1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

ULWindowSeek / ULWindowURL Popups

Discussion in 'Windows - Virus and spyware problems' started by BC425, Jun 19, 2006.

  1. BC425

    BC425 Member

    Joined:
    Jun 19, 2006
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Hi, ive been getting these two popups quite often every day. My AdAware does not get rid of them, nor does the program I used to remove atmclk.exe. What is the quickest easiest way for me to get rid of these? Im not that great with the technical workings of computers so please explain to me very detailed what I need to do. Thank You!!!

    Brian C.
     
  2. Xeres

    Xeres Member

    Joined:
    Apr 27, 2003
    Messages:
    85
    Likes Received:
    0
    Trophy Points:
    16
  3. BC425

    BC425 Member

    Joined:
    Jun 19, 2006
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Heres the Log I got when I ran HijackThis



    Logfile of HijackThis v1.99.1
    Scan saved at 4:04:17 AM, on 6/22/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\f771094d.exe
    C:\WINDOWS\system32\fa0f298b.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\WINDOWS\system32\wscntfy.exe
    C:\Program Files\Trillian\trillian.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Brian\Desktop\HijackThis_v1.99.1.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    O2 - BHO: (no name) - {0649ECAD-A7F5-4C85-A4FC-69DC373D201A} - C:\WINDOWS\system32\pmkhg.dll
    O4 - HKLM\..\Run: [f771094d.exe] C:\WINDOWS\system32\f771094d.exe
    O4 - HKLM\..\Run: [fa0f298b.exe] C:\WINDOWS\system32\fa0f298b.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [f771094d.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\f771094d.exe
    O4 - HKCU\..\Run: [fa0f298b.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\fa0f298b.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150307133999
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150310164389
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
    O20 - AppInit_DLLs: C:\WINDOWS\System32\mshta.dll
    O20 - Winlogon Notify: pmkhg - C:\WINDOWS\system32\pmkhg.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wintjv32 - C:\WINDOWS\SYSTEM32\wintjv32.dll
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

     
  4. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi BC425

    Xeres is forgot you :) Fine I'll help you.

    Please download here -> http://www.atribune.org/ccount/click.php?id=4 VundoFix.exe to your desktop.

    * Double-click VundoFix.exe to run it.
    * Put a check next to Run VundoFix as a task.
    * You will receive a message saying vundofix will close and re-open in a minute or less. Click OK
    * When VundoFix re-opens, click the Scan for Vundo button.
    * Once it's done scanning, click the Remove Vundo button.
    * You will receive a prompt asking if you want to remove the files, click YES
    * Once you click yes, your desktop will go blank as it starts removing Vundo.
    * When completed, it will prompt that it will shutdown your computer, click OK.
    * Turn your computer back on and post a fresh HjT-log along with
    contents of C:\vundofix.txt
     
  5. Xeres

    Xeres Member

    Joined:
    Apr 27, 2003
    Messages:
    85
    Likes Received:
    0
    Trophy Points:
    16
    Tapiiri;
    Nopr didn't forget, a small Item got in my way ..A Job..hehe.

    BC425 your're in good hands, if Tapiiri can't fix it, than you really are broke!

    Xeres

     
  6. BC425

    BC425 Member

    Joined:
    Jun 19, 2006
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Here is the new HjT log. and then under it will be the Vundo file.


    Logfile of HijackThis v1.99.1
    Scan saved at 12:09:55 PM, on 6/23/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\f771094d.exe
    C:\WINDOWS\system32\fa0f298b.exe
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\WINDOWS\system32\a1670d.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\Trillian\trillian.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\system32\wscntfy.exe
    C:\Documents and Settings\Brian\Desktop\HijackThis_v1.99.1.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    O2 - BHO: (no name) - {062492AF-392E-479D-BF52-A7A4BCA00307} - C:\WINDOWS\compstuic.dll
    O2 - BHO: (no name) - {E35ABB1D-65BB-48AD-B4B0-16783A4EACA8} - C:\WINDOWS\system32\pmkhg.dll (file missing)
    O4 - HKLM\..\Run: [f771094d.exe] C:\WINDOWS\system32\f771094d.exe
    O4 - HKLM\..\Run: [fa0f298b.exe] C:\WINDOWS\system32\fa0f298b.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [a1670d.exe] C:\WINDOWS\system32\a1670d.exe
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [f771094d.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\f771094d.exe
    O4 - HKCU\..\Run: [fa0f298b.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\fa0f298b.exe
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [a1670d.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\a1670d.exe
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150307133999
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150310164389
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
    O20 - AppInit_DLLs: C:\WINDOWS\System32\mshta.dll
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g2795234.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O20 - Winlogon Notify: wintjv32 - C:\WINDOWS\SYSTEM32\wintjv32.dll
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe




    Vundo



    VundoFix V4.2.84

    Running as SYSTEM
    from c:\windows\system32\VundoFix.exe

    Checking Java version...

    Sun Java not detected
    Scan started at 12:08:03 PM 6/23/2006

    Listing files found while scanning....


    C:\WINDOWS\system32\ghkmp.bak1
    C:\WINDOWS\system32\ghkmp.bak2
    C:\WINDOWS\system32\ghkmp.ini
    C:\WINDOWS\system32\pmkhg.dll
    Attempting to delete C:\WINDOWS\system32\ghkmp.bak1
    C:\WINDOWS\system32\ghkmp.bak1 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ghkmp.bak2
    C:\WINDOWS\system32\ghkmp.bak2 Has been deleted!

    Attempting to delete C:\WINDOWS\system32\ghkmp.ini
    C:\WINDOWS\system32\ghkmp.ini Has been deleted!

    Attempting to delete C:\WINDOWS\system32\pmkhg.dll
    C:\WINDOWS\system32\pmkhg.dll Has been deleted!

    Performing Repairs to the registry.
    Done!
     
  7. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi BC425

    Please download ewido anti malware it is a free version of the program -> http://www.ewido.net/en/download/

    1. Install ewido security suite
    2. When installing, under "Additional Options" uncheck..
    * Install background guard
    * Install scan via context menu
    3. Launch ewido, there should be an icon on your desktop, double-click it.
    4. The program will now open to the main screen.
    5. When you run ewido for the first time, you may get a warning "Database could not be found!". Click OK. We will fix this in a moment.
    6. You will need to update ewido to the latest definition files.
    * On the left hand side of the main screen click update.
    * Then click on Start Update.
    7. The update will start and a progress bar will show the updates being installed.
    (the status bar at the bottom will display ("Update successful")

    If you are having problems with the updater, you can use this link to manually update ewido.
    ewido manual updates -> http://www.ewido.net/en/download/updates/

    Once the updates are installed do the following:


    Download Killbox to your desktop -> http://www.downloads.subratam.org/KillBox.zip
    Unzip it to your desktop.

    Run Killbox.exe
    -> Choose Delete on Reboot
    -> Click All Files option.

    Copy the following lines to your clipboard (choose text with your mouse, press CTRL+C or copy)

    C:\WINDOWS\compstuic.dll
    C:\WINDOWS\system32\f771094d.exe
    C:\WINDOWS\system32\fa0f298b.exe
    C:\WINDOWS\system32\a1670d.exe
    C:\Documents and Settings\Brian\Local Settings\Application Data\f771094d.exe
    C:\Documents and Settings\Brian\Local Settings\Application Data\fa0f298b.exe
    C:\Documents and Settings\Brian\Local Settings\Application Data\a1670d.exe
    C:\WINDOWS\g2795234.dll
    C:\WINDOWS\SYSTEM32\wintjv32.dll

    Then go back to Killbox
    -> go to File
    -> choose Paste from Clipboard
    -> Click the red-white Delete File option.
    -> Click Yes to Delete on Reboot question
    -> Click OK to any PendingFileRenameOperations requests (and tell me if you get any of these!)
    -> Restart your computer if Killbox won't do it.

    (If you get this error when running Killbox: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid.", download Missingfilessetup.exe form here to your desktop and run the file, then try running killbox -> http://www.eudaemonia.me.uk/downloads/Files/missingfilesetup.exe)


    When comp is running after removin, Scan hijack this and check

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
    O2 - BHO: (no name) - {062492AF-392E-479D-BF52-A7A4BCA00307} - C:\WINDOWS\compstuic.dll
    O2 - BHO: (no name) - {E35ABB1D-65BB-48AD-B4B0-16783A4EACA8} - C:\WINDOWS\system32\pmkhg.dll (file missing)
    O4 - HKLM\..\Run: [f771094d.exe] C:\WINDOWS\system32\f771094d.exe
    O4 - HKLM\..\Run: [fa0f298b.exe] C:\WINDOWS\system32\fa0f298b.exe
    O4 - HKLM\..\Run: [a1670d.exe] C:\WINDOWS\system32\a1670d.exe
    O4 - HKCU\..\Run: [f771094d.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\f771094d.exe
    O4 - HKCU\..\Run: [fa0f298b.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\fa0f298b.exe
    O4 - HKCU\..\Run: [a1670d.exe] C:\Documents and Settings\Brian\Local Settings\Application Data\a1670d.exe
    O20 - Winlogon Notify: cfgmngr32 - C:\WINDOWS\g2795234.dll
    O20 - Winlogon Notify: wintjv32 - C:\WINDOWS\SYSTEM32\wintjv32.dll
    Reboot your computer in SafeMode by doing the following:

    1. Restart your computer
    2. After hearing your computer beep once during startup, but before the Windows icon appears, press F8.
    3. Instead of Windows loading as normal, a menu should appear
    4. Select the first option, to run Windows in Safe Mode.

    Launch ewido:

    * Click on scanner
    * Click on Complete System Scan and the scan will begin.
    * You will be prompted to clean the first infection.
    * Select "Perform action on all infections", then proceed.
    * Once the scan has completed, there will be a button located on the bottom of the screen named Save report
    * Click Save report.
    * Save the report .txt file to your desktop or a location where you can find it easily.

    Close ewido security suite.

    Reboot back to normal mode

    Send a fresh HjT log and ewido report
     
  8. BC425

    BC425 Member

    Joined:
    Jun 19, 2006
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    Been busy but here is the 2 files after I run all things you told me to.


    ---------------------------------------------------------
    ewido anti-spyware - Scan Report
    ---------------------------------------------------------

    + Created at: 6:59:42 AM 6/30/2006

    + Scan result:



    C:\Program Files\Cowabanga\Cowabanga.exe -> Adware.MediaTicket : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\khfgebc.dll -> Adware.Virtumonde : Cleaned with backup (quarantined).
    C:\!KillBox\compstuic.dll -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
    C:\!KillBox\compstuic.dll( 12) -> Downloader.Delf.aeo : Cleaned with backup (quarantined).
    C:\!KillBox\g2795234.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\!KillBox\g2795234.dll( 5) -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g10481750.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g1230968.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g1473468.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g150765.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g1600765.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g5196343.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\WINDOWS\g9279859.dll -> Downloader.Delf.amb : Cleaned with backup (quarantined).
    C:\!KillBox\f771094d.exe -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\!KillBox\f771094d.exe( 11) -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\!KillBox\f771094d.exe( 3) -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\!KillBox\f771094d.exe( 8) -> Downloader.Obfuscated.a : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\OA.exe -> Downloader.PurityScan.cq : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win99D.tmp.exe -> Downloader.Small.cvw : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\regperf.exe -> Downloader.Zlob.sz : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\oins.exe -> Dropper.Small : Cleaned with backup (quarantined).
    :mozilla.187:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.188:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.189:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.196:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@microsofteup.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@microsoftwga.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
    :mozilla.39:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Addynamix : Cleaned.
    :mozilla.48:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.49:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.50:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.51:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.52:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned.
    :mozilla.32:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.33:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.34:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.35:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Advertising : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
    :mozilla.26:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
    :mozilla.156:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Bluestreak : Cleaned.
    :mozilla.65:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
    :mozilla.66:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
    :mozilla.67:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Bridgetrack : Cleaned.
    :mozilla.218:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned.
    :mozilla.215:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.216:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Burstnet : Cleaned.
    :mozilla.113:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.114:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.115:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.116:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.117:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned.
    :mozilla.222:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@com[2].txt -> TrackingCookie.Com : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned.
    :mozilla.121:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned.
    :mozilla.31:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
    :mozilla.41:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.42:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.43:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.44:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned.
    :mozilla.225:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Googleadservices : Cleaned.
    :mozilla.147:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.148:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.149:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.150:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.151:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.152:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Hitbox : Cleaned.
    :mozilla.124:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Mediaplex : Cleaned.
    :mozilla.59:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.61:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.62:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.63:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Pointroll : Cleaned.
    :mozilla.45:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.46:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.47:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Questionmarket : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
    :mozilla.172:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.175:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.176:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.177:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.178:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@stats1.reliablestats[2].txt -> TrackingCookie.Reliablestats : Cleaned.
    :mozilla.37:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Revenue : Cleaned.
    :mozilla.219:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.220:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.221:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned.
    :mozilla.94:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.95:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.96:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.97:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned.
    :mozilla.212:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.213:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.214:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Smartadserver : Cleaned.
    :mozilla.194:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned.
    :mozilla.168:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.169:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.170:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
    :mozilla.86:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.87:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.88:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.89:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.90:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.91:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.92:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.93:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned.
    :mozilla.109:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.110:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.111:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.112:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned.
    :mozilla.28:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned.
    :mozilla.80:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.81:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned.
    C:\Documents and Settings\Brian\Cookies\brian@ad.yieldmanager[1].txt -> TrackingCookie.Yieldmanager : Cleaned.
    :mozilla.38:C:\Documents and Settings\Brian\Application Data\Mozilla\Firefox\Profiles\qv4z0sfd.default\cookies.txt -> TrackingCookie.Zedo : Cleaned.
    C:\!KillBox\wintjv32.dll -> Trojan.Agent.vg : Cleaned with backup (quarantined).
    C:\!KillBox\wintjv32.dll( 4) -> Trojan.Agent.vg : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win11.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win14.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win7.tmp -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win7.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\winB.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\winB83.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\winE.tmp.exe -> Trojan.Dialer.oy : Cleaned with backup (quarantined).
    C:\Documents and Settings\Brian\Local Settings\Temporary Internet Files\Content.IE5\KHQZWTUZ\bgates[1].exe -> Trojan.Dialer.pz : Cleaned with backup (quarantined).
    C:\WINDOWS\Temp\win102A.tmp -> Trojan.Dialer.pz : Cleaned with backup (quarantined).
    C:\WINDOWS\system32\1024 -> Trojan.Small : Cleaned with backup (quarantined).


    ::Report end



    HjT Logfile:
    Logfile of HijackThis v1.99.1
    Scan saved at 7:04:27 AM, on 6/30/2006
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\QuickTime\qttask.exe
    C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    C:\Program Files\McAfee.com\VSO\oasclnt.exe
    C:\PROGRA~1\mcafee.com\agent\mcagent.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    C:\Program Files\ewido anti-spyware 4.0\ewido.exe
    C:\Program Files\Messenger\msmsgs.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\Program Files\WinZip\WZQKPICK.EXE
    C:\Program Files\ewido anti-spyware 4.0\guard.exe
    c:\program files\mcafee.com\agent\mcdetect.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
    C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    C:\WINDOWS\System32\nvsvc32.exe
    c:\progra~1\mcafee.com\vso\mcvsftsn.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\Documents and Settings\Brian\Desktop\Spyware Removal\HijackThis_v1.99.1.exe

    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe
    O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
    O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
    O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
    O4 - HKLM\..\Run: [!ewido] "C:\Program Files\ewido anti-spyware 4.0\ewido.exe" /minimized
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
    O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150307133999
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1150310164389
    O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1162
    O20 - AppInit_DLLs: C:\WINDOWS\System32\mshta.dll
    O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
    O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
    O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe
    O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe
    O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
    O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe

     
  9. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    Hi BC425

    Looks good now.

    Is there problem anymore ?
     
  10. BC425

    BC425 Member

    Joined:
    Jun 19, 2006
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    11
    not that i can see. thank you very much for all the help. i had a slight problem with opening programs just before i did those last few steps. it was giving me errors and i couldnt load adaware or world of warcraft. but after those last steps with the killbox and ewido, everything is working fine and no more popups.

    Thanks so much again.

    Brian Corpus
     
  11. tapiiri

    tapiiri Regular member

    Joined:
    Jun 11, 2005
    Messages:
    1,142
    Likes Received:
    0
    Trophy Points:
    46
    You're welcome.
     

Share This Page