Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

HijackThis Log: Please help Diagnose


  • Please log in to reply
6 replies to this topic

#1 tuknrm

tuknrm

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:41 PM

Posted 15 July 2005 - 09:15 PM

Logfile of HijackThis v1.99.1
Scan saved at 10:09:12 PM, on 7/15/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
c:\windows\system32\vvbtva.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\LimeWire\LimeWire 4.2.6\LimeWire.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\tuknrm\LOCALS~1\Temp\Rar$EX19.829\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.e4me.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Qosfpogz] C:\Program Files\Rfwpm\Azkoy.exe
O4 - HKLM\..\Run: [smmdxde] c:\windows\system32\smmdxde.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [qabbzr] c:\windows\system32\foqbsfe.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [yggmvf] c:\windows\system32\hwqcivb.exe r
O4 - HKLM\..\Run: [knsuhuj] c:\windows\system32\gsbflqw.exe r
O4 - HKLM\..\Run: [fgoxqb] c:\windows\system32\vvbtva.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: RitzPix E-Z Print & Share.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe

BC AdBot (Login to Remove)

 


m

#2 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,395 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:41 PM

Posted 17 July 2005 - 02:29 PM

Welcome,
Please follow the instructions provided, you may want to print out these instructions and use them as a reference.

First:
Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
http://www.ewido.net/en/download/updates/

Once the updates are installed close the Ewido program.

Reboot your computer into Safe Mode

Once in safe mode, start Ewido and do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • While the scan is in progress you will be prompted to clean files, click OK
  • When it asks if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report.txt file to your desktop.
Now close ewido security suite.

Reboot back to normal mode, open report.txt and post it as a reply to this post.

#3 tuknrm

tuknrm
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:41 PM

Posted 17 July 2005 - 10:56 PM

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 11:51:57 PM, 7/17/2005
+ Report-Checksum: 89BA40D0

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-3833581854-1532886375-2419647484-1005\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-3833581854-1532886375-2419647484-1005\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-3833581854-1532886375-2419647484-1005\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-3833581854-1532886375-2419647484-1005\Software\Microsoft\Internet Explorer\Extensions\{6685509E-B47B-4f47-8E16-9A5F3A62F683} -> Spyware.MoneyMaker : Cleaned with backup
:mozilla.7:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.8:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.9:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.10:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.11:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.14:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.15:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.16:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.17:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.18:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.19:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.20:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.21:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.22:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.23:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.33:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.34:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.49:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.50:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.51:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.65:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.66:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.68:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.69:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.70:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.71:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.78:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.79:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.80:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.81:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.103:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.104:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.127:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.128:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.130:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.152:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.153:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.154:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.155:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.156:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.157:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.158:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.167:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.179:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.180:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Matchcraft : Cleaned with backup
:mozilla.181:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Matchcraft : Cleaned with backup
:mozilla.182:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Matchcraft : Cleaned with backup
:mozilla.192:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.193:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.212:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.213:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.225:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.226:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.227:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.228:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.232:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.233:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.234:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.235:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.236:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.237:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.250:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.251:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.252:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.253:C:\Documents and Settings\becky\Application Data\Mozilla\Firefox\Profiles\default.n02\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@adopt.specificclick[1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@ads.pointroll[2].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@commission-junction[2].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@data.coremetrics[1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@ehg-nbif.hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@overture[2].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@perf.overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@servedby.advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\becky\Cookies\becky@z1.adserver[1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\becky\Desktop\MyFunCardsSetup2.0.3.26.exe -> Spyware.MyWebSearch : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\AAC\auraupg1.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ARZ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\BKP\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\BZY\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\CXF\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\CZY\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\DDJ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\DDU\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\DUJ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\DWK\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\EJW\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ENF\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\FAT\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\FTS\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\GXM\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\HMX\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\HXD\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\IBV\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\IDD\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\IHQ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\IOH\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\JLV\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\JUL\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\KCK\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\KPY\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\LKE\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\LXD\uacupg.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\MIU\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\mm_reco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\MXO\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\NFC\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\NOU\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\PCM\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\PNS\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\RBT\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\UCD\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ULK\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\VCX\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\WVR\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ZAP\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ZJH\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ZLR\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ZPC\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\becky\Local Settings\Temp\ZYH\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.11:C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\default.yc2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.12:C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\default.yc2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.13:C:\Documents and Settings\bob\Application Data\Mozilla\Firefox\Profiles\default.yc2\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\bob\Local Settings\Temporary Internet Files\Content.IE5\4KKCPLJ5\Nail[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\bob\Local Settings\Temporary Internet Files\Content.IE5\OT42HKO7\Nail[1].exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\bob\Local Settings\Temporary Internet Files\Content.IE5\XR525QIS\svcproc[1].exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.20:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.22:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.23:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.24:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.25:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.26:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.27:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.31:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.32:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.35:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.36:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.47:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
:mozilla.63:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.64:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.65:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.66:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.76:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.77:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.78:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.79:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.81:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.82:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.121:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.122:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.123:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.124:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.125:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.126:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.127:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.128:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.129:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.130:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.131:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.132:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.134:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.135:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.136:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.137:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.138:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.139:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.140:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.145:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.146:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.147:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.148:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.160:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.161:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.165:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.191:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.196:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.204:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.206:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.207:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.208:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.219:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.220:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.221:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.225:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.226:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.227:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.228:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.229:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.230:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.231:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.232:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.261:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.262:C:\Documents and Settings\kaylee\Application Data\Mozilla\Firefox\Profiles\default.qh2\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\kaylee\Cookies\kaylee@adopt.specificclick[2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\kaylee\Cookies\kaylee@ads18.bpath[2].txt -> Spyware.Cookie.Bpath : Cleaned with backup
C:\Documents and Settings\kaylee\Desktop\pictures.pif -> Backdoor.SdBot : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\ANB\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\CZW\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\EHX\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\EUJ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\FAT\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\FCK\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\FRB\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\GEY\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\GRI\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\HMV\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\IQP\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\KEL\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\LVP\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\mm_reco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\MOL\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\NSZ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\OFN\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\OLG\uacupg.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\PAN\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\RXD\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\TSF\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\VPN\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\VVI\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\WVT\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\XFG\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\YHM\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\kaylee\Local Settings\Temp\ZWX\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
:mozilla.11:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.12:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.52:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.53:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.55:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.71:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.82:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.83:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.84:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.85:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.86:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.87:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.88:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.89:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.92:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.94:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.95:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.96:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.97:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.98:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.99:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.100:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.101:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.108:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.109:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.110:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.111:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.112:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.113:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.114:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.115:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.116:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.117:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.131:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.132:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.133:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.134:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.135:C:\Documents and Settings\kaylee.HILLS\Application Data\Mozilla\Firefox\Profiles\default.xpq\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.136:C:\Documents and Settings\kaylee.HILLS\Applicati

#4 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,395 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:41 PM

Posted 18 July 2005 - 10:38 AM

I need to see a new hijackthis log as well

#5 tuknrm

tuknrm
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:41 PM

Posted 20 July 2005 - 08:00 PM

Logfile of HijackThis v1.99.1
Scan saved at 8:58:10 PM, on 7/20/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinRAR\WinRAR.exe
C:\DOCUME~1\tuknrm\LOCALS~1\Temp\Rar$EX00.610\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.e4me.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Qosfpogz] C:\Program Files\Rfwpm\Azkoy.exe
O4 - HKLM\..\Run: [smmdxde] c:\windows\system32\smmdxde.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [qabbzr] c:\windows\system32\foqbsfe.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [wljpryn] c:\windows\system32\gilujpi.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: RitzPix E-Z Print & Share.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe (file missing)

#6 Grinler

Grinler

    Lawrence Abrams


  • Admin
  • 43,395 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:USA
  • Local time:05:41 PM

Posted 23 July 2005 - 01:51 AM

You are currently using hijackthis from a temp directory. This can cause problems. Please create a directory on your c: drive called c:\hijackthis and download and unzip hijackthis into that directory. Run the program from that directory from now on.

For a tutorial on how to use HijackThis please see the following link:

Using HijackThis to Remove Spyware, Browser Hijackers, and Dialers

Print out these instructions and then close all windows including Internet Explorer.

Then I want you to fix some of those entries. Please do the following:

Please make sure that you can view all hidden files. Instructions on how to do this can be found here:

How to see hidden files in Windows

Run Hijackthis again, click scan, and Put a checkmark next to each of these. Then click the Fix button:

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [Qosfpogz] C:\Program Files\Rfwpm\Azkoy.exe
O4 - HKLM\..\Run: [smmdxde] c:\windows\system32\smmdxde.exe
O4 - HKLM\..\Run: [qabbzr] c:\windows\system32\foqbsfe.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [wljpryn] c:\windows\system32\gilujpi.exe r
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe (file missing)

Reboot your computer into Safe Mode

Then delete these files or directories (Do not be concerned if they do not exist)

C:\WINDOWS\Nail.exe
C:\Program Files\Rfwpm\
c:\windows\system32\smmdxde.exe
c:\windows\system32\foqbsfe.exe
C:\WINDOWS\wupdt.exe
c:\windows\system32\gilujpi.exe


Reboot your computer to go back to normal mode and post a new log.

#7 tuknrm

tuknrm
  • Topic Starter

  • Members
  • 4 posts
  • OFFLINE
  •  
  • Local time:05:41 PM

Posted 23 July 2005 - 09:18 AM

Logfile of HijackThis v1.99.1
Scan saved at 10:15:26 AM, on 7/23/2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\AIM\aim.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jucheck.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\Sony Corporation\Image Transfer\SonyTray.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.e4me.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://home.microsoft.com/search/search.asp
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.e4me.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.microsoft.com/isapi/redir.dll?p....0&plcid=0x0409
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\Money Express.exe"
O4 - Global Startup: Event Reminder.lnk = C:\Program Files\Broderbund\PrintMaster\PMremind.exe
O4 - Global Startup: Exif Launcher.lnk = C:\Program Files\FinePixViewer\QuickDCF.exe
O4 - Global Startup: Image Transfer.lnk = ?
O4 - Global Startup: RitzPix E-Z Print & Share.lnk = ?
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZU
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: MoneySide - {E023F504-0C5A-4750-A1E7-A9046DEA8A21} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.e4me.com
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=36467&clcid=0x409
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe (file missing)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users