flavallee & CyberTech,
Here is the Mawarebytes & SuperAntiSpyware logs. will be posting the HijackThis momentarily!!
Thanks again for your help!!
Malwarebytes' Anti-Malware 1.41
Database version: 3112
Windows 5.1.2600 Service Pack 3
11/6/2009 6:54:02 PM
mbam-log-2009-11-06 (18-54-02).txt
Scan type: Quick Scan
Objects scanned: 118130
Time elapsed: 17 minute(s), 36 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 19
Registry Values Infected: 5
Registry Data Items Infected: 2
Folders Infected: 5
Files Infected: 16
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\Interface\{10125c2d-6821-4070-b24e-2e992501ad55} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{10125c2f-6821-4070-b24e-2e992501ad55} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{277e1fe0-cf65-11d3-b377-0800460222f0} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{6d54a7c0-c379-11d3-b377-0800460222f0} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{d714a94f-123a-45cc-8f03-040bcaf82ad6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{78429873-f771-11d3-ae1d-0050dac24e8f} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ed4 03e8-470a-4a8a-85a4-d7688cfe39a3} (Adware.Gamevance) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{4e7b d74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{d714 a94f-123a-45cc-8f03-040bcaf82ad6} (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c298 fb42-e3e2-11d3-adcd-0050dac24e8f} (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\AvScan (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.TryMedia) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Weat her Services (Adware.Hotbar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{ca0b9b71-c2af-11d3-b376-0800460222f0} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{4e7bd74f-2b8d-469e-86bd-fd60bb9aae3a} (Adware.OneToolBar) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{ca0b9b71-c2af-11d3-b376-0800460222f0} (Adware.iWon) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\System tool (Rogue.SysGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Fold ers\c:\program files\registrysmart\(default) (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\scrfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: ("%1" /S) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: (NOTEPAD.EXE %1) Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Folders Infected:
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\RegistrySmart (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates (Adware.SelectRebates) -> Quarantined and deleted successfully.
Files Infected:
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Log\2008 Apr 09 - 07_12_01 PM_078.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Log\2008 Apr 09 - 07_12_18 PM_109.log (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-08_10-55-21.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-09_10-01-29.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-10_10-46-27.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-12_10-35-07.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-13_11-41-29.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-02-19_12-07-43.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-03-01_12-24-05.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-03-15_10-51-51.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-03-21_08-59-52.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-03-30_11-45-28.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Documents and Settings\Donna Murphy\Application Data\RegistrySmart\Registry Backups\2008-04-06_18-23-47.reg (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\RegistrySmart\TCL.dll.vzr (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
C:\Program Files\SelectRebates\SelectRebatesDownload.exe (Adware.SelectRebates) -> Quarantined and deleted successfully.
C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job (Rogue.RegistrySmart) -> Quarantined and deleted successfully.
SUPERANTISPYWARE
SUPERAntiSpyware Scan Log
http://www.superantispyware.com
Generated 11/06/2009 at 06:45 PM
Application Version : 4.29.1004
Core Rules Database Version : 4239
Trace Rules Database Version: 2135
Scan type : Quick Scan
Total Scan Time : 01:15:49
Memory items scanned : 563
Memory threats detected : 0
Registry items scanned : 772
Registry threats detected : 62
File items scanned : 15587
File threats detected : 57
Adware.Gamevance
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0ED403E8-470A-4A8A-85A4-D7688CFE39A3}
Adware.SideStep Toolbar
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{D714A94F-123A-45CC-8F03-040BCAF82AD6}
HKCR\CLSID\{D714A94F-123A-45CC-8F03-040BCAF82AD6}
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\Implemented Categories
HKCR\CLSID\{83B28A74-640D-48F4-9F51-E80EED7CC7E0}\Implemented Categories\{00021493-0000-0000-C000-000000000046}
Adware.Tracking Cookie
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@richmedia.yahoo[4].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@ad.yieldmanager[4].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@realmedia[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@mediaplex[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@azjmp[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@content.yieldmanager[6].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@casalemedia[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@cdn4.specificclick[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@fastclick[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@doubleclick[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@admarketplace[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@247realmedia[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@ecomtracker[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@media.expedia[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@specificmedia[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@www.linktrack66[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@zedo[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@publishers.clickbooth[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@ads.slingo[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@pro-market[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@www.incentaclick[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@login.tracking101[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@interclick[4].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@ads.nascar[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@revsci[4].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@www.socialtrack[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@incentaclick[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@www.rmllctrack[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@invitemedia[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@roiservice[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@collective-media[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@toseeka[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@media6degrees[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@burstnet[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@eleadztracks[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@trafficregenerator[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@tracking.vampmarketing[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@trafficmp[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@enhance[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@bridge2.admarketplace[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@tribalfusion[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@questionmarket[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@www.tracklead[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@advertising[3].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@specificclick[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@apmebf[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@atdmt[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@adbrite[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@popcapgames.122.2o7[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@lynxtrack[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@ads.financialcontent[2].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@adv.dmv[1].txt
C:\Documents and Settings\Donna Murphy\Cookies\donna_murphy@telefloracom.112.2o7[1].txt
Registry Cleaner Trial
HKCR\Install.Install
HKCR\Install.Install\CLSID
HKCR\Install.Install\CurVer
HKCR\Install.Install.1
HKCR\Install.Install.1\CLSID
Adware.MyWebSearch/FunWebProducts
HKLM\SOFTWARE\FunWebProducts
HKLM\SOFTWARE\FunWebProducts\Installer
HKLM\SOFTWARE\FunWebProducts\Installer#CurInstall
HKLM\SOFTWARE\FunWebProducts\Installer#sr
HKLM\SOFTWARE\FunWebProducts\Installer#pl
HKLM\SOFTWARE\FunWebProducts\Installer#CheckForConnection
HKLM\SOFTWARE\FunWebProducts\Installer\downloaded
HKLM\SOFTWARE\FunWebProducts\PopSwatter
HKLM\SOFTWARE\FunWebProducts\PopSwatter#backedUp
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}
HKCR\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239}\TreatAs
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}
HKCR\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3}\TreatAs
Adware.SysGuard/FakeAlert
HKLM\Software\Microsoft\Windows\CurrentVersion\Run#system tool [ C:\Program Files\jvcpdk\xbimsysguard.exe ]
Rogue.Agent/Gen
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#aazalirt
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#skaaanret
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#jungertab
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#zibaglertz
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#iddqdops
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#ronitfst
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#tobmygers
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#jikglond
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#tobykke
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#klopnidret
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#jiklagka
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#salrtybek
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#seeukluba
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#jrjakdsd
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#krkdkdkee
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#dkewiizkjdks
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#dkekkrkska
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#rkaskssd
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#kuruhccdsdd
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#krujmmwlrra
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#kkwknrbsggeg
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#ktknamwerr
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#iqmcnoeqz
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#ienotas
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#krkmahejdk
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#otpeppggq
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#krtawefg
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#oranerkka
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#kitiiwhaas
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#otowjdseww
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#otnnbektre
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#oropbbsee
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#irprokwks
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#ooorjaas
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#id
HKU\S-1-5-21-1010553979-3580224116-4264976939-1006\SOFTWARE\AVSCAN#ready
Adware.SelectRebates
C:\Program Files\SELECTREBATES\SelectRebatesDownload.exe
C:\Program Files\SELECTREBATES
Trojan.Dropper/Gen
C:\DOCUMENTS AND SETTINGS\DONNA MURPHY\LOCAL SETTINGS\APPLICATION DATA\YAHOO\WIDGET ENGINE\UNZIPPED\TIVONAVIGATOR.WIDGET\TIVONAVIGATOR.WIDGET\CONTENTS\RESOURCE S\WGET.EXE
Adware.CouponBar
C:\WINDOWS\SYSTEM32\CPNPRT2.CID