Re: Malware - file tmp[x].tmp.exe keeps getting created and antispyware can't solve i
Hi again,
Sorry for the delay in my response - I was on holiday and not near a computer for awhile. Here is the AVG Scan log:
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 11:22:10 AM 7/3/2007
+ Scan result:
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004064.exe -> Dropper.Mudrop.du : Cleaned.
C:\Documents and Settings\flanders\My Documents\Downloads\evid4226patch223d-en\EvID4226Patch.exe -> Not-A-Virus.Hacktool.EvID : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@2o7[2].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@educationmanagementllc.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@livenation.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@msnportal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@pch.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@upi.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@arn.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@getmusicfree.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@pan.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@www.abcsearch[1].txt -> TrackingCookie.Abcsearch : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@3.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ads.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ads.addynamix[2].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@bluestreak[2].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ads.cnn[1].txt -> TrackingCookie.Cnn : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@enhance[2].txt -> TrackingCookie.Enhance : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@fastclick[1].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ehg-netquote.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ehg-playboy.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ssl-hints.netflame[1].txt -> TrackingCookie.Netflame : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@questionmarket[1].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@web4.realtracker[1].txt -> TrackingCookie.Realtracker : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@stats1.reliablestats[1].txt -> TrackingCookie.Reliablestats : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@bs.serving-sys[2].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@adopt.specificclick[1].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@specificclick[2].txt -> TrackingCookie.Specificclick : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@anad.tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@statse.webtrendslive[1].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\flanders\Cookies\flanders@zedo[2].txt -> TrackingCookie.Zedo : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp100.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp11.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21D2.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21E7.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp74.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp98.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmpD4.tmp.exe.vir -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004230.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004234.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004238.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004242.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004262.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0004649.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0005643.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007761.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007762.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007778.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007784.exe -> Trojan.Agent.anr : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007792.exe -> Trojan.Agent.anr : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp1.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21C1.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21C6.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21CA.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21D9.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21F4.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp223D.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2263.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp229C.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp22CD.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp22F2.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp230D.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2311.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp25.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp3D.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp6.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp6A.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp6D.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp8.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp9.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp95.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmpBA.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmpFD.tmp.exe.vir -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004049.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004120.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004142.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004144.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004145.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004223.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004225.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004228.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004232.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004236.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004240.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004260.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004264.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004289.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP93\A0004308.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004543.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004548.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004549.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004552.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0004650.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0005752.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0005754.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0006745.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007759.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007763.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007764.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007767.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007771.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007772.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007773.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007779.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007780.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007781.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007787.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007794.exe -> Trojan.Agent.aoy : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007880.exe -> Trojan.Agent.aoy : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21C3.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21C7.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21D1.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp21E6.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2224.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2249.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp2279.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp229E.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp22CE.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp22FD.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp230E.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp27.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmpB.tmp.exe.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp21C3.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp21C7.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp21D1.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp21E6.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp2224.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp2249.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp2279.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp229E.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp22CE.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp22FD.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp230E.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp2312.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp4.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmp72.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\WINDOWS\system32\tmpB.tmp.dll.vir -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP100\A0007992.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP100\A0007993.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP95\A0004384.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004544.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP96\A0004550.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0005642.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0006741.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP98\A0006751.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007766.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007786.exe -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007797.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007799.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007800.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007801.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007802.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007803.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007804.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007805.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007806.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007807.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007808.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007809.dll -> Trojan.BHO.bd : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007810.dll -> Trojan.BHO.bd : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp26.tmp.exe.vir -> Trojan.Pakes : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp7.tmp.exe.vir -> Trojan.Pakes : Cleaned.
C:\QooBox\Quarantine\C\DOCUME~1\flanders\APPLIC~1\tmp71.tmp.exe.vir -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0005641.exe -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP97\A0006740.exe -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007765.exe -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007774.exe -> Trojan.Pakes : Cleaned.
C:\System Volume Information\_restore{35FBD4A9-B0F5-4C5D-9DF8-B859D4321294}\RP99\A0007775.exe -> Trojan.Pakes : Cleaned.
::Report end
Here is the updated HJT log:
Logfile of HijackThis v1.99.1
Scan saved at 10:13:13 AM, on 7/9/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
c:\program files\ge security supra\syncservice.exe
C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\GE Security Supra\ProxyDaemon.exe
C:\SSL\stunnel-4.10.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\GE Security Supra\SyncInfoApp.exe
C:\WINDOWS\system32\dlbxcoms.exe
C:\Program Files\Citrix\ICA Client\pnagent.exe
C:\Program Files\ScanSoft\PDF Professional 4.0\PdfPro4Hook.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://news.google.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [dlbxmon.exe] "C:\Program Files\Dell Photo AIO Printer 962\dlbxmon.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PDF4 Registry Controller] "C:\Program Files\ScanSoft\PDF Professional 4.0\\RegistryController.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [DLBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBXtime.dll,_RunDLLEntry@16
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: DisplayKEY eSYNC Info.lnk = C:\Program Files\GE Security Supra\SyncInfoApp.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Open with ScanSoft PDF Converter 4.0 - res://C:\Program Files\ScanSoft\PDF Professional 4.0\cnvres_eng.dll /100
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky.com/kos/eng/par...an_unicode.cab
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) -
http://www.linkedin.com/cab/LinkedIn...derControl.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoftware.com/actives...ree/asinst.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: DkeySync - GE Security Supra - c:\program files\ge security supra\syncservice.exe
O23 - Service: dlbx_device - Dell - C:\WINDOWS\system32\dlbxcoms.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: spkrmon - Unknown owner - C:\Program Files\Analog Devices\SoundMAX\spkrmon.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
I think all of this has fixed it. I'm not getting any random pop-ups and it seems to be running the same as it was before I was infected. Thanks again for all your help!