Sorry this took so long but this whole process took awhile.
Logfile of HijackThis v1.99.1
Scan saved at 11:37:58 PM, on 5/10/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Dell Photo AIO Printer 922\dlbtbmon.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Dell Support\DSAgnt.exe
C:\Program Files\MSN Messenger\MsnMsgr.Exe
C:\Program Files\iolo\System Mechanic\Scheduled_Maintenance.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\iTunes\iTunes.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Family\Desktop\HijackThis.exe
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares Lite Edition\Ares.exe" -h
O4 - HKCU\..\Run: [Scheduled Maintenance] C:\Program Files\iolo\System Mechanic\Scheduled_Maintenance.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmat...enWebRadio.html (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.micros...b?1134617272718O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) -
http://messenger.msn...pDownloader.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{DA5F4ACF-FFAE-4622-B755-67632FFF2D39}: NameServer = 205.171.3.65 205.171.2.65
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - C:\Program Files\Kerio\Personal Firewall\persfw.exe
Incident Status Location
Adware:adware/searchtheweb Not disinfected c:\windows\system32\cache\mswinstall.exe
Spyware:spyware/marketscore Not disinfected c:\windows\system32\osmim.dll
Adware:adware/beginto Not disinfected c:\windows\system32\rtneg.dll
Adware:adware/mirar Not disinfected c:\windows\system32\WinNB57.dll
Adware:adware/portalscan Not disinfected c:\windows\system32\winupdt.008
Adware:adware/transponder Not disinfected c:\windows\inf\Pynix.inf
Adware:adware/bookedspace Not disinfected c:\windows\cfgmgr52.ini
Adware:adware/ipinsight Not disinfected c:\windows\farmmext.ini
Adware:adware/enhancemsearch Not disinfected c:\windows\Helper101.dll
Spyware:application/bestoffer Not disinfected c:\windows\smdat32m.sys
Adware:adware/ezula Not disinfected c:\windows\woinstall.exe
Adware:adware/whenusearch Not disinfected c:\program files\common files\WhenU
Adware:adware/wupd Not disinfected c:\program files\Media Pass
Spyware:spyware/search3 Not disinfected c:\program files\SEARCH3 TOOLBAR
Adware:adware/elitebar Not disinfected c:\documents and settings\family\favorites\Casino & Carrers
Adware:adware/ieplugin Not disinfected Windows Registry
Adware:adware/savenow Not disinfected Windows Registry
Potentially unwanted tool:application/altnet Not disinfected hkey_local_machine\software\classes\appid\Altnet Signing Module.EXE
Spyware:Spyware/UrlSpy Not disinfected C:\!KillBox\ADSLDPC9.exe
Adware:Adware/eZula Not disinfected C:\!KillBox\Advtg.exe
Adware:Adware/PurityScan Not disinfected C:\Documents and Settings\Family\Application Data\eoew.exe
Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.doubleclick.net/]
Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.atdmt.com/]
Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.tribalfusion.com/]
Spyware:Cookie/myaffiliateprogram Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.www.myaffiliateprogram.com/]
Spyware:Cookie/Mediaplex Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.mediaplex.com/]
Spyware:Cookie/QkSrv Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.qksrv.net/]
Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.apmebf.com/]
Spyware:Cookie/Casalemedia Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.casalemedia.com/]
Spyware:Cookie/SexList Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.sexlist.com/]
Spyware:Cookie/cs.sexcounter Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.cs.sexcounter.com/]
Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.advertising.com/]
Spyware:Cookie/Traffic Marketplace Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.trafficmp.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/PointRoll Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.ads.pointroll.com/]
Spyware:Cookie/QuestionMarket Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.questionmarket.com/]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[ad.yieldmanager.com/]
Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.fastclick.net/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/Linksynergy Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.linksynergy.com/]
Spyware:Cookie/Bluestreak Not disinfected C:\Documents and Settings\Family\Application Data\Mozilla\Firefox\Profiles\hl4b5ca6.default\cookies.txt[.bluestreak.com/]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e6c188d-13fed43e.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e6c188d-13fed43e.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e6c188d-13fed43e.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-1e6c188d-13fed43e.zip[Beyond.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5c5c4cd1-53a67792.zip[BlackBox.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5c5c4cd1-53a67792.zip[VerifierBug.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5c5c4cd1-53a67792.zip[Dummy.class]
Virus:Exploit/ByteVerify Disinfected C:\Documents and Settings\Family\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\count.jar-5c5c4cd1-53a67792.zip[Beyond.class]
Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Family\Cookies\
[email protected][1].txt
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Family\Cookies\family@adultfriendfinder[2].txt
Spyware:Cookie/Reliablestats Not disinfected C:\Documents and Settings\Family\Cookies\
[email protected][2].txt
Adware:Adware/BookedSpace Not disinfected C:\Documents and Settings\Family\Desktop\backups\backup-20060510-213959-231.dll
Adware:Adware/BookedSpace Not disinfected C:\Documents and Settings\Family\Desktop\backups\backup-20060510-213959-585.dll
Adware:Adware/SAHAgent Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\1.exe[BundleLite_westfrontier1001.exe]
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\1.exe[thin-94-1-x-x.exe]
Adware:Adware/EliteBar Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\1133875.dll
Potentially unwanted tool:Application/Altnet Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\asmfiles.cab
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\p2psetup.exe
Spyware:Spyware/BetterInet Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\rndrcus.exe
Spyware:Spyware/UrlSpy Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\setup1015.exe
Adware:Adware/EliteBar Not disinfected C:\Documents and Settings\Family\Local Settings\Temp\uninstall.exe
Adware:Adware/EliteBar Not disinfected C:\EliteToolBar version 60.dll
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\angelex.exe
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\exclean.exe
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\exdl.exe
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\exdl0.exe
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\exdl1.exe
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\exul.exe
Hacktool:HackTool/SRunner.B Not disinfected C:\I386\instsrv.exe
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\javexulm.vxd
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\mac80ex.idf[C:/WINDOWS/system32/msbe.dll]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\mac80ex.idf[C:/Program Files/BullsEye Network/bin/bargains.exe]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\mac80ex.idf[C:/Program Files/BullsEye Network/bin/adv.exe]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\mac80ex.idf[C:/Program Files/BullsEye Network/bin/adx.exe]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\mqexdlm.srg
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\msbe.dll
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\msexreg.exe
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/exdl.exe]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/mqexdlm.srg]
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/exul.exe]
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/javexulm.vxd]
Adware:Adware/Exact.BargainBuddy Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/msexreg.exe]
Hacktool:HackTool/SRunner.B Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/instsrv.exe]
Adware:Adware/Exact.SearchBar Not disinfected C:\I386\netut80ex.vxd[C:/WINDOWS/system32/exclean.exe]
Spyware:Spyware/MarketScore Not disinfected C:\I386\rk.exe
Spyware:Spyware/ClearSearch Not disinfected C:\Program Files\3jnnkvww\3jnnkvww.dll
Adware:Adware Program Not disinfected C:\Program Files\3jnnkvww\63562640.exe
Spyware:Spyware/ClearSearch Not disinfected C:\Program Files\3jnnkvww\9r2n84tt.DLL
Spyware:Spyware/ClearSearch Not disinfected C:\Program Files\3jnnkvww\kglhegxw.DLL
Spyware:Spyware/ClearSearch Not disinfected C:\Program Files\3jnnkvww\td4bwxie.DLL
Adware:Adware/WhenUSearch Not disinfected C:\Program Files\Common Files\WhenU\EmbedSE.dll
Adware:Adware/Mirar Not disinfected C:\WINDOWS\876056.exe
Adware:Adware/StartPage.AHW Not disinfected C:\WINDOWS\bs7beta.exe
Adware:Adware/StartPage.AHW Not disinfected C:\WINDOWS\dhyjwgme.dll
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll
Adware:Adware/StartPage.AHW Not disinfected C:\WINDOWS\eyahavbg.dll
Adware:Adware/StartPage.AHW Not disinfected C:\WINDOWS\hopamjkt.dll
Adware:Adware/BookedSpace Not disinfected C:\WINDOWS\nvlbdjuq.exe
Adware:Adware/Transponder Not disinfected C:\WINDOWS\Pynix.dll
Adware:Adware/StartPage.AHW Not disinfected C:\WINDOWS\qemnuhfx.dll
Spyware:Spyware/UrlSpy Not disinfected C:\WINDOWS\SYSTEM32\ACLUI376.exe
Adware:Adware/WinTools Not disinfected C:\WINDOWS\SYSTEM32\Cache\adl_ibis_AS2.exe
Potentially unwanted tool:Application/MyWay Not disinfected C:\WINDOWS\SYSTEM32\Cache\bs51-egihsg51-va.exe[²ÇÇ]
Spyware:Spyware/ShhhToolbar Not disinfected C:\WINDOWS\SYSTEM32\Cache\runsearch.exe
Spyware:Spyware/UrlSpy Not disinfected C:\WINDOWS\SYSTEM32\Cache\setup1015.exe
Spyware:Spyware/BetterInet Not disinfected C:\WINDOWS\SYSTEM32\Cache\thin-8-3-x-x.exe
Adware:Adware/Beginto Not disinfected C:\WINDOWS\SYSTEM32\Cache\tool5-fran-one.exe
Adware:Adware/ILookup Not disinfected C:\WINDOWS\SYSTEM32\Cache\trafficgen-fran.exe
Adware:Adware/Ucmore Not disinfected C:\WINDOWS\SYSTEM32\Cache\ucmoreiex.exe
Adware:Adware/TopRebates Not disinfected C:\WINDOWS\SYSTEM32\Cache\WebRebates_Auto_InstallSilent.exe
Adware:Adware/VirtualBouncer Not disinfected C:\WINDOWS\SYSTEM32\Cache\wrapperouter.exe
Spyware:Spyware/UrlSpy Not disinfected C:\WINDOWS\SYSTEM32\CLBCATQ3.exe
Adware:Adware/PurityScan Not disinfected C:\WINDOWS\SYSTEM32\m?dtc.exe
Potentially unwanted tool:Application/P2PNetworking Not disinfected C:\WINDOWS\SYSTEM32\P2P Networking v126.cpl
Spyware:Spyware/MarketScore Not disinfected C:\WINDOWS\SYSTEM32\rk.bin
Spyware:Spyware/MarketScore Not disinfected C:\WINDOWS\SYSTEM32\rk.exe
Adware:Adware/BookedSpace Not disinfected C:\WINDOWS\vznmlwap.dll