Virus Blocking Avast

Hi everyone… I’d Really Appreciate some Help on Resolving.
I’m Using the Main Administrative Account On my Pc and initially Noticed A browser Jacker Taking Over IE Occasionally ,

Currently When i Launch the Avast Splash and it performs the Memory scan… it then advises me…
" Access is Denied "
…Splash cannot Execute the following Program:
C:Downloads\Avasthomeedition 4.6\download.application\ashsimple.exe

If i perform a restart i can occasionally get the avast scanner to launch but it will then close after about 4-7 minutes into a full scan then will advise me of “Access Denied” as i mention Prior.

My Internet Explorer if currently Unavailable to be launched IE 8 … I’ve uninstalled & went back to IE7 in a effort to bypass and IE8/IE7 are unable to reinstall after advising it hasnt been installed and i need to restart and then right click “trouble Shoot” from my IE Shortcut on my desk top… Which is no longer available after my Uninstall…

Since i cant launch IE I’ve been using the latest version of Firefox which Is unable to run the “Onecare online virus scanner” But i am aware of the following Viruses which i’ve Manually tried to remove but havent located the Main Backdoor Virus which Re-Launches them.

The Viruses or Suspected Viruses are as follow:
lsass.exe
alg.exe
wuauclt
freddy49.exe
mstre19.exe
c:\windows\system32trz10.tmp
winzip32.ex_
pws:win32/daurso.gen!a
koobface

My System Information is the following :
OS Name Microsoft Windows XP Home Edition
Version 5.1.2600 Service Pack 3 Build 2600
Processor x86 Family 15 Model 2 Stepping 9 GenuineIntel ~2394 Mhz
SMBIOS Version 2.3
Hardware Abstraction Layer Version = “5.1.2600.5512 (xpsp.080413-2111)”
Total Physical Memory 2,048.00 MB
Available Physical Memory 1.06 GB
Total Virtual Memory 2.00 GB
Available Virtual Memory 1.96 GB
Page File Space 2.23 GB

I’ve Used the " Panda Active Scan 2.0" (only scanner i found on firefox for free) online scanner to locate the Major threats & allowed it to remove or attempt to remove the issues…

Yet My Avast wont launch properly and when i do get it to launch i do a bootscan and restart immediately to resolve… Yet after a few or another restart of the PC the avast will then go back to a " Access Denied’ Issue.

What can i do or what other information is needed to Help Resolve this issue…

Thanks a lot in advance.

You could try Avira rescue cd, which will scan your pc without booting windows.It will not remove anything, but rename the extensions.I don’t think it produces a log, so you will have to note any findings.
Then run Malwarebytes and SAS to remove anything found.

http://forum.avira.com/wbb/index.php?page=Thread&postID=730130#post730130
http://filehippo.com/download_malwarebytes_anti_malware/
http://filehippo.com/download_superantispyware/

Please post any findings

Hi Sirconversation,

Try a boot time scan with avast! Right click the scanner screen, select ‘schedule a boot time scan’ and reboot when requested. (Or open the tab at the top left of the scanner screen and select the boot time option from there.)

Try a scan with DrWeb CureIT!

Try the usual free adware/spyware scanners.

SUPERAntiSpyware Free
a-Squared Free
Malwarebytes’ Anti-Malware

@micky77 … Thanks I’ll try those last 2 links you provided…I reviewed all 3 and with the rescue scan my concern is finding a Clean Pc… with the rash of virus’s and hacks i’ve noticed in the news and i’m sure you guys had a few days head notice i’d probably only trust a pc right out the box right about now or a MAC lol… If u have any other tips i appreciate or online scanners i can run independently without install would be great

Thanks for the rapid reply

HI freewheelin franks

Thanks for the reply also… I have tried to launch the avast Splash screen to access the boot scan… and after the memory test is performed it will then say " Access Denied" and then close avast…After a restart or few… i will gain access of avast and will be able to perform a boot scan which i mention in my prior post…but even after doin this a few times and over a few HRs… the same issue Occurs and then Blocks access to avast as again & Unable to Load or Reinstall IE 7/8. ?? Any added tips? … i Am tryin the links u provided to resolve and will Repost the Results in a few.

Appreciated

I’d definitely look at MBAM. You may need to rename the installer package to get it to install, and possibly the main exe to get it to update/run after installtion.
Are you really running Avast 4.6?
That one has been out of date for a while. Get the latest, 4.8.1335.

@Tarq57… Thanks I’ll google Mbam or a good link if you ( anyone has one available) … I’m Currently running Build : Feb2009 (4.8.1335)
I’ve Been Using Avast For years… So Anytime it updates or Installs the latest Version I’d Often Put it in my Avast Folder Which reflects that Older version name but the older versions are Extracted and updated upon New Installs to my Belief ? Could this be a Issue or just Superficial?

Appreciated

FreewheelinFrank posted a link to MBAM above. Micky77 posted a link for the same program, different mirror. (Either site is fine.)

Regarding your program run location. I actually dont’ know if this could be a problem. I think it may be.
I usually have the program run from its default location and keep downloaded files (installers etc) in a different folder completely.
It would seem that possibly there is some confusion from within the program as to what is supposed to run, possibly caused by the path.
The “C:Downloads\Avasthomeedition 4.6\download.application\ashsimple.exe” causes a bit of puzzlement and suspicion to me. I mean, why is 4.6 still trying to run? Maybe it’s because the version of “ashsimple” hasn’t actually changed since 4.6, while other aspects of the program have.
But I don’t think so. My one is titled ashSimp.exe and the version # is 4.8.1335.
It is even possible your version of Avast may not be the real thing.

PS it is also possible, of course, that the malware is corrupting/modifying the error message, and your installation mayy be otherwise fine.
I just don’t know enough to be sure. Something worth checking out, though.

@Targ57…Thanks again for the tips and rapid reply…

I’m Checkin Each of the prior links/Programs by micky77 & FreewheelinFrank
I started out with Malwarbytes and just completed the quick scan with the results posted below… I will also check out the other links if the issue isn’t resolved… I didn’t want to Run too many programs which may conflict or interrupt each other… So I’ll Definitely advise which worked and the results of each if possible till fixed… All the help is appreciated from Everyone.

As for the Name of the folder… I’ve Recently Updated Avast Renewals & From everything i’ve checked it Seems to be Legit… I would Often create a Subfolder of the most recent Version in that Intial Folder to Keep track & find it quick on downloads of newer versions.

Should I try to uninstall and re-DownLoad Avast ?? and how will that affect my License Key if any affect at all??? & should i use the Control Panel Add/Remove program or the Avast Uninstall option in the folder itself. ??

I am able to access the Avast Icon in my tool bar and go into the menu options and get the information such as the version which is " version # is 4.8.1335. Version 4.8 Home Edition… That information i accessed thru the " About Avast " option.

The main issue is when i launch the Antivirus Scanner … after doin the memory check to launch the interface… it would then advise " Access Denied" and the prior information i mentioned…

Thanks again

I will post the Malwarebytes Log in the next few links since i’m limited to a 1000 key limit

Malwarebytes’ Anti-Malware 1.39
Database version: 2432
Windows 5.1.2600 Service Pack 3

7/15/2009 5:48:42 AM
mbam-log-2009-07-15 (05-48-33).txt

Scan type: Quick Scan
Objects scanned: 185304
Time elapsed: 1 hour(s), 28 minute(s), 1 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 56
Registry Values Infected: 2
Registry Data Items Infected: 3
Folders Infected: 23
Files Infected: 167

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) → No action taken.
HKEY_CLASSES_ROOT\TypeLib{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) → No action taken.
HKEY_CLASSES_ROOT\Interface{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) → No action taken.
HKEY_CLASSES_ROOT\CLSID{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) → No action taken.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) → No action taken.
HKEY_CLASSES_ROOT\videoegg.activexloader (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{168dc258-1455-4e61-8590-9dac2f27b675} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{1a8642f1-dc80-4edc-a39d-0fb62a58b455} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{3f91eb90-ef62-44ee-a685-fac29af111cd} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{5c29c7e4-5321-4cad-be2e-877666bed5df} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{83dfb6ee-ab18-41b5-86d4-b544a141d67e} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{88d6cf0e-cf70-4c24-bf6e-e4e414bc649c} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{8f6a82a2-d7b1-443e-bb9f-f7dc887dd618} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{9856e2d8-ffb2-4fe5-8cad-d5ad6a35a804} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{a3d06987-c35e-49e4-8fe2-ac67b9fbfb4c} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{a58c497b-3ee2-45e7-9594-daca6be2a0d0} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{ad0a3058-fd49-4f98-a514-fd055201835e} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{ad5915ea-b61a-4dba-b5c8-ef4b2df0a3c7} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution

Units{af2e62b6-f9e1-4d4f-a10a-9dc8e6dcbcc0} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{bb187c0d-6f53-4f3e-9590-98fd3a7364a2} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{c5041fd9-4819-4dc4-b20e-c950b5b03d2a} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{d17726cc-d4dd-4c4a-9671-471d56e413b5} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{db8cce99-59c6-4552-8bfc-058feb38d6ce} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{dc3a04ee-cdd7-4407-915c-a5502f97eecd} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{e1a63484-a022-4d42-830a-fbd411514440} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\CLSID{e282c728-189d-419e-8ee2-1601f4b39ba5} (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\videoegg.activexloader.1 (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\Interface{2e9937fc-cf2f-4f56-af54-5a6a3dd375cc} (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\Interface{741de825-a6f0-4497-9aa6-8023cf9b0fff} (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\CLSID{147a976f-eee1-4377-8ea7-4716e4cdd239} (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\CLSID{a4730ebe-43a6-443e-9776-36915d323ad3} (Adware.MyWebSearch) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{bbd4551a-9b23-41cd-9bcd-818aa2da7b63} (Trojan.FakeAlert) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{07b18ea1-a523-4961-b6bb-170de4475cca} (Adware.MyWebSearch) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{674de1aa-facf-47a5-a4cf-9ef05f9a1b2a} (Trojan.FakeAlert) → No action taken.
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) → No action taken.
HKEY_USERS.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) → No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{19127ad2-394b-70f5-c650-b97867baa1f7} (Backdoor.Bot) → No action taken.
HKEY_USERS\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer{43bf8cd1-c5d5-2230-7bb2-98f22c2b7dc6} (Backdoor.Bot) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\videoegg (Adware.VideoEgg) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\VideoEgg (Adware.VideoEgg) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\VideoEgg (Adware.VideoEgg) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\MozillaPlugins@videoegg.com/publisher,version=1.5 (Adware.VideoEgg) → No action taken.
HKEY_CLASSES_ROOT\mywebsearchwbbar.settingsplugin (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\mywebsearchwbbar.settingsplugin.1 (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\mywebsearchwbbar.toolbarplugin (Adware.MyWebSearch) → No action taken.
HKEY_CLASSES_ROOT\mywebsearchwbbar.toolbarplugin.1 (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FunWebProducts (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) → No action taken.
HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) → No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\sysfbtray (Worm.KoobFace) → No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) → Bad: (1) Good: (0) → No action taken.
HKEY_CLASSES_ROOT\CLSID{46c166aa-3108-11d4-9348-00c04f8eeb71}\inprocserver32(default) (Hijack.Hnetcfg) → Bad: (\?\globalroot\systemroot\installer\f3d0ce2.msi) Good: (hnetcfg.dll) → No action taken.

Folders Infected:
C:\Program Files\MyWebSearch (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) → No action taken.
C:\Program Files\FunWebProducts (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\PopSwatr (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\PopSwatr\History (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\ScreenSaver (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\Shared (Adware.MyWebSearch) → No action taken.
C:\Documents and Settings\Work.Hm.Pc\Application Data\VideoEgg (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Data (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Loader (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Loader\4665 (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Publisher (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520 (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\messages (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4665 (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\4665 (Adware.VideoEgg) → No action taken.

Files Infected:
C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) → No action taken.
C:\Documents and Settings\Work.Hm.Pc\Application Data\VideoEgg\Loader\4665\npvideoegg-loader.dll (Adware.VideoEgg) → No action taken.
c:\program files\mywebsearch\bar\History\search (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar\Settings\settings.dat (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar\Settings\settings.htm (Adware.MyWebSearch) → No action taken.
c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\PopSwatr\History\allowed (Adware.MyWebSearch) → No action taken.
c:\program files\funwebproducts\PopSwatr\History\notallow (Adware.MyWebSearch) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\DataLOCKED (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Uninstall.exe (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Data\report.log (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Loader\loader.ver (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\publisher.ver (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\avcodec.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\crashRpt.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\FLVEncoder.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\lame_enc.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\LevelMeter.ax (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\libcurlve.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\libpng.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\npvideoegg-publisher.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\VideoEgg_FLVWriter.ax (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\zlib.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\aol_watermark.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\audio_combo.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\audio_source.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\big_gray_logo.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\big_logo_cropped.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\blank_slide.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\button_browse_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\button_browse_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\button_browse_up.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\camcorders_title.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\camcorder_btn_highlighted.png (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\camcorder_slide.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\corners_bottom_left.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\corners_bottom_left_curve.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\corners_bottom_right.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\corners_top_right.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done_capture.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done_capture_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done_capture_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\done_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dropshadow_bottom_left.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dropshadow_horiz.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dropshadow_vertical.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dropzone.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dv_fast_forward.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dv_pause.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dv_play.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dv_rewind.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\dv_stop.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\email_instructions.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\email_sent.png (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\email_sent_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\email_sent_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\eraser.CUR (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\eraser_cursor.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\file_btn_highlighted.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\file_slide.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\help.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_camcorder.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_camcorders.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_camcorder_dark.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_camcorder_light.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_ff.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_file_dark.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_file_light.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_pause.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_phone_dark.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_phone_light.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_play.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_rewind.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_stop.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_webcam.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_webcams.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_webcam_dark.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\icon_webcam_light.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\loading.png (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\loading_movie.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\locating.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\logo.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\logo_bottom.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\logo_middle.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\logo_top.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\mobile_btn_highlighted.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\mobile_slide.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\mobile_slide_disabled.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\movie_placeholder.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\ok.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\ok_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\ok_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_fast_forward.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_fast_forward_disabled.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_fill.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_pause.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_play.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_rewind.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_rewind_disabled.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\player_rewind_to_start.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\playhead.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\powered_by.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\progress.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\refresh_list_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\refresh_list_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\refresh_list_up.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\restart.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\restart_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_capture.png (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_capture_disabled.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_capture_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_capture_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_over_highlight.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\start_slider.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\stop_capture.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\stop_capture_disabled.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\stop_capture_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\stop_capture_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\stop_slider.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\tab_slide_deselected.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\tape_control.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_camcorder.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_camcorder_highlight.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_file.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_file_highlight.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_phone.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_phone_highlight.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_webcam.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\text_webcam_highlight.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\title.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\upload.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading_fill.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading_high.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading_low.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading_medium.png (Adware.VideoEgg) → No action taken.

c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\uploading_thumbnail.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\upload_down.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\upload_from.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\upload_over.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_gray.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_green.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_high.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_low.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_orange.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_red.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\volume_slider.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\waiting_for_email.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\webcams_title.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\webcam_btn_highlighted.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\images\webcam_slide.png (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\publisher\4520\resources\VideoEgg\messages\messages.en-US.bundle (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\updater.exe (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\updater.ver (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\VideoEggBroker.exe (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\VideoEggBroker.exe.old (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\4665\libcurlve.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\application data\VideoEgg\Updater\4665\updater.dll (Adware.VideoEgg) → No action taken.
c:\documents and settings\Work.Hm.Pc\local settings\Temp\cd15E3.tmp (Heuristics.Malware) → No action taken.
C:\Program Files\Common\helper.sig (Trojan.Agent) → No action taken.
C:\WINDOWS\SYSTEM32\DRIVERS\str.sys (Rootkit.Agent) → No action taken.
C:\WINDOWS\bf23567.dat (Worm.KoobFace) → No action taken.
c:\WINDOWS\0101120101465749.dat (Worm.KoobFace) → No action taken.
c:\WINDOWS\0101120101465752.dat (Worm.KoobFace) → No action taken.

I Have Since Taken the Suggested Option By Malwarebytes & Deleted/Quarantine these FIles and Restarted the PC

The Same Issue with Launchin the Avast Splash Has Occurred !

Quickly run this program, it will take seconds http://filehippo.com/download_hijackthis/
Then post that first
Choose scan and save a log file, copy/paste the txt log. Then I would run MBAM quick scan again, should be lots quicker. Then run SAS and post both logs. I get the feeling, something is still lurking

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 7:19:04 AM, on 7/15/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Downloads\avasthomeedition 4.6\download.application\aswUpdSv.exe
C:\Downloads\avasthomeedition 4.6\download.application\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\WINDOWS\wanmpsvc.exe
C:\Downloads\avasthomeedition 4.6\download.application\ashMaiSv.exe
C:\Downloads\avasthomeedition 4.6\download.application\ashWebSv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\BroadJump\Client Foundation\CFD.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\DOWNLO~1\AVASTH~1.6\DOWNLO~1.APP\ashDisp.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\eFax Messenger 4.1\J2GDllCmd.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AWS\WEATHE~1\Weather.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Malwarebytes’ Anti-Malware\mbam.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
C:\Program Files\IE7-WindowsXP-x86-enu.exe
c:\6f9b93bb5472ded60bfb76c4564c7fa5\update\iesetup.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe