Page 1 of 3 123 LastLast
Results 1 to 10 of 29
  1. #1
    Member
    Join Date
    Apr 2013
    Posts
    18
    Points
    0

    Default Finished the required scans, logs below

    Hi,
    First run on the scans got rid of a
    good number of viruses/malware. I do not get the "high CPU usage" error that I was getting. However, the sysuytem is still running very slow. I am unable to get rid of the unnamed toolbar on the "hijackThis" log even though I followed the instructions, twice. Here is some system information : Inter Pentium 4 CPU 2.80GHz, 2.81 GHz, 1.99 GB of RAM

    It is taking me forever to write this message because the computer is so slow and I can only type ahead so far.

    Thanks,
    Carol




    SUPERAntiSpyware Scan Log
    SUPERAntiSpyware | Remove Malware | Remove Spyware - AntiMalware, AntiSpyware, AntiAdware!

    Generated 05/01/2013 at 08:20 PM

    Application Version : 5.6.1014

    Core Rules Database Version : 10341
    Trace Rules Database Version: 8153

    Scan type : Complete Scan
    Total Scan Time : 01:56:25

    Operating System Information
    Windows XP Professional 32-bit, Service Pack 3 (Build 5.01.2600)
    Administrator

    Memory items scanned : 592
    Memory threats detected : 0
    Registry items scanned : 38050
    Registry threats detected : 0
    File items scanned : 41008
    File threats detected : 16

    Adware.Tracking Cookie
    C:\Documents and Settings\Carol\Cookies\47S35CI1.txt [ /atdmt.com ]
    C:\Documents and Settings\Carol\Cookies\EG0THPBT.txt [ /ad.yieldmanager.com ]
    C:\Documents and Settings\Carol\Cookies\G6VR9UE9.txt [ /advertising.com ]
    C:\Documents and Settings\Carol\Cookies\AEG8NRET.txt [ /imrworldwide.com ]
    C:\Documents and Settings\Carol\Cookies\V8NT4TAK.txt [ /ads.creative-serving.com ]
    C:\Documents and Settings\Carol\Cookies\53P0QN2J.txt [ /apmebf.com ]
    C:\Documents and Settings\Carol\Cookies\H5UM5SK9.txt [ /mediaplex.com ]
    C:\Documents and Settings\Carol\Cookies\L4F2XIX2.txt [ /amazon-adsystem.com ]
    C:\Documents and Settings\Carol\Cookies\H4S9XCVG.txt [ /adtechus.com ]
    C:\Documents and Settings\Carol\Cookies\E4U8R3PY.txt [ /ru4.com ]
    C:\Documents and Settings\Carol\Cookies\GTAA7CFA.txt [ /doubleclick.net ]
    C:\Documents and Settings\Carol\Cookies\HBFR1P20.txt [ /invitemedia.com ]
    C:\Documents and Settings\Carol\Cookies\DYQGN5EQ.txt [ /2o7.net ]
    C:\Documents and Settings\Carol\Cookies\PTC4QVDD.txt [ /ad.mlnadvertising.com ]
    C:\Documents and Settings\Carol\Cookies\PUJY3MDN.txt [ /c1.atdmt.com ]
    C:\Documents and Settings\Carol\Cookies\E4XEQUMM.txt [ /microsoftwindows.112.2o7.net ]


    Malwarebytes' Anti-Malware 1.50.1.1100
    Malwarebytes : Free anti-malware download

    Database version: 5591

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 8.0.6001.18702

    1/2/2003 2:25:55 AM
    mbam-log-2003-01-02 (02-25-55).txt

    Scan type: Full scan (C:\|)
    Objects scanned: 212106
    Time elapsed: 30 minute(s), 50 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 37
    Registry Values Infected: 6
    Registry Data Items Infected: 0
    Folders Infected: 20
    Files Infected: 250

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CLASSES_ROOT\AppID\{57ABA38E-6535-48F3-99FD-EFDC62137C78} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{25B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{25B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{25B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{35B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{35B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{35B8D58C-B0CB-46B0-BA64-05B3804E4E86} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\AppID\AIMActiveXDLL.DLL (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Outlook\Addins\OEActiveXDLL.DesktopOEAddin1 (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Internet Saving Optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\msupdate (Rootkit.Agent) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\podmena (Trojan.Downloader) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\podmenadrv (Trojan.Downloader) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{5617ECA9-488D-4BA2-8562-9710B9AB78D2} (Adware.DoubleD) -> Value: {5617ECA9-488D-4BA2-8562-9710B9AB78D2} -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Value: {2224E955-00E9-4613-A844-CE69FCCAAE91} -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\{2224E955-00E9-4613-A844-CE69FCCAAE91} (Adware.DoubleD) -> Value: {2224E955-00E9-4613-A844-CE69FCCAAE91} -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\podmena (Trojan.Agent) -> Value: podmena -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List\8085:TCP (Malware.Trace) -> Value: 8085:TCP -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    c:\documents and settings\all users\application data\36692430 (Rogue.Multiple) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920 (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\bin (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\internet saving optimizer (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\internet saving optimizer\3.4.0.4340 (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850 (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2} (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\TDF (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\TDF\Cache (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\TDF\Data (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\TDF\Icons (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\temporary internet files\{5617eca9-488d-4ba2-8562-9710b9ab78d2}\TDF\Skins (Adware.DoubleD) -> Quarantined and deleted successfully.

    Files Infected:
    c:\WINDOWS\9g2234wesdf3dfgjf23 (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\dk39fi4fe.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\f23567.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\f5087.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\msmark2.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\ro122715.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\ro122739.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\WINDOWS\ro122807.dat (Worm.KoobFace) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\248d6576afce4ee94af42d7350131106.gif (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\24a70fb875fab686b6b3c217612bc07c.gif (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\2afcf6f3f2e19cc42d7f72f3b18b26ef.gif (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\50bffa6936b3e661971a58e3c8bdf4cb.gif (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\default1.dat (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\loading.dat (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Cache\loading.gif (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_screensaver.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_cursor.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_dailyvideo.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_game.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_glitter.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_logo.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_option.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_recipe.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_ringtone.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_search.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_smiley.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_smiley_config.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_smiley_tellafriend.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_wallpaper.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_web.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_01.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_02.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_03.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_04.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_05.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_06.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\module_webdropdown_07.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\pixel.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\productinfo.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\profile.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\searchenginelist.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\tbcore.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\toolbarlayout.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\updatecentre.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\updatecentrebk.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\urldynamic.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Data\urlstatic.mx (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\About.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\component_combobox.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_cursor.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_cursor.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_dailyvideo.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_game.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_glitter.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_glitter.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_option.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_recipe.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_ringtone.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_screensaver.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_search.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_smiley.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_smiley.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_wallpaper.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_web.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_01.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_01.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_02.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_02.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_03.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_03.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtndisplay.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtndisplay18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtndisplay20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnglitters.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnglitters.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnglitters18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnglitters20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnoption.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnsmiley.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnsmiley.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnsmiley18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnsmiley20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtntellfd.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtntellfd.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtntellfd18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtntellfd20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnwink.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnwink.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnwink18.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtnwink20.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_04.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_05.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_05.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_06.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_06.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_07.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_07.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtndefault.png (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_logo.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\module_webdropdown_04.mg (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Icons\tbbtndisplay.bmp (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\myskin1.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\myskin2.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\myskin3.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\myskin4.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\tellafriendskin.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\tellafriendskin_s.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\DoubleD\gamingharbor toolbar\4.1.4.20920\Skins\toastskin.skf (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\internet saving optimizer\3.4.0.4340\config.md (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\internet saving optimizer\3.4.0.4340\np_20030108-050846.343.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\config.md (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-202152.660.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-202427.973.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-202543.254.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-120220.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-120643.671.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-154040.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-154136.531.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-154626.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-155103.390.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-155643.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-155703.921.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-181258.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-200052.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-202521.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-202608.437.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-202945.437.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-220502.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-220515.562.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-221517.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-231640.968.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-231828.718.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090812-202400.203.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090812-202737.296.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090812-211120.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090812-212737.859.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090816-204043.375.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-202009.176.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090811-200245.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090816-204210.750.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090819-204539.406.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090822-224711.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090824-222338.718.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090827-101716.125.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-222111.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090816-210853.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090816-211022.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090816-213715.656.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090817-184342.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090817-222702.828.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090817-223610.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090817-230321.468.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-095652.031.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-095700.921.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-100710.625.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-104558.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-104657.390.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090818-104702.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090819-204649.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090819-204722.421.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090819-204816.125.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090819-213435.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090820-091311.781.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090820-094736.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090820-220512.946.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090820-220655.716.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090820-222246.147.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090821-215604.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090821-215718.031.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090822-222900.640.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090822-223000.828.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090822-224817.406.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090822-224923.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-021823.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-021934.171.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-023848.171.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-213646.564.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-215045.376.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-221222.656.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-223036.566.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090823-235321.546.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090824-002138.468.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090824-003258.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090824-003547.671.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090824-225302.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090825-105733.778.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090825-112927.903.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090825-113700.340.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090825-114034.496.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090825-180159.156.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-223821.515.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-224014.125.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-224047.343.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-224123.000.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-225219.406.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090826-231452.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090827-101532.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090827-230409.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090827-230503.781.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090828-211259.234.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090828-215058.781.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090829-231143.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090829-233900.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-125542.625.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-125641.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-130508.359.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-210305.156.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-210442.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-220704.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-220715.953.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030101-230423.906.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030101-230653.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030101-230747.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030101-230802.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030102-000247.796.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030102-000402.765.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030102-001129.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-031527.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-031719.812.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-031848.031.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-031925.421.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-034601.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-035941.281.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-040946.984.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-043342.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-172036.718.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-172106.562.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-172249.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-172304.265.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030104-175204.593.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030105-033956.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030105-034145.687.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030105-034304.703.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030108-050321.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20030108-050845.937.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-201737.801.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090810-202009.160.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-224144.203.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-224228.093.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231222.921.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231356.109.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231356.140.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231427.312.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231456.390.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090830-231518.500.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090831-123810.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090831-230455.250.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090910-175921.609.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090910-175948.453.log (Adware.DoubleD) -> Quarantined and deleted successfully.
    c:\documents and settings\Carol\local settings\application data\media access startup\1.5.0.850\hjhp_20090910-180127.890.log (Adware.DoubleD) -> Quarantined and deleted successfully.




    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 7:03:38 AM, on 5/2/2013
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v8.00 (8.00.6001.18702)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Windows Defender\MsMpEng.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Java\jre7\bin\jqs.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Uniblue\SpeedUpMyPC\spmonitor.exe
    C:\Program Files\Uniblue\SpeedUpMyPC\sump.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe
    C:\Program Files\Microsoft IntelliPoint\ipoint.exe
    C:\Program Files\AVAST Software\Avast\avastUI.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
    C:\Program Files\Belkin\Router Setup and Monitor\BelkinSetup.exe
    C:\Program Files\FixCleaner\FixCleaner.exe
    C:\Program Files\DriverUpdate\DriverUpdate.exe
    C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    C:\Program Files\Citrix\ICA Client\redirector.exe
    C:\Program Files\Citrix\ICA Client\wfcrun32.exe
    C:\Program Files\Citrix\ICA Client\concentr.exe
    C:\Program Files\Citrix\Receiver\Receiver.exe
    C:\Program Files\Citrix\SelfServicePlugin\SelfServicePlugin.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Yahoo!
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = XFINITY by Comcast -- Official Customer Site | Email | Watch TV Online
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Bing
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Bing
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Yahoo!
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = Customize Your Settings
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
    O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
    O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
    O4 - HKLM\..\Run: [InstaLAN] "C:\Program Files\Belkin\Router Setup and Monitor\BelkinRouterMonitor.exe" startup
    O4 - HKLM\..\Run: [Conime] %windir%\system32\conime.exe
    O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
    O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
    O4 - HKLM\..\Run: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [FixCleaner] C:\Program Files\FixCleaner\FixCleaner.exe -boot
    O4 - HKCU\..\Run: [DriverUpdate] "C:\Program Files\DriverUpdate\DriverUpdate.exe" -boot
    O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
    O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
    O4 - HKUS\S-1-5-18\..\RunOnce: [KodakHomeCenter] "C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [KodakHomeCenter] "C:\Program Files\Kodak\AiO\Center\AiOHomeCenter.exe" (User 'Default user')
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: c:\program files\speedbit video accelerator\sblsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\speedbit video accelerator\sblsp.dll
    O10 - Unknown file in Winsock LSP: c:\program files\speedbit video accelerator\sblsp.dll
    O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} - http://www.superadblocker.com/activex/sabspx.cab
    O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
    O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files\Citrix\ICA Client\IcaMimeFilter.dll
    O20 - AppInit_DLLs: C:\PROGRA~1\Citrix\ICACLI~1\RSHook.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
    O23 - Service: SAS Core Service (!SASCORE) - SUPERAntiSpyware.com - C:\Program Files\SUPERAntiSpyware\SASCORE.EXE
    O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
    O23 - Service: AffinegyService - Affinegy, Inc. - C:\Program Files\Belkin\Router Setup and Monitor\BelkinService.exe
    O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
    O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: getPlus(R) Helper - GEAR Software Inc. - (no file)
    O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Program Files\Java\jre7\bin\jqs.exe

    --
    End of file - 9698 bytes

    Please review the recommendations below. Only you are responsible for your computer - use these guidelines at your own risk.




    Malicious

    These entries have been positively identified as malicious programs.
    Reboot your computer into safe mode. (instructions)
    Run HijackThis again, and place a check mark next to the following entries.

    O3 - Toolbar: (no name) - !{2318C2B1-4965-11d4-9B18-009027A5CD4F} - (no file)
    (Description: A blank toolbar entry. Possibly an adware toolbar that was removed by an anti-virus or anti-spyware program.)






    Suspicious

    Suspicious entries have been found in your log. They might be spyware/malware. We advise that you follow all of the directions on this page, and then re-run HijackThis. If you are still seeing this "Suspicious" section, you should go to the Spyware Help section of our site and post your log in a new topic so that our experts can analyze it personally.








    1) Press the "Fix checked" button. Then close HijackThis.


    2) Empty your recycle bin.

    3) Run Windows Update and install all critical updates.

    4) Make sure your anti-virus program is up to date with the latest patches. If you do not have an anti-virus program, download and install Avast Antivirus, which is free.

    5)

    6) Some suspicious entries have been found in your log. The next step is to run the suggested scans in this tutorial and then post the logs in the Spyware Help Forum along with a note that the Detective prompted you to do so. One of our experts will analyze your logs and post a response if there is anything else you need to fix.


    How to Help
    Help2Go is a free public service, without any advertising or pop-ups. We depend on donations to keep the site running. If the Help2Go Detective service has been helpful to you, please consider donating a few dollars to the cause. Thanks!

  2. #2
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello cjrancourt,

    Please run the following scans and post their logs.

    1.
    Download AdwCleaner
    • Double click on AdwCleaner.exe to run the tool.
      ***Note: Windows Vista and Windows 7 users:
      Right click in the adwCleaner.exe and select
    • Click the Delete button.
    • A logfile will automatically open after the scan has finished.
    • Please post the content of that logfile in your next reply.
    • Or you can find the logfile at C:\AdwCleaner[R1].txt.


    2.
    • Download RogueKiller on the desktop
    • Close all the running processes
    • Under Vista/Seven, right click -> Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • When prompted, Click Scan
    • A report should open, give its content to your helper. (RKreport could also be found next to the executable)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename in winlogon.exe (or winlogon.com) and try again
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  3. #3
    Member
    Join Date
    Apr 2013
    Posts
    18
    Points
    0

    Default

    Here is the AswCleaner log:

    # AdwCleaner v2.300 - Logfile created 05/03/2013 at 18:35:14
    # Updated 28/04/2013 by Xplode
    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
    # User : Carol - FAMILY
    # Boot Mode : Normal
    # Running from : C:\Program Files\Adware Cleaner\adwcleaner.exe
    # Option [Search]


    ***** [Services] *****


    ***** [Files / Folders] *****

    Folder Found : C:\Documents and Settings\All Users\Application Data\APN
    Folder Found : C:\Documents and Settings\All Users\Application Data\Speedbit
    Folder Found : C:\Documents and Settings\Carol\Application Data\facemoods.com
    Folder Found : C:\Documents and Settings\Carol\Application Data\iWin
    Folder Found : C:\Documents and Settings\Carol\Application Data\searchquband
    Folder Found : C:\Documents and Settings\Carol\Local Settings\Application Data\Ilivid Player
    Folder Found : C:\Program Files\Celebrity Toolbar

    ***** [Registry] *****

    Key Found : HKCU\Software\DataMngr
    Key Found : HKCU\Software\IGearSettings
    Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98279C38-DE4B-4BCF-93C9-8EC26069D6F4}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98279C38-DE4B-4BCF-93C9-8EC26069D6F4}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
    Key Found : HKCU\Software\SpeedBit
    Key Found : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
    Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{6160F76A-1992-4B17-A32D-0C706D159105}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
    Key Found : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
    Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
    Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
    Key Found : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
    Key Found : HKLM\Software\SpeedBit
    Key Found : HKU\S-1-5-21-789336058-963894560-725345543-1005\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
    Value Found : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registry is clean.

    *************************

    AdwCleaner[R1].txt - [162 octets] - [26/04/2013 21:25:36]
    AdwCleaner[R2].txt - [6523 octets] - [26/04/2013 21:32:57]
    AdwCleaner[R3].txt - [6733 octets] - [03/05/2013 18:35:14]

    ########## EOF - C:\AdwCleaner[R3].txt - [6793 octets] ##########


    and now the RogueKiller log:

    RogueKiller V8.5.4 [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : RogueKiller - Geeks to Go Forums
    Website : Download RogueKiller (Official website)
    Blog : tigzy-RK

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Carol [Admin rights]
    Mode : Scan -- Date : 05/03/2013 18:46:09
    | ARK || FAK || MBR |

    Bad processes : 0

    Registry Entries : 3
    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> FOUND
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> FOUND
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    Particular Files / Folders:

    Driver : [LOADED]
    IRP[IRP_MJ_CREATE_NAMED_PIPE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_READ] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_WRITE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_EA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_EA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_FLUSH_BUFFERS] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_VOLUME_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_VOLUME_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_DIRECTORY_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_FILE_SYSTEM_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SHUTDOWN] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_LOCK_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_CLEANUP] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_CREATE_MAILSLOT] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_SECURITY] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_SECURITY] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_DEVICE_CHANGE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_QUOTA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_QUOTA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)

    HOSTS File:
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost


    MBR Check:

    +++++ PhysicalDrive0: WDC WD5000AAKS-00UU3A0 +++++
    --- User ---
    [MBR] f51b352424f3aa68a32169394543892e
    [BSP] 5e582e24a6564e7b9724a14a02c17098 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[2]_S_05032013_02d1846.txt >>
    RKreport[1]_S_04262013_02d2127.txt ; RKreport[2]_S_05032013_02d1846.txt

  4. #4
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    1.
    • Close all open programs and internet browsers.
    • Double click on adwcleaner.exe to run the tool.
    • Click on Delete.
    • Confirm each time with Ok.
    • You will be prompted to restart your computer. A text file will open after the restart.
    • Please post the contents of that logfile with your next reply.
    • You can find the logfile at C:\AdwCleaner[S1].txt as well.


    2.
    • Re-Run RogueKiller
    • Close all the running processes
    • Under Vista/Seven, right click -> Run as Administrator
    • Otherwise just double-click on RogueKiller.exe
    • When prompted, Click Delete
    • A report should open, give its content to your helper. (RKreport could also be found next to the executable)
    • If RogueKiller has been blocked, do not hesitate to try a few times more. If really won't run, rename in winlogon.exe (or winlogon.com) and try again


    3.
    Download and run Junkware Removal Tool. ***Your Anti Virus may see this download as malicious, don't worry continue on.

    Please download Junkware Removal Tool to your desktop.

    • shut down your protection software now to avoid potential conflicts.
    • run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator"
      the tool will open and start scanning your system
    • please be patient as this can take a while to complete depending on your system's specifications
    • on completion, a log (JRT.txt) is saved to your desktop and will automatically open
    • post the contents of JRT.txt into your next Reply.



    Things to include in your next reply::
    AdwCleaner log
    Roguekiller log
    JRT.txt
    How is your machine running now?
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  5. #5
    Member
    Join Date
    Apr 2013
    Posts
    18
    Points
    0

    Default

    adwcleaner

    # AdwCleaner v2.300 - Logfile created 05/04/2013 at 08:28:45
    # Updated 28/04/2013 by Xplode
    # Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
    # User : Carol - FAMILY
    # Boot Mode : Normal
    # Running from : C:\Program Files\Adware Cleaner\adwcleaner.exe
    # Option [Delete]


    ***** [Services] *****


    ***** [Files / Folders] *****

    Folder Deleted : C:\Documents and Settings\All Users\Application Data\APN
    Folder Deleted : C:\Documents and Settings\All Users\Application Data\Speedbit
    Folder Deleted : C:\Documents and Settings\Carol\Application Data\facemoods.com
    Folder Deleted : C:\Documents and Settings\Carol\Application Data\iWin
    Folder Deleted : C:\Documents and Settings\Carol\Application Data\searchquband
    Folder Deleted : C:\Documents and Settings\Carol\Local Settings\Application Data\Ilivid Player
    Folder Deleted : C:\Program Files\Celebrity Toolbar

    ***** [Registry] *****

    Key Deleted : HKCU\Software\DataMngr
    Key Deleted : HKCU\Software\IGearSettings
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98279C38-DE4B-4BCF-93C9-8EC26069D6F4}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{E8DAAA30-6CAA-4B58-9603-8E54238219E2}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-6E41-4FD3-8538-502F5495E5FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1A93C934-025B-4C3A-B38E-9654A7003239}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6F282B65-56BF-4BD1-A8B2-A4449A05863D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98279C38-DE4B-4BCF-93C9-8EC26069D6F4}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{99079A25-328F-4BD4-BE04-00955ACAA0A7}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{9D717F81-9148-4F12-8568-69135F087DB0}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D4027C7F-154A-4066-A1AD-4243D8127440}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DB4E9724-F518-4DFD-9C7C-78B52103CAB9}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD2FD708-1F6F-4B68-B141-C5778F0C19BB}
    Key Deleted : HKCU\Software\SpeedBit
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0}
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{64182481-4F71-486B-A045-B233BD0DA8FC}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DDE2C74F-58CC-4D71-8CE1-09DEBB8CFB78}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2A42D13C-D427-4787-821B-CF6973855778}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3D8478AA-7B88-48A9-8BCB-B85D594411EC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6160F76A-1992-4B17-A32D-0C706D159105}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{877F3EAB-4462-44DF-8475-6064EAFD7FBF}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\063A857434EDED11A893800002C0A966
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0FF2AEFF45EEA0A48A4B33C1973B6094
    Key Deleted : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\305B09CE8C53A214DB58887F62F25536
    Key Deleted : HKLM\Software\SpeedBit
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{D4027C7F-154A-4066-A1AD-4243D8127440}]
    Value Deleted : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}]
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [10]

    ***** [Internet Browsers] *****

    -\\ Internet Explorer v8.0.6001.18702

    [OK] Registry is clean.

    *************************

    AdwCleaner[R1].txt - [162 octets] - [26/04/2013 21:25:36]
    AdwCleaner[R2].txt - [6523 octets] - [26/04/2013 21:32:57]
    AdwCleaner[R3].txt - [6862 octets] - [03/05/2013 18:35:14]
    AdwCleaner[R4].txt - [6922 octets] - [04/05/2013 08:25:37]
    AdwCleaner[R5].txt - [6982 octets] - [04/05/2013 08:27:42]
    AdwCleaner[S1].txt - [6887 octets] - [04/05/2013 08:28:45]

    ########## EOF - C:\AdwCleaner[S1].txt - [6947 octets] ##########



    Rogue Killer

    V8.5.4 [Mar 18 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : RogueKiller - Geeks to Go Forums
    Website : Download RogueKiller (Official website)
    Blog : tigzy-RK

    Operating System : Windows XP (5.1.2600 Service Pack 3) 32 bits version
    Started in : Normal mode
    User : Carol [Admin rights]
    Mode : Remove -- Date : 05/04/2013 09:12:14
    | ARK || FAK || MBR |

    Bad processes : 0

    Registry Entries : 3
    [HJPOL] HKCU\[...]\System : DisableTaskMgr (0) -> DELETED
    [HJPOL] HKCU\[...]\System : DisableRegistryTools (0) -> DELETED
    [HJ DESK] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

    Particular Files / Folders:

    Driver : [LOADED]
    IRP[IRP_MJ_CREATE_NAMED_PIPE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_READ] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_WRITE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_EA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_EA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_FLUSH_BUFFERS] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_VOLUME_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_VOLUME_INFORMATION] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_DIRECTORY_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_FILE_SYSTEM_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SHUTDOWN] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_LOCK_CONTROL] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_CLEANUP] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_CREATE_MAILSLOT] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_SECURITY] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_SECURITY] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_DEVICE_CHANGE] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_QUERY_QUOTA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)
    IRP[IRP_MJ_SET_QUOTA] : atapi.sys -> HOOKED ([MAJOR] \WINDOWS\system32\TUKERNEL.EXE @ 0x804F979C)

    HOSTS File:
    --> C:\WINDOWS\system32\drivers\etc\hosts

    127.0.0.1 localhost


    MBR Check:

    +++++ PhysicalDrive0: WDC WD5000AAKS-00UU3A0 +++++
    --- User ---
    [MBR] f51b352424f3aa68a32169394543892e
    [BSP] 5e582e24a6564e7b9724a14a02c17098 : Windows XP MBR Code
    Partition table:
    0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 476937 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[2]_D_05042013_02d0912.txt >>
    RKreport[1]_S_05042013_02d0904.txt ; RKreport[2]_D_05042013_02d0912.txt


    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Junkware Removal Tool (JRT) by Thisisu
    Version: 4.9.3 (04.29.2013:2)
    OS: Microsoft Windows XP x86
    Ran by Carol on Sat 05/04/2013 at 9:18:17.07
    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




    ~~~ Services



    ~~~ Registry Values

    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName
    Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL



    ~~~ Registry Keys

    Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\fixcleaner
    Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\fixcleaner



    ~~~ Files

    Successfully deleted: [File] C:\install.res.1028.dll
    Successfully deleted: [File] C:\install.res.1031.dll
    Successfully deleted: [File] C:\install.res.1033.dll
    Successfully deleted: [File] C:\install.res.1036.dll
    Successfully deleted: [File] C:\install.res.1040.dll
    Successfully deleted: [File] C:\install.res.1041.dll
    Successfully deleted: [File] C:\install.res.1042.dll
    Successfully deleted: [File] C:\install.res.2052.dll
    Successfully deleted: [File] C:\install.res.3082.dll



    ~~~ Folders

    Successfully deleted: [Folder] "C:\Documents and Settings\All Users\application data\big fish games"
    Successfully deleted: [Folder] "C:\Documents and Settings\Carol\Application Data\big fish games"
    Failed to delete: [Folder] "C:\Documents and Settings\Carol\Application Data\fixcleaner"
    Successfully deleted: [Folder] "C:\Documents and Settings\Carol\appdata\locallow\datamngr"
    Failed to delete: [Folder] "C:\Program Files\fixcleaner"
    Successfully deleted: [Folder] "C:\Program Files\minddabble_4p"





    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
    Scan was completed on Sat 05/04/2013 at 9:43:23.21
    End of JRT log

  6. #6
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    How is the machine running now?
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  7. #7
    Member
    Join Date
    Apr 2013
    Posts
    18
    Points
    0

    Default

    Pretty good, page transitions seem slow still, but the whole on line experience isn't nearly as frustrating as it was. I appreciate your assistance.

    Carol

  8. #8
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Lets run a few more tools and see if they find anything.

    1.
    Please download the latest version of TDSSKiller from here and save it to your Desktop.
    • Doubleclick on TDSSKiller.exe to run the application, then click on Change parameters.
    • Put a checkmark beside loaded modules.
    • A reboot will be needed to apply the changes. Do it.
    • TDSSKiller will launch automatically after the reboot. Also your computer may seem very slow and unusable. This is normal. Give it enough time to load your background programs.
    • Then click on Change parameters in TDSSKiller.
    • Check all boxes then click OK.
    • Click the Start Scan button.
    • The scan should take no longer than 2 minutes.
    • If a suspicious object is detected, the default action will be Skip, click on Continue.
    • If malicious objects are found, they will show in the Scan results - Select action for found objects and offer three options.
      Ensure Cure (default) is selected, then click Continue > Reboot now to finish the cleaning process.

      Note: If Cure is not available, please choose Skip instead, do not choose Delete unless instructed.
    • A report will be created in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


    2.
    Install Recovery Console and Run ComboFix

    This tool is not a toy. If used the wrong way you could trash your computer. Please use only under direction of a Helper. If you decide to do so anyway, please do not blame me or ComboFix.

    Download Combofix from any of the links below, and save it to your desktop.

    Link 1
    Link 2
    • Close/disable all anti-virus and anti-malware programs so they do not interfere with the running of ComboFix. Refer to this page if you are not sure how.
    • Close any open windows, including this one.
    • Double click on ComboFix.exe & follow the prompts.
    • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
    • If you did not have it installed, you will see the prompt below. Choose YES.
    • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

    Note:The Windows Recovery Console will allow you to boot up into a special recovery (repair) mode. This allows us to more easily help you
    should your computer have a problem after an attempted removal of malware. It is a simple procedure that will only take a few moments of your time.

    • Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    • Click on Yes, to continue scanning for malware.
    • When finished, it will produce a report for you. Please post the contents of the log (C:\ComboFix.txt).
    Leave your computer alone while ComboFix is running.
    ComboFix will restart your computer if malware is found; allow it to do so.


    Note: Please Do NOT mouseclick combofix's window while its running because it may cause it to stall.


    Things to include in your next reply::
    TdssKiller log
    Combofix.txt
    How is the machine running now?
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  9. #9
    Member Spyware Fighter
    Join Date
    Jun 2010
    Location
    Bement,Ill USA
    Posts
    1,340
    Points
    146

    Default

    Hello.

    Are you still there?

    If you are please follow the instructions in my previous post.

    If you still need help, follow the instructions I have given in my response. If you have since had your problem solved, we would appreciate you letting us know so we can close the topic.

    Please reply back telling us so. If you don't reply within 3-5 days the topic will need to be closed.

    Thanks for understanding

    With Regards,
    fireman4it
    " Extinguishing Malware from the world"

    The Spware Help forum is very busy. If I'm helping you and I've not posted back within 24 hrs., send a PM with your topic link. Thank you.
    HELP REQUESTS VIA THE PM SYSTEM WILL BE IGNORED. The Forums are there for a reason!
    Thanks-




  10. #10
    Member
    Join Date
    Apr 2013
    Posts
    18
    Points
    0

    Default

    Hi, I am still here. Having difficulty posting the TDSSKiller log, it is very large and the computer freezes when I try to paste it in the reply window. After 3 attempts, rebooted the computer, now will try to paste it in smaller chunks.

    Carol

Page 1 of 3 123 LastLast