I do not know the name of the file. Unfortunately the post has been removed and I cannot locate a similar post to provide you a link.
Here is the HiJack log...
----------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:32 AM, on 10/19/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Trend Micro\HijackThis\icmore.exe
C:\Program Files\Internet Explorer\iexplore.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.nuklearpower.com/
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: Registration Athena Sword.LNK = D:\Support\Register\RegistrationReminder.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 4947 bytes
----------------
Here is the AVG report
---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------
+ Created at: 10:19:44 AM 10/19/2007
+ Scan result:
HKU\S-1-5-21-1004336348-1078145449-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA0D26BD-9029-431A-86E0-83152D67828A} -> Adware.180Solutions : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3F6A9C46-3382-47C8-B9B8-3134B22B90A5}\RP822\A0467899.exe -> Adware.WeirWeb : Cleaned with backup (quarantined).
C:\System Volume Information\_restore{3F6A9C46-3382-47C8-B9B8-3134B22B90A5}\RP822\A0467900.exe -> Adware.WeirWeb : Cleaned with backup (quarantined).
C:\Documents and Settings\brian mah\Setup.exe -> Adware.Zango : Cleaned with backup (quarantined).
C:\Documents and Settings\brian mah\Cookies\brian mah@2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@cbs.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@divx.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@educationmanagementllc.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@heavycom.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@metacafe.122.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@paypal.112.2o7[1].txt -> TrackingCookie.2o7 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@adserver.71i[2].txt -> TrackingCookie.71i : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@arn.aavalue[1].txt -> TrackingCookie.Aavalue : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@3.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@4.adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@adbrite[1].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ads.adbrite[2].txt -> TrackingCookie.Adbrite : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ads.addynamix[1].txt -> TrackingCookie.Addynamix : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@rotator.adjuggler[2].txt -> TrackingCookie.Adjuggler : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@adrevolver[3].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@media.adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@advertising[2].txt -> TrackingCookie.Advertising : Cleaned.
C:\WINDOWS\Temp\Cookies\brian
mah@servedby.advertising[1].txt -> TrackingCookie.Advertising : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@atdmt[2].txt -> TrackingCookie.Atdmt : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@bluestreak[1].txt -> TrackingCookie.Bluestreak : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ads.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ge.bridgetrack[2].txt -> TrackingCookie.Bridgetrack : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@www.burstbeacon[2].txt -> TrackingCookie.Burstbeacon : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@burstnet[1].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@www.burstnet[2].txt -> TrackingCookie.Burstnet : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@casalemedia[2].txt -> TrackingCookie.Casalemedia : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ad1.clickhype[1].txt -> TrackingCookie.Clickhype : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@techrepublic.com[2].txt -> TrackingCookie.Com : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@doubleclick[2].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@adopt.euroclick[2].txt -> TrackingCookie.Euroclick : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@as-eu.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@as-us.falkag[1].txt -> TrackingCookie.Falkag : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@fastclick[2].txt -> TrackingCookie.Fastclick : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@fortunecity[1].txt -> TrackingCookie.Fortunecity : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-bestbuy.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-globalgamingleague.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-groupernetworks.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-ifilm.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-linksys.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-traderpublishing.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-upperdeck.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-warnerbrothers.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ehg-youtube.hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@hitbox[1].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINDOWS\Temp\Cookies\brian
mah@ehg-knightridder.hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@hitbox[2].txt -> TrackingCookie.Hitbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@ivwbox[1].txt -> TrackingCookie.Ivwbox : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@search.live[1].txt -> TrackingCookie.Live : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@image.masterstats[1].txt -> TrackingCookie.Masterstats : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@auto.search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@search.msn[2].txt -> TrackingCookie.Msn : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@data2.perf.overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@data4.perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@overture[2].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@perf.overture[1].txt -> TrackingCookie.Overture : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@www.paypal[1].txt -> TrackingCookie.Paypal : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ads.pointroll[1].txt -> TrackingCookie.Pointroll : Cleaned.
C:\WINDOWS\Temp\Cookies\brian
mah@ads.pointroll[2].txt -> TrackingCookie.Pointroll : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@questionmarket[2].txt -> TrackingCookie.Questionmarket : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@realmedia[1].txt -> TrackingCookie.Realmedia : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@revenue[2].txt -> TrackingCookie.Revenue : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@revsci[2].txt -> TrackingCookie.Revsci : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@edge.ru4[1].txt -> TrackingCookie.Ru4 : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@bs.serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@serving-sys[1].txt -> TrackingCookie.Serving-sys : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@sexlist[1].txt -> TrackingCookie.Sexlist : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@smartadserver[1].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@smartadserver[3].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@www.smartadserver[2].txt -> TrackingCookie.Smartadserver : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@statcounter[2].txt -> TrackingCookie.Statcounter : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@anad.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@anat.tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@tradedoubler[1].txt -> TrackingCookie.Tradedoubler : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@trafficmp[2].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\WINDOWS\Temp\Cookies\brian mah@trafficmp[1].txt -> TrackingCookie.Trafficmp : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@a.tribalfusion[1].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@tribalfusion[2].txt -> TrackingCookie.Tribalfusion : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@reduxads.valuead[2].txt -> TrackingCookie.Valuead : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@m.webtrends[1].txt -> TrackingCookie.Webtrends : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@statse.webtrendslive[2].txt -> TrackingCookie.Webtrendslive : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian
mah@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\WINDOWS\Temp\Cookies\brian
mah@ad.yieldmanager[2].txt -> TrackingCookie.Yieldmanager : Cleaned.
C:\Documents and Settings\brian mah\Cookies\brian mah@zedo[1].txt -> TrackingCookie.Zedo : Cleaned.
::Report end
--------------
And the NOD file
# version=4
# OnlineScanner.ocx=1.0.0.56
# OnlineScannerDLLA.dll=1, 0, 0, 51
# OnlineScannerDLLW.dll=1, 0, 0, 51
# OnlineScannerUninstaller.exe=1, 0, 0, 49
# vers_standard_module=2603 (20071019)
# vers_arch_module=1.058 (20070906)
# vers_adv_heur_module=1.066 (20070917)
# EOSSerial=cc422154d945474295730202cea61d41
# end=finished
# remove_checked=false
# unwanted_checked=true
# utc_time=2007-10-19 05:51:51
# local_time=2007-10-19 10:51:51 (-0800, Pacific Daylight Time)
# country="United States"
# osver=5.1.2600 NT Service Pack 2
# scanned=142535
# found=0
# scan_time=1318