Hello Sam...
I did everything exactly as you said. I just want to let you know that when I was finishing with AVG it asked: "The file C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe can not be quarantined because it is embedded in the archive C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe Do you want to quarantine the whole archive?
I clicked
YESIt also asked the same question regarding:
E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe can not be quarantined because it is embedded in the archive E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe
AND
C:\WINNT\ucmoreiex.exe/IUCMORE.DLL can not be quarantined because it is embedded in the archive C:\WINNT\ucmoreiex.exe/IUCMORE.DLL
I click YES to both of those as well.
When I finished and resarted my computer in normal mode my Anti-Virus program came up with these messages:
File name: C:\Documents and Settings\Amanda\Local Settings\Temporary internet Files\Content.IE5\SBIJDXYB\lo1[1]
infection: "Vundo!generic" Deleted
Filename: C\WINNT\System32\nnlii.dll infection: "Vundo!generic" Deleted
Filename: C\WINNT\System32\nnlii.dll infection: "Vundo!generic" Infected
Here are my log reports:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:10:12 PM 5/1/2007
+ Scan result:
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
E:\AWS\WeatherBug\MiniBugTransporter.dll -> Adware.Aws : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq89.tmp -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINNT\system32\BO2802040113.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
C:\WINNT\system32\KVIF_11.dll -> Adware.BargainBuddy : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppq89.tmp -> Adware.BargainBuddy : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute -> Adware.CashBack : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute.1 -> Adware.CashBack : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CLSID -> Adware.CashBack : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Classes\WEBInstaller.CExecute\CurVer -> Adware.CashBack : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{c95fe080-8f5d-11d2-a20b-00aa003c157a} -> Adware.Generic : Cleaned with backup (quarantined).
C:\WINNT\system32\ffInst.exe -> Adware.Look2Me : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\NHUninstaller.exe -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\NHelper.dll -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHelper.dll -> Adware.NavExcel : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\NHUninstaller.exe -> Adware.NavExcel : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\NHelper.dll -> Adware.NavExcel : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHUninstaller.exe -> Adware.NavExcel : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppqE.tmp\NavHelper\v2.0.4c\v2.0.4c.cab/NHelper.dll -> Adware.NavExcel : Cleaned with backup (quarantined).
C:\WINNT\system32\smpi1\win.exe -> Adware.NewDotNet : Cleaned with backup (quarantined).
HKLM\SOFTWARE\Clickspring -> Adware.PurityScan : Cleaned with backup (quarantined).
C:\WINNT\b122.exe -> Adware.Softomate : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zzzu\zzzud\zzzuc.dll -> Adware.TargetServer : Cleaned with backup (quarantined).
C:\Downloads\BellesBeautyBoutiqueSetup-dm[1].exe -> Adware.Trymedia : Cleaned with backup (quarantined).
E:\Downloads\TheGameOfLifeSetup-dm.exe -> Adware.Trymedia : Cleaned with backup (quarantined).
C:\TTC.dll -> Adware.TTC : Cleaned with backup (quarantined).
C:\WINNT\ucmoreiex.exe/IUCMORE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\WINNT\ucmoreiex.exe/UCMTSAIE.DLL -> Adware.Ucmore : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7.tmp -> Adware.WinAD : Cleaned with backup (quarantined).
C:\WINNT\Downloaded Program Files\WINADX.0LL -> Adware.WinAD : Cleaned with backup (quarantined).
E:\Yahoo!\YPSR\Quarantine\ppq7.tmp -> Adware.WinAD : Cleaned with backup (quarantined).
C:\WINNT\system32\smpi1\win33.exe -> Adware.ZQuest : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\WINNT\updater.exe.vir -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\WINNT\retadpu2000219.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\WINNT\system32\smpi1\win11.exe -> Downloader.Agent.bls : Cleaned with backup (quarantined).
C:\Program Files\Common Files\Yazzle1122OinAdmin.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\WINNT\b128.exe -> Downloader.PurityScan.eh : Cleaned with backup (quarantined).
C:\WINNT\Downloaded Program Files\ATPartners.inf -> Downloader.Rameh.c : Cleaned with backup (quarantined).
C:\WINNT\bl4ck.com -> Downloader.Small : Cleaned with backup (quarantined).
C:\WINNT\b104.exe -> Downloader.Small.buy : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zzzu\zzzup.exe -> Downloader.TSUpdate.f : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zzzu\zzzud\vocabulary -> Downloader.TSUpdate.j : Cleaned with backup (quarantined).
C:\Program Files\Common Files\zzzu\zzzua.exe -> Downloader.TSUpdate.l : Cleaned with backup (quarantined).
C:\WINNT\b103.exe -> Downloader.TSUpdate.o : Cleaned with backup (quarantined).
C:\tskmgr.exe -> Dropper.VB.nn : Cleaned with backup (quarantined).
C:\Program Files\WindowsUpdate\lacu.dll -> Hijacker.StartPage : Cleaned with backup (quarantined).
C:\WINNT\Downloaded Program Files\CONFLICT.1\popcaploader.dll -> Not-A-Virus.Downloader.Win32.PopCap.a : Cleaned with backup (quarantined).
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq21.tmp -> TrackingCookie.247realmedia : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq21.tmp -> TrackingCookie.247realmedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq11.tmp -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq23.tmp -> TrackingCookie.2o7 : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq11.tmp -> TrackingCookie.2o7 : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq23.tmp -> TrackingCookie.2o7 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq69.tmp -> TrackingCookie.Adserver : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq69.tmp -> TrackingCookie.Adserver : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq98.tmp -> TrackingCookie.Adtech : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq15.tmp -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq30.tmp -> TrackingCookie.Advertising : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq15.tmp -> TrackingCookie.Advertising : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq30.tmp -> TrackingCookie.Advertising : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq32.tmp -> TrackingCookie.Atdmt : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq32.tmp -> TrackingCookie.Atdmt : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq17.tmp -> TrackingCookie.Bfast : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq17.tmp -> TrackingCookie.Bfast : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq34.tmp -> TrackingCookie.Bluestreak : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq34.tmp -> TrackingCookie.Bluestreak : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3A.tmp -> TrackingCookie.Bridgetrack : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq3A.tmp -> TrackingCookie.Bridgetrack : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq37.tmp -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6D.tmp -> TrackingCookie.Burstnet : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq37.tmp -> TrackingCookie.Burstnet : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq6D.tmp -> TrackingCookie.Burstnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq38.tmp -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6E.tmp -> TrackingCookie.Casalemedia : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq38.tmp -> TrackingCookie.Casalemedia : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq6E.tmp -> TrackingCookie.Casalemedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq39.tmp -> TrackingCookie.Centrport : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6F.tmp -> TrackingCookie.Centrport : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq39.tmp -> TrackingCookie.Centrport : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq6F.tmp -> TrackingCookie.Centrport : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3B.tmp -> TrackingCookie.Clickbank : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq3B.tmp -> TrackingCookie.Clickbank : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3C.tmp -> TrackingCookie.Com : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9A.tmp -> TrackingCookie.Com : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq3C.tmp -> TrackingCookie.Com : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq72.tmp -> TrackingCookie.Commission-junction : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq72.tmp -> TrackingCookie.Commission-junction : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq74.tmp -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8D.tmp -> TrackingCookie.Coremetrics : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq74.tmp -> TrackingCookie.Coremetrics : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq83.tmp -> TrackingCookie.Dealtime : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq84.tmp -> TrackingCookie.Dealtime : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9C.tmp -> TrackingCookie.Dealtime : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq83.tmp -> TrackingCookie.Dealtime : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq84.tmp -> TrackingCookie.Dealtime : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3F.tmp -> TrackingCookie.Doubleclick : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq3F.tmp -> TrackingCookie.Doubleclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq31.tmp -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq45.tmp -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9F.tmp -> TrackingCookie.Falkag : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq31.tmp -> TrackingCookie.Falkag : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq45.tmp -> TrackingCookie.Falkag : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq46.tmp -> TrackingCookie.Fastclick : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq46.tmp -> TrackingCookie.Fastclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA0.tmp -> TrackingCookie.Findwhat : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA1.tmp -> TrackingCookie.Fortunecity : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA2.tmp -> TrackingCookie.Goclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq48.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq79.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8E.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9D.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9E.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA3.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA4.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA5.tmp -> TrackingCookie.Hitbox : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq48.tmp -> TrackingCookie.Hitbox : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq79.tmp -> TrackingCookie.Hitbox : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA6.tmp -> TrackingCookie.Hitslink : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA7.tmp -> TrackingCookie.Hitslink : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7A.tmp -> TrackingCookie.Linksynergy : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqA8.tmp -> TrackingCookie.Linksynergy : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq7A.tmp -> TrackingCookie.Linksynergy : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4C.tmp -> TrackingCookie.Mediaplex : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq4C.tmp -> TrackingCookie.Mediaplex : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5F.tmp -> TrackingCookie.Onestat : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAE.tmp -> TrackingCookie.Onestat : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5F.tmp -> TrackingCookie.Onestat : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq4E.tmp -> TrackingCookie.Paycounter : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq4E.tmp -> TrackingCookie.Paycounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAC.tmp -> TrackingCookie.Popuptraffic : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq3E.tmp -> TrackingCookie.Pro-market : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq9B.tmp -> TrackingCookie.Pro-market : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq3E.tmp -> TrackingCookie.Pro-market : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq50.tmp -> TrackingCookie.Qksrv : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq50.tmp -> TrackingCookie.Qksrv : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq51.tmp -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7C.tmp -> TrackingCookie.Questionmarket : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq51.tmp -> TrackingCookie.Questionmarket : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq7C.tmp -> TrackingCookie.Questionmarket : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq52.tmp -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7D.tmp -> TrackingCookie.Realmedia : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq52.tmp -> TrackingCookie.Realmedia : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq7D.tmp -> TrackingCookie.Realmedia : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq53.tmp -> TrackingCookie.Realtracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAD.tmp -> TrackingCookie.Realtracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq53.tmp -> TrackingCookie.Realtracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq54.tmp -> TrackingCookie.Revenue : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq54.tmp -> TrackingCookie.Revenue : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq41.tmp -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq75.tmp -> TrackingCookie.Ru4 : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq41.tmp -> TrackingCookie.Ru4 : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq75.tmp -> TrackingCookie.Ru4 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq36.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq55.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq8B.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq91.tmp -> TrackingCookie.Serving-sys : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq36.tmp -> TrackingCookie.Serving-sys : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq55.tmp -> TrackingCookie.Serving-sys : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq56.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq57.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq58.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq59.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5A.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5B.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5C.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5D.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5E.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq56.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq57.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq58.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq59.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5A.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5B.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5C.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5D.tmp -> TrackingCookie.Sextracker : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq5E.tmp -> TrackingCookie.Sextracker : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7E.tmp -> TrackingCookie.Spylog : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq7E.tmp -> TrackingCookie.Spylog : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq60.tmp -> TrackingCookie.Statcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq92.tmp -> TrackingCookie.Statcounter : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq60.tmp -> TrackingCookie.Statcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq93.tmp -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqAF.tmp -> TrackingCookie.Tacoda : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB0.tmp -> TrackingCookie.Targetnet : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq61.tmp -> TrackingCookie.Tradedoubler : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB2.tmp -> TrackingCookie.Tradedoubler : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq61.tmp -> TrackingCookie.Tradedoubler : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq62.tmp -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq7F.tmp -> TrackingCookie.Trafficmp : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq62.tmp -> TrackingCookie.Trafficmp : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq7F.tmp -> TrackingCookie.Trafficmp : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq63.tmp -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq81.tmp -> TrackingCookie.Tribalfusion : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq63.tmp -> TrackingCookie.Tribalfusion : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq81.tmp -> TrackingCookie.Tribalfusion : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq65.tmp -> TrackingCookie.Valueclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq82.tmp -> TrackingCookie.Valueclick : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq65.tmp -> TrackingCookie.Valueclick : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq82.tmp -> TrackingCookie.Valueclick : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq66.tmp -> TrackingCookie.Webtrendslive : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq95.tmp -> TrackingCookie.Webtrendslive : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq66.tmp -> TrackingCookie.Webtrendslive : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppqB3.tmp -> TrackingCookie.X10 : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq67.tmp -> TrackingCookie.Xxxcounter : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq67.tmp -> TrackingCookie.Xxxcounter : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq5.tmp -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq96.tmp -> TrackingCookie.Yieldmanager : Cleaned.
C:\Program Files\Yahoo!\YPSR\Quarantine\ppq6B.tmp -> TrackingCookie.Zedo : Cleaned.
E:\Yahoo!\YPSR\Quarantine\ppq6B.tmp -> TrackingCookie.Zedo : Cleaned.
C:\temp\ja.exe -> Trojan.Agent : Cleaned with backup (quarantined).
C:\QooBox\Quarantine\C\Program Files\Ipwindows\UnInstall.exe.vir -> Trojan.Rond : Cleaned with backup (quarantined).
::Report end
and my new HiJackThis report:
Logfile of HijackThis v1.99.1
Scan saved at 10:48:49 PM, on 5/1/2007
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP1 (5.00.2920.0000)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\LEXBCES.EXE
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\LEXPPS.EXE
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Program Files\Yahoo!\Antivirus\ISafe.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe
C:\WINNT\system32\carpserv.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Yahoo!\Antivirus\CAVTray.exe
C:\Program Files\Yahoo!\Antivirus\CAVRID.exe
C:\PROGRA~1\Yahoo!\YOP\yop.exe
C:\Program Files\Common Files\AOL\1150423870\ee\AOLSoftware.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\PROGRA~1\Yahoo!\browser\ycommon.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
E:\QUICKENW\QWDLLS.EXE
E:\Internet Explorer\IEXPLORE.EXE
C:\WINNT\explorer.exe
C:\Documents and Settings\Amanda\Desktop\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6711
F1 - win.ini: load=c:\01comm32\bin\01comm32.exe
F2 - REG:system.ini: Shell=
F3 - REG:win.ini: load=c:\01comm32\bin\01comm32.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\programs\ActiveX\AcroIEHelper.dll
O2 - BHO: 0 - {0FBA1A47-CA02-4EEF-4A86-E82B295083BF} - C:\Program Files\WindowsUpdate\lacu.dll (file missing)
O2 - BHO: (no name) - {2FA13BAB-7DEF-4A26-8B26-67AA4ADA29C6} - \
O2 - BHO: (no name) - {35ABA5C8-9807-46A8-AD57-0F66ECAF4455} - \
O2 - BHO: PeoplePC FixedBandBHO - {3DE88907-3E38-11D4-BEB2-CBE76C0598DD} - C:\Program Files\ISP40\bin\BandObject.dll (file missing)
O2 - BHO: (no name) - {46A9A505-DE6F-4C11-98CB-F9CD294C8F8F} - \
O2 - BHO: (no name) - {618AB4EC-F7AC-4459-A1EA-108039F75B59} - \
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {8E01C5C0-B2AB-443A-8FC0-23F1BFFC5968} - \
O2 - BHO: (no name) - {C9475987-7FA0-4FDE-9115-8E754199206F} - \
O2 - BHO: (no name) - {CA2CFBDE-0F94-491B-9286-00C60C553954} - C:\WINNT\system32\iifcdec.dll
O2 - BHO: (no name) - {D0DBD288-F7A9-47AB-BA48-B9AFC77F5FF5} - \
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [PrinTray] C:\WINNT\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [LVCOMS] C:\Program Files\Common Files\Logitech\QCDriver2\LVCOMS.EXE
O4 - HKLM\..\Run: [AOL Spyware Protection] "C:\PROGRA~1\COMMON~1\AOL\AOLSPY~1\AOLSP Scheduler.exe"
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [BJCFD] C:\Program Files\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\Yahoo!\Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\Yahoo!\Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [YOP] C:\PROGRA~1\Yahoo!\YOP\yop.exe /autostart
O4 - HKLM\..\Run: [HostManager] C:\Program Files\Common Files\AOL\1150423870\ee\AOLSoftware.exe
O4 - HKLM\..\Run: [AOLDialer] C:\Program Files\Common Files\AOL\ACS\AOLDial.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [IPHSend] C:\Program Files\Common Files\AOL\IPHSend\IPHSend.exe
O4 - HKLM\..\Run: [Bart Station] C:\Program Files\ISP40\hta\station.sbrt
O4 - HKLM\..\Run: [3P6WAHF5SNWXZ2] C:\WINNT\system32\JwqVfC.exe
O4 - HKLM\..\Run: [ParentalFilter] C:\Program Files\Parental Filter\ParentalFilter.exe
O4 - HKLM\..\Run: [Adobe Photo Downloader] "E:\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [MalwareBot] C:\Program Files\MalwareBot\MalwareBot.exe -boot
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [MBstRWJ6Q] caponf.exe
O4 - HKCU\..\Run: [updateMgr] "E:\programs\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [zzzu] C:\Program Files\Common Files\zzzu\zzzum.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\programs\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = E:\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O4 - Global Startup: Quicken Startup.lnk = E:\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - E:\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O16 - DPF: RaptisoftGameLoader -
http://www.miniclip....tgameloader.cabO16 - DPF: {0E0D50BC-E086-4E3A-B07D-C5C5869C0FFF} (Abx Control) -
http://real.gamehous...ureball/abx.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\common\yinsthelper.dll
O16 - DPF: {3DA5D23B-EFE1-4181-ADB7-7D457567AACA} (TGOnlineCtrl Class) -
http://zone.msn.com/...pandaonline.cabO16 - DPF: {4E7BD74F-2B8D-469E-DEFA-EB76B1D5FA7D} -
http://eztracks.aava...olbar/eztdl.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.av.a...83/mcinsctl.cabO16 - DPF: {4F5E4276-C120-11D6-A1FD-00508B9D48EA} (dldisplay Class) -
http://www.gamehouse.com/ghdlctl.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) -
http://www.slide.com...ageUploader.cabO16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} (CPlayFirstDinerDash2Control Object) -
http://real.gamehous.../DinerDash2.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.micros...b?1149634915184O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www3.ca.com/s...nfo/webscan.cabO16 - DPF: {7D731A83-6C80-4EA4-9646-5E06A0513274} (Sandlot Loader Control) -
http://www.shockwave...gwebinstall.cabO16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) -
http://aolsvc.aol.co...mesLauncher.cabO16 - DPF: {A0EAC162-A012-4AD8-B2E1-D5A0BBBCDA51} (PopupSh Control) -
http://209.190.5.106...lay/PopupSh.ocxO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://zone.msn.com/...ro.cab34246.cabO16 - DPF: {BAE1D8DF-0B35-47E3-A1E7-EEB3FF2ECD19} (CPlayFirstddfotgControl Object) -
http://aolsvc.aol.co...tg.1.0.0.33.cabO16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} -
http://download.av.a...,20/mcgdmgr.cabO16 - DPF: {BE319D04-18BD-4B34-AECC-EE7CB610FCA9} (BewitchedGameClass Control) -
http://aolsvc.aol.co...itched/main.cabO16 - DPF: {BF985246-09BF-11D2-BE62-006097DF57F6} (SimCityX Control) -
http://simcity.ea.co...ic/SimCityX.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://aolsvc.aol.co...zylomplayer.cabO16 - DPF: {D54160C3-DB7B-4534-9B65-190EE4A9C7F7} (SproutLauncherCtrl Class) -
http://zone.msn.com/...outLauncher.cabO16 - DPF: {D77EF652-9A6B-40C8-A4B9-1C0697C6CF41} (TikGames Online Control) -
http://zone.msn.com/...pandaonline.cabO16 - DPF: {DC75FEF6-165D-4D25-A518-C8C4BDA7BAA6} (CPlayFirstDinerDashControl Object) -
http://www.playfirst...h/dinerdash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://real.gamehous...opcaploader.cabO16 - DPF: {E36C5562-C4E0-4220-BCB2-1C671E3A5916} (Seagate SeaTools English Online) -
http://www.seagate.c.../npseatools.cabO16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
http://pdl.stream.ao.../ampx_en_dl.cabO16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} -
http://www.trueswitc...eInstallSBC.exeO20 - Winlogon Notify: iifcdec - C:\WINNT\SYSTEM32\iifcdec.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\ISafe.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\Yahoo!\Antivirus\VetMsg.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
Again, thanks for your help!