest
2010-05-27 05:12 . 2010-05-27 05:12--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Intuit

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-06 06:27 . 2005-06-17 13:26--------d-----w-c:\program files\Common Files\Adobe
2010-06-06 06:11 . 2007-05-08 05:27--------d--h--r-c:\documents and settings\All Users\Application Data\yahoo!
2010-06-06 06:11 . 2005-08-15 05:00--------d-----w-c:\program files\Yahoo!
2010-06-06 06:11 . 2010-01-15 01:41--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Yahoo!
2010-06-04 08:52 . 2008-12-09 06:03--------d-----w-c:\program files\Google
2010-06-04 07:11 . 2010-06-04 07:11--------d-----w-c:\program files\EA Games
2010-06-04 07:11 . 2004-12-02 05:41--------d--h--w-c:\program files\InstallShield Installation Information
2010-06-03 23:58 . 2010-06-03 23:58--------d-----w-c:\program files\Trend Micro
2010-06-03 23:53 . 2004-12-02 05:15--------d-----w-c:\program files\Java
2010-06-03 23:43 . 2004-12-02 05:15--------d-----w-c:\program files\Common Files\Java
2010-06-03 23:41 . 2010-06-03 23:42411368----a-w-c:\windows\system32\deployJava1.dll
2010-06-03 22:29 . 2010-06-03 22:29--------d-----w-c:\program files\Malwarebytes' Anti-Malware
2010-06-03 10:42 . 2010-06-03 10:42--------d-----w-c:\program files\SUPERAntiSpyware
2010-06-03 10:31 . 2010-06-03 10:31--------d-----w-c:\program files\CCleaner
2010-06-02 00:36 . 2010-01-15 00:43--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Apple Computer
2010-06-01 21:10 . 2010-05-31 06:00242896----a-w-c:\windows\system32\drivers\avgtdix.sys
2010-06-01 21:10 . 2010-05-31 06:0029584----a-w-c:\windows\system32\drivers\avgmfx86.sys
2010-06-01 05:08 . 2009-06-08 18:15--------d-----w-c:\program files\Bonjour
2010-06-01 03:49 . 2004-12-02 05:46--------d-----w-c:\program files\iTunes
2010-06-01 03:12 . 2006-11-01 02:47--------d-----w-c:\program files\Napster
2010-06-01 02:37 . 2010-05-31 23:54--------d-----w-c:\program files\RadarSync
2010-06-01 02:36 . 2010-01-15 02:20--------d-----w-c:\program files\Shockwave.com
2010-06-01 02:28 . 2010-01-17 03:31--------d-----w-c:\program files\WildTangent
2010-05-31 23:56 . 2010-01-17 22:5842472----a-w-c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-05-31 23:17 . 2010-05-31 23:17--------d-----w-c:\program files\iXi Tools
2010-05-31 21:45 . 2010-05-31 21:45--------d-----w-c:\program files\sisagp
2010-05-31 20:46 . 2004-12-02 05:54--------d-----w-c:\program files\PC-Doctor for Windows
2010-05-31 20:26 . 2004-12-02 06:07--------d-----w-c:\program files\Common Files\Symantec Shared
2010-05-31 19:58 . 2004-12-02 06:07--------d-----w-c:\program files\Symantec
2010-05-31 19:58 . 2004-12-02 06:07--------d-----w-c:\documents and settings\All Users\Application Data\Symantec
2010-05-31 19:51 . 2004-12-02 05:41--------d-----w-c:\program files\IntelliMover Data Transfer Demo
2010-05-31 19:49 . 2004-12-02 05:55--------d-----w-c:\program files\Easy Internet signup
2010-05-31 11:07 . 2004-12-02 06:08--------d-----w-c:\program files\Norton AntiVirus
2010-05-31 10:35 . 2010-05-31 10:35--------d-----w-c:\program files\Tall Emu
2010-05-31 08:52 . 2004-12-02 05:46--------d-----w-c:\program files\QuickTime
2010-05-31 08:46 . 2006-11-06 20:04--------d-----w-c:\program files\Apple Software Update
2010-05-31 06:00 . 2010-05-31 06:0012464----a-w-c:\windows\system32\avgrsstx.dll
2010-05-31 06:00 . 2010-05-31 06:0052872----a-w-c:\windows\system32\drivers\avgrkx86.sys
2010-05-31 06:00 . 2010-05-31 06:0025096----a-w-c:\windows\system32\drivers\AVGIDSxx.sys
2010-05-31 06:00 . 2010-05-31 06:00216200----a-w-c:\windows\system32\drivers\avgldx86.sys
2010-05-31 05:57 . 2010-05-31 05:57--------d-----w-c:\program files\AVG
2010-05-31 05:13 . 2010-05-31 01:55--------d-----w-c:\program files\Belkin
2010-05-30 06:23 . 2010-05-30 06:23--------d-----w-c:\program files\Xenocode
2010-05-29 05:17 . 2006-11-25 02:46--------d-----w-c:\program files\GameFiesta
2010-05-28 01:33 . 2010-05-28 01:33--------d-----w-c:\program files\Common Files\AnswerWorks 5.0
2010-05-28 01:32 . 2005-06-15 16:50--------d-----w-c:\program files\Quicken
2010-05-27 05:11 . 2010-01-15 00:43--------d-----w-c:\documents and settings\HP_Owner.RACER\Application Data\Symantec
2010-04-29 22:39 . 2010-06-03 22:2938224----a-w-c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 22:39 . 2010-06-03 22:2920952----a-w-c:\windows\system32\drivers\mbam.sys
2010-04-20 11:13 . 2010-05-31 10:3524440----a-w-c:\windows\system32\drivers\OAmon.sys
2010-04-20 11:13 . 2010-05-31 10:3529560----a-w-c:\windows\system32\drivers\OAnet.sys
2010-04-20 11:13 . 2010-05-31 10:35228216----a-w-c:\windows\system32\drivers\OADriver.sys
2010-04-12 09:40 . 2004-12-02 05:1819200----a-w-c:\windows\system32\drivers\srvkp.sys
2010-04-12 09:40 . 2004-12-02 05:181571001----a-w-c:\windows\system32\sisgl.dll
2010-04-12 09:22 . 2004-12-02 05:183468288----a-w-c:\windows\system32\sisgrv.dll
2010-04-12 09:17 . 2004-12-02 05:18324608----a-w-c:\windows\system32\drivers\sisgrp.sys
2010-04-12 09:08 . 2010-04-12 09:089728----a-w-c:\windows\system32\SiSPIns2.dll
2010-04-12 09:07 . 2005-06-18 03:1412288----a-w-c:\windows\InstFunc.dll
2010-04-12 09:07 . 2004-12-02 05:18172032----a-w-c:\windows\system32\SiSInst.dll
2010-04-12 09:07 . 2004-12-02 05:18258048----a-w-c:\windows\system32\SiSParse.dll
2010-04-12 09:06 . 2004-12-02 05:1849152----a-w-c:\windows\system32\SiSBase.dll
2010-04-08 20:20 . 2010-04-08 20:2091424----a-w-c:\windows\system32\dnssd.dll
2010-04-08 20:20 . 2010-04-08 20:20107808----a-w-c:\windows\system32\dns-sd.exe
2010-03-10 06:15 . 2004-08-04 11:00420352----a-w-c:\windows\system32\vbscript.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-05-31 136176]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HPHUPD06"="c:\program files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe" [2004-06-07 49152]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2004-04-18 196608]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-02-17 81920]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"NapsterShell"="c:\program files\Napster\napster.exe" [2009-10-06 323280]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb10.exe" [2004-03-04 172032]
"MSN Toolbar"="c:\program files\MSN Toolbar\Platform\4.0.0379.0\mswinext.exe" [2009-12-09 240992]
"Microsoft Default Manager"="c:\program files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe" [2009-07-17 288080]
"@OnlineArmor GUI"="c:\program files\Tall Emu\Online Armor\oaui.exe" [2010-04-20 6678008]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 52736]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-03-18 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-04-28 142120]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2004-12-02 180269]
"AGRSMMSG"="AGRSMMSG.exe" [2004-06-29 88363]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinCinema Manager.lnk - c:\program files\Sandisk\Common\Bin\WinCinemaMgr.exe [2010-1-29 303104]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2004-5-29 241664]
SpySubtract.lnk - c:\program files\interMute\SpySubtract\SpySub.exe [2006-5-4 1187840]
Updates from HP.lnk - c:\program files\Updates from HP\309731\Program\Updates from HP.exe [2004-12-1 45056]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{4F07DA45-8170-4859-9B5F-037EF2970034}"= "c:\progra~1\TALLEM~1\ONLINE~1\oaevent.dll" [2010-04-20 925688]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21548352----a-w-c:\program files\SUPERAntiSpyware\SASWINLO.DLL

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2010-05-31 06:0012464----a-w-c:\windows\system32\avgrsstx.dll

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\309731\\Program\\Updates from HP.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgam.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgdiagex.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG9\\avgnsx.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\WINDOWS\\system32\\dlbtcoms.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"1308:UDP"= 1308:UDP:Windows Media Format SDK (napster.exe)
"1309:UDP"= 1309:UDP:Windows Media Format SDK (napster.exe)

R0 AVGIDSErHrxpx;AVG9IDSErHr;c:\windows\system32\drivers\AVGIDSxx.sys [5/30/2010 11:00 PM 25096]
R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [5/30/2010 11:00 PM 52872]
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [5/30/2010 11:00 PM 216200]
R1 AvgTdiX;AVG Network Redirector;c:\windows\system32\drivers\avgtdix.sys [5/30/2010 11:00 PM 242896]
R1 OADevice;OADriver;c:\windows\system32\drivers\OADriver.sys [5/31/2010 3:35 AM 228216]
R1 OAmon;OAmon;c:\windows\system32\drivers\OAmon.sys [5/31/2010 3:35 AM 24440]
R1 OAnet;OAnet;c:\windows\system32\drivers\OAnet.sys [5/31/2010 3:35 AM 29560]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 11:25 AM 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 11:41 AM 67656]
R2 avg9wd;AVG WatchDog;c:\program files\AVG\AVG9\avgwdsvc.exe [5/30/2010 10:58 PM 308064]
R2 AVGIDSAgent;AVG9IDSAgent;c:\program files\AVG\AVG9\Identity Protection\Agent\Bin\AVGIDSAgent.exe [5/30/2010 10:58 PM 5888008]
R3 AVGIDSDriverxpx;AVG9IDSDriver;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSDriver.sys [5/30/2010 10:58 PM 122376]
R3 AVGIDSFilterxpx;AVG9IDSFilter;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSFilter.sys [5/30/2010 10:58 PM 30216]
R3 AVGIDSShimxpx;AVG9IDSShim;c:\program files\AVG\AVG9\Identity Protection\Agent\Driver\Platform_XP\AVGIDSShim.sys [5/30/2010 10:58 PM 26120]
R3 RTL8192su;%RTL8192su.DeviceDesc.DispName%;c:\windows\system32\drivers\RTL8192su.sys [5/30/2010 10:08 PM 594048]

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
2009-03-08 12:32128512----a-w-c:\windows\system32\advpack.dll
.
Contents of the 'Scheduled Tasks' folder

2010-02-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]

2010-06-03 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-12-09 18:30]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-04 08:43]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-06-04 08:43]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750873676-2119400782-1055263353-1009Core.job
- c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-31 06:39]

2010-06-06 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1750873676-2119400782-1055263353-1009UA.job
- c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-05-31 06:39]

2010-06-05 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-04-04 01:12]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/?fr=fp-yie8
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
mSearch Bar = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q105&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = *.local
uSearchAssistant =
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\HP_Owner.RACER\Application Data\Mozilla\Firefox\Profiles\5uge2q0r.default\
FF - component: c:\program files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\components\SEPsearchhelperff.dll
FF - plugin: c:\documents and settings\HP_Owner.RACER\Local Settings\Application Data\Google\Update\1.2.183.23\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMySrch.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npstrlnk.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npWTHost.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_ everywhere__temporarily_available_pref", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_a s_broken", false);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-Search Protection - c:\program files\Yahoo!\Search Protection\SearchProtection.exe
HKCU-Run-DriverUpdaterPro - c:\program files\iXi Tools\Driver Updater Pro\DriverUpdaterPro.exe
HKLM-Run-IS CfgWiz - c:\program files\Common Files\Symantec Shared\cfgwiz.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-06-06 00:20
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(472)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll

- - - - - - - > 'explorer.exe'(2748)
c:\windows\system32\WININET.dll
c:\docume~1\HP_OWN~1.RAC\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\AVG\AVG9\avgchsvx.exe
c:\program files\AVG\AVG9\avgrsx.exe
c:\program files\Tall Emu\Online Armor\OAcat.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\windows\AGRSMMSG.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\windows\system32\dlbtcoms.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
c:\program files\AVG\AVG9\avgam.exe
c:\program files\AVG\AVG9\avgnsx.exe
c:\program files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
c:\program files\AVG\AVG9\avgcsrvx.exe
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2010-06-06 00:32:06 - machine was rebooted
ComboFix-quarantined-files.txt 2010-06-06 07:31

Pre-Run: 103,217,016,832 bytes free
Post-Run: 103,561,994,240 bytes free

- - End Of File - - 36B2B1C882C60CCE211754A93108191D
I'd like us to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)

  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt

Here are the ESET scan results



C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\file\omfgn.class-234f3403-1f6066ff.classprobably a variant of Java/TrojanDownloader.OpenStream trojancleaned by deleting - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\cnte-dhncgts.jar-746825f5-16fe8516.zipmultiple threatsdeleted - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\crtdcghcn.jar-516dc14a-5e884b29.zipprobably a variant of Win32/Agent trojandeleted - quarantined
C:\Documents and Settings\HP_Owner\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\loaderadv645.jar-750ad2c1-6189b599.zipmultiple threatsdeleted - quarantined
C:\Documents and Settings\HP_Owner\Local Settings\Temporary Internet Files\Content.IE5\R77SF69V\scn3[1].jsJS/TrojanDownloader.FakeAlert.NAB trojancleaned by deleting - quarantined
It looks like your computer is clean. If there's nothing else, let's do some clean-up

* Click START then RUN - Vista users press the Windows Key and the R keys for the Run box.
* Now type Combofix /uninstall in the runbox
* Make sure there's a space between Combofix and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.

===============================

Download OTC by OldTimer and save it to your desktop.

1. Double-click OTC to run it.
2. Click the CleanUp! button.
3. Select Yes when the "Begin cleanup Process?" prompt appears.
4. If you are prompted to Reboot during the cleanup, select Yes
5. OTC should delete itself once it finishes, if not delete it yourself.

===============================

Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.

================================

Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!


Discussion

No Comment Found