My Reply inline:
nybarton said:
Daave.......
I found "view report" in Spybot and was able to copy and paste it. These
items were all in red. Here it is:
--- Report generated: 2007-07-10 02:08 ---
ISearchTech.PowerScan: Settings (Registry value, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\BandRest
Make sure the check box is selected for this item [ ]
AdwareAlert: Settings (Registry key, nothing done)
HKEY_USERS\S-1-5-21-335388756-1319870562-3049974079-1006\Software\AdwareAlert
Make sure the check box is selected for this item [ ]
AdwareAlert: Program directory (Directory, nothing done)
C:\Program Files\AdwareAlert\Log\
Make sure the check box is selected for this item [ ]
DyFuCA: Settings (Registry value, nothing done)
HKEY_USERS\S-1-5-21-335388756-1319870562-3049974079-1006\Software\Microsoft\Internet
Explorer\Main\BandRest
Make sure the check box is selected for this item [ ]
Rotue: Uninstall settings (Registry key, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Rotue
Microsoft.Windows.Security.InternetExplorer: Settings (Registry change,
nothing done)
Make sure the check box is selected for this item [ ]
HKEY_USERS\S-1-5-21-335388756-1319870562-3049974079-1006\Software\Microsoft\Internet
Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN\iexplore.exe!=W=1
Microsoft.WindowsSecurityCenter.AntiVirusDisableNotify: Settings (Registry
change, nothing done)
For now Make sure the check box is selected for this item [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusDisableNotify!=dword:0
Microsoft.WindowsSecurityCenter.FirewallDisableNotify: Settings (Registry
change, nothing done)
For Now Make sure the check box is selected for this item [ ]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallDisableNotify!=dword:0
Microsoft.Windows.IEFirewallBypass: Settings (Registry value, nothing done)
For now Make sure the check box is selected for this item [ ]
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List\C:\Program
Files\Internet Explorer\IEXPLORE.EXE
180Solutions.SearchAssistant: Data (File, nothing done)
Make sure the check box is selected for this item [ ]
C:\WINDOWS\saap.log
BlueStreak: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
FastClick: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
Statcounter: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
Clickbank: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
TagASaurus: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done
Make sure the check box is selected for this item [ ]
Advertising.com: Tracking cookie (Internet Explorer: Marilyn) (Cookie,
nothing done)
Make sure the check box is selected for this item [ ]
CoreMetrics: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
Zedo: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
FastClick: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
WebTrends live: Tracking cookie (Internet Explorer: Marilyn) (Cookie,
nothing done)
Make sure the check box is selected for this item [ ]
WebTrends live: Tracking cookie (Internet Explorer: Marilyn) (Cookie,
nothing done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
MediaPlex: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing
done)
Make sure the check box is selected for this item [ ]
HitBox: Tracking cookie (Internet Explorer: Marilyn) (Cookie, nothing done)
Make sure the check box is selected for this item [ ]
WebTrends live: Tracking cookie (Internet Explorer: Marilyn) (Cookie,
nothing done)
Make sure the check box is selected for this item [ ]
Win32.Small.ddx: Bookmark (Internet Explorer: Marilyn) (Bookmark, nothing
done)
Make sure the check box is selected for this item [ ]
Click Fix All Button and let Spybot fix then and pay attention to any
message will pop up and write down.
Run Lavasoft SE and a Virus Scan, any thing found?.
Then Run the HijackThis and select these items:
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://my.msn.com/?page=2&refresh=1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=566...p://www.msn.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft
Internet Explorer provided by Comcast High-Speed Internet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet
Settings,ProxyServer = :0
R3 - URLSearchHook: (no name) - _{DD1BCA06-F674-424D-A08E-42DA97C4D5DD} -
(no file)
O2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program
Files\Microsoft Money\System\mnyside.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O4 - HKLM\..\Run: [WrtMon.exe]
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} -
C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {9239E4EC-C9A6-11D2-A844-00C04F68D538} - (no
file)
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no
file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} -
%windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O16 - DPF: symsupportutil -
https://www-secure.symantec.com/techsupp/ac...supportutil.CAB
O16 - DPF: Yahoo! Finance MarketTracker -
http://finance.yahoo.com/jmt/mt.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) -
http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) -
http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {11260943-421B-11D0-8EAC-0000C07D88CF} (iPIX ActiveX Control) -
http://www.ipix.com/download/ipixx.cab
O16 - DPF: {11A02365-2859-4598-A9D5-4FDE99D67723} (PQIEBrowserConnector
Class) -
http://www.pqprintcenter.com/plugin/axvers...ntquick1622.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/200305...meInstaller.exe
O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj
Class) -
http://aolcc.aol.com/computercheckup/qdiagcc.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety
Center Base Module) -
http://cdn.scan.onecare.live.com/resource/...lscbase8300.cab
O16 - DPF: {6A344D34-5231-452A-8A57-D064AC9B7862} (Symantec Download
Manager) -
https://webdl.symantec.com/activex/symdlmgr.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1128537877381
O16 - DPF: {712362BF-E411-4F43-99D2-EB15F80AF1DB} -
http://entimg.msn.com/client/msnediag3606.cab
O16 - DPF: {74C861A1-D548-4916-BC8A-FDE92EDFF62C} -
http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield
International Setup Player) -
http://www.installengine.com/engine/isetup.cab
O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) -
http://a19.g.akamai.net/7/19/7125/4056/ftp...02/cpbrkpie.cab
O16 - DPF: {963BE66B-121D-4E6C-BF9F-1A774D9A2E41} (MSN Money Charting) -
http://moneycentral.msn.com/cabs/pmupdate2.exe
O16 - DPF: {AECD14A8-F662-11D1-A395-00805F535788} (Plotwon Control) -
http://www.investors.com/member/ocx/plotwon.ocx
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) -
https://www-secure.symantec.com/techsupp/ac...ta/SymAData.dll
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) -
https://www-secure.symantec.com/techsupp/ac.../ActiveData.cab
O16 - DPF: {E8F628B5-259A-4734-97EE-BA914D7BE941} (Driver Agent ActiveX
Control) -
http://driveragent.com/files/driveragent.cab
O16 - DPF: {ED28050F-D713-43BA-A376-DCC5C35407D5} (MsnMusicAx Class) -
http://entimg.msn.com/client/msnmusax3718.cab
O16 - DPF: {EF0DBA6F-43CE-4B26-9808-2AB38FA0DB29} (MSN Money Ticker) -
http://fdl.msn.com/public/investor/v13/ticker.cab
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-loc/...066/mcfscan.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
http://chat.msn.com/bin/msnchat45.cab
After selecting these item click Fix selected Item and close the HijackThis
Reboot your machine in Safe Mode and perform a scan with McAfee (full scan) ,
also spybot and Lavasoft.
To get another opinion scan on-line from here:
Run a scan from here on-line:
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner from here:
http://www.avast.com/eng/avast-virus-cleaner.html
Run disk Clean up and defrag and see if the printer is working okay, if not
then try to uninstall the software and then reinstall it again.
Note: there are three entries in spybot log will show again read this link
to exclude them from future scan:
http://forums.spybot.info/showthread.php?t=1059