Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

"fake fix windows malware"


  • Please log in to reply

#1
illuminati

illuminati

    Member

  • Member
  • PipPip
  • 56 posts
okay so 2 programs called
virus birst
and antivirus golden
infected my computer and create fake "system errors"
when u click on them they go to a buy this site

** and there are a few popups here and there **
please help :whistling:
thank you
oh and btw dont worry about QQ
heres the hjt log if u want...

Logfile of HijackThis v1.99.1
Scan saved at 8:02:54 PM, on 9/16/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\strCodec\isamonitor.exe
C:\Program Files\strCodec\pmsngr.exe
C:\Program Files\strCodec\pmmon.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\strCodec\isamini.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {202a961f-23ae-42b1-9505-ffe3c818d717} - C:\Program Files\strCodec\isaddon.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll
O3 - Toolbar: Protection Bar - {479fd0cf-5be9-4c63-8cda-b6d371c67bd5} - C:\Program Files\strCodec\iesplugin.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [NAV CfgWiz] c:\Program Files\Common Files\Symantec Shared\CfgWiz.exe /GUID NAV /CMDLINE "REBOOT"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Organize.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP OfficeJet Series 500 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\Bin\HPOstr05.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZNxmk572IUUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL (file missing)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O21 - SSODL: hemadynamometer - {6076d2b1-634c-4685-843b-f826045ea5dc} - C:\WINDOWS\System32\syycum.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
  • 0

Advertisements


#2
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
Run HJT:
  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

1) Download SmitfraudFix.zip by S!Ri from here and save it to your Desktop.
You will then need to extract the files.
To do this: Right click on the zipped folder and from the menu that appears, click on Extract All...
In the 'Extraction Wizard' window that opens, click on Next> and in the next window that appears, click on Next> again.
In the final window, click on Finish


2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "1" and then <ENTER> to start the search process.
When the search has completed, a text file, rapport.txt, will open with the results in - Copy and paste this report into your next reply.

A copy of the report can be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
For most, this file can be found by double-clicking My Computer and then Local Disk (C:)


IMPORTANT: Do NOT run any other options until you are asked to do so!

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.
http://www.beyondlog...processutil.htm

This fix is based on a canned speech supplied by Kimberly.
  • 0

#3
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
okay uhh i downloaded smitfraudfix...
and 1 as soon as i extracted Norton told me i just got a bloodhound virus...>.<
and then i tried to run smitfroud fix it said that download.exe was missing...
  • 0

#4
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
and uhh
the popups are in creasing
probbally due to the bloodhound?
  • 0

#5
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
"Bloodhound" is a Symantec term for something that it thinks looks suspicious - this tool isn't a risk, but it has a component that could be used maliciously, which is why Norton got involved.
You will need to set your anti-virus program to ignore this file when you download it, otherwise you won't be able to supply the information I require, nor remove the infection.
  • 0

#6
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
yay =) tyty
oh and i just did a ewido full system scan rite b4 it and removed like...700+ things if that helps any :whistling:


SmitFraudFix v2.91

Scan done at 15:44:05.56, 09/17/2006 Sun
Run from C:\Documents and Settings\ning.FAMILYCOMP\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in normal mode

换换换换换换换换换换换换 C:\


换换换换换换换换换换换换 C:\WINDOWS

C:\WINDOWS\drsmartload2.dat FOUND !
C:\WINDOWS\keyboard1.dat FOUND !
C:\WINDOWS\newname.dat FOUND !

换换换换换换换换换换换换 C:\WINDOWS\system


换换换换换换换换换换换换 C:\WINDOWS\Web


换换换换换换换换换换换换 C:\WINDOWS\system32

C:\WINDOWS\system32\syycum.dll FOUND !

换换换换换换换换换换换换 C:\Documents and Settings\ning.FAMILYCOMP\Application Data


换换换换换换换换换换换换 Start Menu

C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url FOUND !

换换换换换换换换换换换换 C:\DOCUME~1\NING~2.FAM\FAVORI~1


换换换换换换换换换换换换 Desktop

C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url FOUND !
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url FOUND !

换换换换换换换换换换换换 C:\Program Files

C:\Program Files\strCodec\ FOUND !

换换换换换换换换换换换换 Corrupted keys


换换换换换换换换换换换换 Desktop Components

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"


换换换换换换换换换换换换 Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{6076d2b1-634c-4685-843b-f826045ea5dc}"="hemadynamometer"

[HKEY_CLASSES_ROOT\CLSID\{6076d2b1-634c-4685-843b-f826045ea5dc}\InProcServer32]
@="C:\WINDOWS\System32\syycum.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6076d2b1-634c-4685-843b-f826045ea5dc}\InProcServer32]
@="C:\WINDOWS\System32\syycum.dll"



换换换换换换换换换换换换 AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\\PROGRA~1\\Google\\GOOGLE~1\\GOEC62~1.DLL"

换换换换换换换换换换换换 Scanning wininet.dll infection


换换换换换换换换换换换换 End
  • 0

#7
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Download the trial version of Ewido anti-spyware from here and save it to your Desktop.
If you already have this program installed, skip to Updating Ewido: below.

* Please note that these instructions are for the new version - Ewido anti-spyware. If you have the old version - Ewido anti-malware and it is the:
  • paid-for version - you will need to go here and obtain an updated license code before you upgrade.
  • free version - you will need to uninstall it and reboot before installing the new version.
Double click the ewido-setup file to begin installation and follow the prompts.
When the program has been installed, and you click the Finish button, Ewido anti-spyware will open.
  • Updating Ewido:

    By default Ewido is configured to update automatically so, if you have an active internet connection, it should do so following installation. If you are unsure whether or not it has done so, do the following:
  • Click the Update icon at the top and under "Manual Update" - click the Start update button.
  • Either Ewido will update or inform you that no update was available.
  • If you cannot access the internet with the infected PC, or you are having problems updating, you can download the signatures file from here.
    Once you have installed Ewido, double click ewido-signatures-full-current.exe to update it.

    Disabling the Resident Shield:
  • By default the Resident Shield is active but as it may interfere with the process of cleaning your PC, it will need to be disabled.
    (When the PC has been cleaned you can activate the shield again, if you wish.)
  • Click the Shield icon at the top and under "Resident shield is..." - click active.
  • This should now change to inactive.

    Changing Recommended Actions
  • Click the Scanner icon at the top and then click the Settings Tab.
  • Under "How to act?" click Recommended actions and select "Quarantine" from the menu.
You can now close Ewido anti-spyware.

Ewido anti-spyware is designed to be used to both scan for and remove malicious files and also to run in real-time alongside, but not replace, your existing anti-virus program to give an added layer of protection.
Both the Resident Shield and Automatic Updates will only be available for the thirty day trial period, after that Ewido will revert to a stand-alone scanner which you can keep and manually update for free and use in a similar way to Ad-Aware SE Personal, Spybot S&D etc.
Should you wish to benefit from the real-time protection, you will need to upgrade the program. To do this, simply open it and click on the Buy now button.


2) You will need to know how to boot into Safe Mode.
Instructions can be found here.

3) You will need to set Windows to show All Hidden Files and Folders.
Instructions can be found here.
** These files are hidden to stop you accidentally removing something important.
It is advisable to hide them again after fixing your computer. **

4) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Boot into Safe Mode.

2) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "2" and then <ENTER> to start the cleaning process.
  • Wait for the tool to complete and disk cleanup to finish.
  • You will be prompted "Registry cleaning - Do you want to clean the registry ? Press "Y" and then <ENTER>.
  • The tool will also check if wininet.dll is infected. You may be prompted to "Replace infected file ?" - press "Y" and then <ENTER>.
Your PC now needs to be rebooted. If this does not happen automatically, you will need to do so manually. Either way, your PC will need to be booted back INTO SAFE MODE.

3) Navigate to the C:\Windows\Temp folder and delete all the files that you find there.
Do this for all Usernames.

4) Navigate to C:\Documents and Settings\Username\Local Settings\Temp and delete all the files that you find there.
Do this for all Usernames.

5) Go to Start > Control Panel > Internet Options and under Temporary Internet files, click on Delete Files...
Check the box to the left of 'Delete all offline content' and then click on OK.

6) Go to Start > Control Panel > Display.
Select the Desktop Tab, click on Customise Desktop... and then select the Web Tab.
Under Web pages: you may see a checked entry called Security info - or similar. Highlight this entry and then click the Delete button.
Finally click OK > Apply > OK.

7) Empty the Recycle Bin.

8) Ensure that ALL open Windows / Programs / Folders are closed and then run Ewido anti-spyware.
  • If it is not already selected, click the Scanner icon at the top and then select the Scan Tab.
  • Click "Complete System Scan"
  • While the scan is in progress the PC should be left otherwise idle - so if you fancy a cuppa, now's the time to put the kettle on!
  • When the scan has completed, any threats that Ewido has detected will be displayed.
  • Click the Apply all actions button at the bottom.
  • When Ewido has finished, it will display the message "All actions have been applied".

    Saving a report:
  • Click the Save Report button at the bottom left and the "Reports" window will open.
  • The content of the scan report will be displayed in the right hand pane and a copy will be automatically saved as Report-Scan-date-time.txt into the C:\Program Files\ewido anti-spyware 4.0\Reports folder.
  • You will need to post a copy of this report into your next reply, so if it is more convenient, you can save another copy of this report elsewhere:
    Click the Save report as button and select a destination by clicking the down arrow to the right of the Save in: text box and then click Save.
Close Ewido Anti-Spyware.

9) Reboot into Normal Mode.

10) Open the SmitfraudFix folder and double-click smitfraudfix.cmd
Press "3" and then <ENTER> to "Delete Trusted Zone".
When prompted "Restore Trusted Zone ?", press "Y" and then <ENTER>.

* Please Note: If you use SpywareBlaster and/or IE/Spyads, it will be necessary to re-install the protection both afford. For SpywareBlaster, run the program and re-protect all items. For IE/Spyads, run the batch file and reinstall the protection *

Will you then post the following:
  • A new HJT log,
  • The Ewido log,
  • The text file rapport.txt that will be found in the root of your drive, eg: Local Disk C: or partition where your operating system is installed.
    For most, this file can be found by double-clicking My Computer and then Local Disk (C:)
  • A description of how your PC is behaving.
This fix is based on a canned speech supplied by Kimberly.
  • 0

#8
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
well
the only thing ive got right now is
good news
and gratitude =)
but yea my computer is running lightning fast again... and the fake "warnings" have all gone away
*ewido is powerful!* the scan took over 2 hours but it took out 900+ things! wowie..
so im guessing all we have left is a little bit of cleanup?

heres the ewido log

---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------

+ Created on: 9:11:38 PM, 9/17/2006
+ Report-Checksum: A043557

+ Scan result:

:mozilla.6:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.9:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.10:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.11:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.12:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.26:C:\Documents and Settings\admin\Application Data\Mozilla\Firefox\Profiles\ocwdvbsp.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\admin\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\admin\Cookies\admin@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\admin\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\admin\Cookies\admin@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\cursorcafe.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\cursorcafeA.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindIt.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\FindItHot.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\findithotxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\finditxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\games.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Games0.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\gamesA.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Highlight.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\HighlightHot.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlighthotxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\highlightxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\jokesearch.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\logo.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\logoxp.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Movies0.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\moviesA.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\pranks.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Reference.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\ReferenceHot.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\referencehotxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\referencexp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaver.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\screensaverA.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Screensavers0.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\ScreensaversMarketingSitePager0.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\smiley.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\smileyxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\Weather.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\weatherhotxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\buttons\weatherxp.png -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\contexts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\contexts\error.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\contexts\related.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\contexts\travel.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\images -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\images\walertXP.bmp -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\ProductMessagingConfig.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\SimpleUpdateConfig.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\All Users\Application Data\Starware\SimpleUpdate\TimerManagerConfig.xml.backup -> Adware.Starware : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Default User\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\JokeSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\JokeSearch\JokeSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\JokeSearch\JokeSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Pranks -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Pranks\PranksOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Pranks\PranksOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SmileyTown\SmileyTownOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\SmileyTown\SmileyTownOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Application Data\Τasks\nѕlookup.exe -> Adware.ClickSpring : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@admarketplace[3].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][3].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][3].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][3].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@cpvfeed[3].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@kmpads[3].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@starware[3].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\Default User\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Default User\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\!update.exe -> Downloader.PurityScan.da : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\ac2_0004.exe -> Downloader.Small.cpu : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\B8EA4.tmp/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\B8EA4.tmp/wfxqhv.exe -> Adware.Suggestor : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\B8EA4.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\BundleInstaller.exe -> Trojan.LdPinch.atp : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\da1F8.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\drsmartload180a.exe -> Downloader.Pakes : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\GLB227.tmp/empty_00000001 -> Adware.Ucmore : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\mmxsnet.exe -> Adware.MediaMotor : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temp\~DF21.exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\Default User\Local Settings\Temporary Internet Files\Content.IE5\UFMWJ5KZ\popup[1].php -> Hijacker.Agent.a : Cleaned with backup
C:\Documents and Settings\Default User\My Documents\sуmbols\tracert.exe -> Downloader.PurityScan.da : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\[email protected][1].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\LocalService\Cookies\system@zedo[2].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\ning\Cookies\[email protected][2].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\ning\Cookies\[email protected][2].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\Documents and Settings\ning\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\ning\Cookies\ning@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\ning\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ning\Cookies\ning@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning\Cookies\[email protected][1].txt -> TrackingCookie.G3x : Cleaned with backup
:mozilla.65:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.66:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.142:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.143:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.168:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.169:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.172:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup
:mozilla.181:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.182:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.183:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.184:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.185:C:\Documents and Settings\ning.COMPUTER\Application Data\Mozilla\Firefox\Profiles\xu3fl823.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Realcastmedia : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@click2begin[2].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\ning@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][2].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][2].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\Cookies\[email protected][1].txt -> TrackingCookie.Click2begin : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER\TMS008.exe -> Adware.Exfol : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Cookies\ning@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Cookies\ning@enhance[1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Cookies\ning@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u104.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u108.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u10A.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u112.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u113.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u114.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u11C.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u121.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.COMPUTER.000\Local Settings\Temp\u128.tmp -> Adware.SurfSide : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Screensavers -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Screensavers\ScreensaversOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Weather\AlertArchive.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Cookies\ning@admarketplace[1].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Cookies\[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\ning.FAMILY\Cookies\ning@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.20:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Doubleclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.33:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.34:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.35:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Fastclick : Cleaned with backup
:mozilla.37:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.38:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.39:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.46:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.59:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.60:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.61:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.62:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.64:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.65:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.66:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Trafficmp : Cleaned with backup
:mozilla.71:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Atdmt : Cleaned with backup
:mozilla.81:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.82:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.83:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.84:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.85:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.92:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.93:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.94:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.95:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.96:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.97:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Casalemedia : Cleaned with backup
:mozilla.98:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.99:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.100:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.101:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tribalfusion : Cleaned with backup
:mozilla.104:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.124:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.125:C:\Documents and Settings&#
  • 0

#9
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
Owing to the size of the logs, most of your post didn't register. You will need to repost the information in sections before I can do anything else.
  • 0

#10
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
uhh hers the last half of ewido scan

:mozilla.126:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.127:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.128:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.129:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.130:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.131:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.135:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Com : Cleaned with backup
:mozilla.136:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.156:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.188:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Statcounter : Cleaned with backup
:mozilla.213:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Targetnet : Cleaned with backup
:mozilla.226:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Clickzs : Cleaned with backup
:mozilla.236:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tradedoubler : Cleaned with backup
:mozilla.242:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Overture : Cleaned with backup
:mozilla.246:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Webtrendslive : Cleaned with backup
:mozilla.272:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Belstat : Cleaned with backup
:mozilla.285:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adbrite : Cleaned with backup
:mozilla.298:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Falkag : Cleaned with backup
:mozilla.303:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Ru4 : Cleaned with backup
:mozilla.313:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Cqcounter : Cleaned with backup
:mozilla.346:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Clickhype : Cleaned with backup
:mozilla.376:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Burstbeacon : Cleaned with backup
:mozilla.383:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Findwhat : Cleaned with backup
:mozilla.391:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.392:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.418:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.2o7 : Cleaned with backup
:mozilla.492:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Euroclick : Cleaned with backup
:mozilla.500:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Serving-sys : Cleaned with backup
:mozilla.505:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Valuead : Cleaned with backup
:mozilla.507:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Specificclick : Cleaned with backup
:mozilla.509:C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Mozilla\Firefox\Profiles\4tgr1ap1.default\cookies.txt -> TrackingCookie.Adjuggler : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\JokeSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Pranks -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\[email protected][2].txt -> TrackingCookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\[email protected][1].txt -> TrackingCookie.Addynamix : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\ning@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\ning@mediaplex[1].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\Cookies\ning@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.FAMILYCOMP\My Documents\sуmbols\tracert.exe -> Downloader.PurityScan.da : Cleaned with backup
:mozilla.38:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.39:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.40:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.41:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.63:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.64:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.65:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.89:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.90:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.92:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.93:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.99:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Admarketplace : Cleaned with backup
:mozilla.139:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Enhance : Cleaned with backup
:mozilla.236:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.237:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.238:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.239:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.240:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.241:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.242:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.247:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.258:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.262:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.263:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.266:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.267:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.393:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.415:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.530:C:\Documents and Settings\ning.HOMECOMP\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Configurator -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Configurator\ConfiguratorOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Configurator\ConfiguratorOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Reference -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Reference\ReferenceOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Reference\ReferenceOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Screensavers -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Screensavers\ScreensaversOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Screensavers\ScreensaversOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Weather -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Weather\AlertArchive.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Weather\WeatherOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Application Data\Starware\Weather\WeatherOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\ning@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][2].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][2].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\ning@cpvfeed[1].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\ning@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\ning@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\ning@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\3K9L7WSG\MediaTicketsInstaller[1].cab/MediaTicketsInstaller.ocx -> Dropper.PurityScan.ae : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\3K9L7WSG\preax[1].cab/preax.ocx -> Downloader.VB.aee : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\3K9L7WSG\pre[1].exe -> Hijacker.VB.lb : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\3K9L7WSG\SystemDoctor2006FreeInstall[1].cab/USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\3K9L7WSG\WinAntiVirusPro2006FreeInstall[1].cab/UWA6P_0001_N91M1807NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.o : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\CJOFUHO3\drsmartload[1].exe -> Downloader.Adload.eo : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\CJOFUHO3\joysavsht[1].cab/amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\CJOFUHO3\joysavsht[2].cab/amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\CJOFUHO3\SystemDoctor2006FreeInstall[1].cab/USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\IHITSXS3\3138302D2D2D[1].exe -> Downloader.Adload.bl : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\IHITSXS3\speedtest2[1].dll -> Not-A-Virus.Downloader.Win32.InsTool.a : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\YJC56XKN\3138302D2D2D[1].exe -> Downloader.Adload.aj : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Local Settings\Temporary Internet Files\Content.IE5\YJC56XKN\joysavsht[1].cab/amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Start Menu\Programs\UCmore - The Search Accelerator -> Adware.Ucmore : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Start Menu\Programs\UCmore - The Search Accelerator\How To Uninstall.lnk -> Adware.Ucmore : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Start Menu\Programs\UCmore - The Search Accelerator\UCmore - The Search Accelerator.lnk -> Adware.Ucmore : Cleaned with backup
C:\Documents and Settings\ning.HOMECOMP\Start Menu\Programs\UCmore - The Search Accelerator\UCmore Tour.lnk -> Adware.Ucmore : Cleaned with backup
:mozilla.111:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.112:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.113:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.114:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.175:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.176:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.177:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.203:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.242:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.243:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.244:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.246:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.247:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.291:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.292:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.293:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.383:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.384:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.385:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
:mozilla.386:C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\APKVQZY7\Setup[1].exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\BZTIREQX\hs[1].exe -> Trojan.Pakes : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\GY6YTUN6\SysProtectScannerInstall[1].cab/USYP_0001_N76M1005NetInstaller.exe -> Downloader.Small : Cleaned with backup
C:\Documents and Settings\ning.YOUR-FSYLY0JTWN\Local Settings\Temporary Internet Files\Content.IE5\GY6YTUN6\WinAntiVirusPro2006FreeInstall[1].exe -> Not-A-Virus.Downloader.Win32.WinFixer.j : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.81:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.82:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.90:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\BrowserSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\BrowserSearch\BrowserSearch.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\BrowserSearch\BrowserSearch.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ErrorSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ErrorSearch\ErrorSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Games -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Games\GamesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Games\GamesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\JokeSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\JokeSearch\JokeSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\JokeSearch\JokeSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Layouts -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Layouts\PreferencesLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Layouts\PreferencesLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Layouts\ToolbarLayout.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Layouts\ToolbarLayout.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Manager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Manager\ManagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Manager\ManagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Movies -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Movies\MoviesOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Movies\MoviesOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Pranks -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Pranks\PranksOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Pranks\PranksOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\RelatedSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\RelatedSearch\RelatedSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ScreensaversMarketingSitePager -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ScreensaversMarketingSitePager\ScreensaversMarketingSitePagerOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchAssistPlus -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchAssistPlus\SearchAssistPlusOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchMatch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchMatch\SearchMatchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchMatch\SearchMatchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SearchMatch\searchMatchPages -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SmileyTown -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SmileyTown\SmileyTownOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\SmileyTown\SmileyTownOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Toolbar -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Toolbar\TBProductsOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\Toolbar\TBProductsOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarLogo -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarLogo\ToolbarLogoOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\ToolbarSearch\ToolbarSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\TravelSearch -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\TravelSearch\TravelSearchOptions.xml -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Starware\TravelSearch\TravelSearchOptions.xml.backup -> Adware.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Application Data\Τasks\nѕlookup.exe -> Adware.ClickSpring : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@2o7[1].txt -> TrackingCookie.2o7 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@admarketplace[3].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@adrevolver[2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt -> TrackingCookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][3].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][3].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][3].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[3].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@cpvfeed[4].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@doubleclick[1].txt -> TrackingCookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@kmpads[1].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@kmpads[3].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@mediaplex[2].txt -> TrackingCookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@starware[1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@starware[3].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][4].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@tacoda[4].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\Cookies\owner@zedo[3].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\Documents and Settings\Owner\My Documents\sуmbols\tracert.exe -> Downloader.PurityScan.da : Cleaned with backup
C:\Documents and Settings\Owner\Start Menu\Virus-Burst 6.1.lnk -> Adware.Generic : Cleaned with backup
C:\Program Files\CMFibula\CMFibula.exe -> Adware.CASClient : Cleaned with backup
C:\Program Files\Common Files\imuu\imuua.exe -> Downloader.TSUpdate.l : Cleaned with backup
C:\Program Files\Common Files\imuu\imuul.exe -> Downloader.TSUpdate.r : Cleaned with backup
C:\Program Files\Common Files\Аdobe\сhkntfs.exe -> Adware.ClickSpring : Cleaned with backup
C:\Program Files\Cowabanga\Cowabanga.exe -> Dropper.VB.nn : Cleaned with backup
C:\Program Files\Deskbar\deskbar.dll -> Adware.Softomate : Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npclntax.dll -> Adware.Zango : Cleaned with backup
C:\Program Files\MSN\medetik.html -> Hijacker.Small.jf : Cleaned with backup
C:\Program Files\MSN Gaming Zone\pogow.html -> Hijacker.Small.jf : Cleaned with backup
C:\Program Files\Network Monitor\netmon.exe -> Not-A-Virus.Monitor.Win32.NetMon.a : Cleaned with backup
C:\Program Files\NewDotNet -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\readme.html -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\uninstall6_38.exe -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\NewDotNet\uninstall7_22.exe -> Adware.NewDotNet : Cleaned with backup
C:\Program Files\PSLister\PSLister.exe -> Adware.PurityScan : Cleaned with backup
C:\Program Files\Sonignup\Cache\00001316_43a8ba46_0000b71b -> Downloader.IstBar.ai : Cleaned with backup
C:\Program Files\Sonignup\Cache\00004b40_43a025d4_0005b8d8 -> Downloader.IstBar.ai : Cleaned with backup
C:\Program Files\Starware
  • 0

#11
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
heres rapport

SmitFraudFix v2.91

Scan done at 18:22:56.89, 09/17/2006 Sun
Run from C:\Documents and Settings\ning.FAMILYCOMP\Desktop\SmitfraudFix\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
Fix ran in safe mode

换换换换换换换换换换换换 Before SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler]
"{6076d2b1-634c-4685-843b-f826045ea5dc}"="hemadynamometer"

[HKEY_CLASSES_ROOT\CLSID\{6076d2b1-634c-4685-843b-f826045ea5dc}\InProcServer32]
@="C:\WINDOWS\System32\syycum.dll"

[HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{6076d2b1-634c-4685-843b-f826045ea5dc}\InProcServer32]
@="C:\WINDOWS\System32\syycum.dll"


换换换换换换换换换换换换 Killing process


换换换换换换换换换换换换 Generic Renos Fix

GenericRenosFix by S!Ri

C:\WINDOWS\System32\syycum.dll -> Hoax.Win32.Renos.gen.d
C:\WINDOWS\System32\syycum.dll -> Deleted


换换换换换换换换换换换换 Deleting infected files

C:\WINDOWS\drsmartload2.dat Deleted
C:\WINDOWS\keyboard1.dat Deleted
C:\WINDOWS\newname.dat Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted
C:\DOCUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted
C:\Program Files\strCodec\ Deleted

换换换换换换换换换换换换 Deleting Temp Files


换换换换换换换换换换换换 Registry Cleaning

Registry Cleaning done.

换换换换换换换换换换换换 After SmitFraudFix
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


换换换换换换换换换换换换 End



aaaaaand a fresh hjt log from TODAY

Logfile of HijackThis v1.99.1
Scan saved at 3:35:11 PM, on 9/18/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
c:\Program Files\Norton AntiVirus\navapsvc.exe
C:\windows\system\hpsysdrv.exe
C:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
C:\WINDOWS\System32\hphmon05.exe
C:\HP\KBD\KBD.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\LTMSG.exe
C:\WINDOWS\ALCXMNTR.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Multimedia Card Reader\shwicon2k.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\WINDOWS\wt\updater\wcmdmgr.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files\interMute\SpamSubtract\SpamSub.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trillian\trillian.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Hijackthis\HijackThis.exe

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: (no name) - - (no file)
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_08\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: HP View - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - c:\Program Files\HP\Digital Imaging\bin\hpdtlk02.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - c:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [CamMonitor] c:\Program Files\HP\Digital Imaging\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [HPHUPD05] c:\Program Files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
O4 - HKLM\..\Run: [HPHmon05] C:\WINDOWS\System32\hphmon05.exe
O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXE
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AutoTKit] C:\hp\bin\AUTOTKIT.EXE
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Sunkist2k] C:\Program Files\Multimedia Card Reader\shwicon2k.exe
O4 - HKLM\..\Run: [Reminder] "C:\Windows\Creator\Remind_XP.exe"
O4 - HKLM\..\Run: [mmtask] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [wcmdmgr] C:\WINDOWS\wt\updater\wcmdmgrl.exe -launch
O4 - HKLM\..\Run: [WT GameChannel] C:\Program Files\WildTangent\Apps\GameChannel.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Organize.lnk = ?
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSub.exe
O4 - Startup: 腾讯QQ.lnk = C:\Program Files\Tencent\QQ\QQ.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP OfficeJet Series 500 Startup.lnk = C:\Program Files\Hewlett-Packard\HP OfficeJet Series 500\Bin\HPOstr05.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Quicken Scheduled Updates.lnk = C:\Program Files\Quicken\bagent.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://edits.mywebse...?p=ZNxmk572IUUS
O8 - Extra context menu item: &Translate English Word - res://c:\program files\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O8 - Extra context menu item: 上传到QQ网络硬盘 - C:\Program Files\Tencent\QQ\AddToNetDisk.htm
O8 - Extra context menu item: 添加到QQ自定义面板 - C:\Program Files\Tencent\QQ\AddPanel.htm
O8 - Extra context menu item: 添加到QQ表情 - C:\Program Files\Tencent\QQ\AddEmotion.htm
O8 - Extra context menu item: 用QQ彩信发送该图片 - C:\Program Files\Tencent\QQ\SendMMS.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL (file missing)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://www.slide.com...ageUploader.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - c:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - c:\Program Files\Norton AntiVirus\SAVScan.exe
  • 0

#12
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You need to preview your replies before you post them as the Ewido log is still incomplete.
I'm also still waiting for the uninstall list that I asked for earlier:

Run HJT:

  • Click Open the Misc Tools section.
  • Click Open Uninstall Manager...
  • Click Save list... and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your next reply.

Let me have all of the information that I require and i'll get back to you when i've had a chance to review it - check that it is all there because I will simply ask for it again, if it isn't.
  • 0

#13
illuminati

illuminati

    Member

  • Topic Starter
  • Member
  • PipPip
  • 56 posts
>.< :) really sorry :whistling: :blink: :help:
C:\Program Files\Starware316\bin\Starware316.dll -> Adware.Comet : Cleaned with backup
C:\Program Files\Tencent\AdPlus\SSAddr.dll -> Adware.Tbh : Cleaned with backup
C:\Program Files\Tencent\AdPlus\stup.exe -> Adware.Tencent : Cleaned with backup
C:\Program Files\whInstall -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\license.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\readme.txt -> Adware.Webhancer : Cleaned with backup
C:\Program Files\whInstall\whAgent.ini -> Adware.Webhancer : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\Assist\yalive.dll/ylive.exe -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\Assist\yalive.dll/yhelper.dll -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\Assist\yalive.dll/ylive.exe -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\Assist\yalive.dll/yhelper.dll -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\Assist\yaswiper.dll -> Adware.Cdn : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\YAlive.dll/ylive.exe -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\YAlive.dll/yhelper.dll -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\YAlive.dll/ylive.exe -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\YAlive.dll/yhelper.dll -> Adware.Yassist : Cleaned with backup
C:\Program Files\Yahoo!\Assistant\ylive.exe -> Adware.Yassist : Cleaned with backup
C:\Program Files\Τаsks\tаskmgr.exe -> Adware.PurityScan : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1003\Dc1.exe -> Hijacker.Small : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc22.exe -> Hijacker.VB.or : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc23.exe -> Downloader.VB.agk : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc24.exe -> Downloader.Adload.ds : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc25.exe -> Downloader.Adload.ds : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc26.exe -> Downloader.Adload.ds : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc27.exe -> Downloader.Adload.ec : Cleaned with backup
C:\RECYCLER\S-1-5-21-2090263142-808982701-1838290916-1007\Dc29.exe -> Downloader.Adload.eb : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc10.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc11.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc12.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc13.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc14.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc15.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc16.exe -> Downloader.Adload.es : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc17.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc18.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc19.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc20.exe -> Downloader.Adload.et : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc40.exe -> Downloader.Adload.eu : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc41.exe -> Hijacker.VB.ly : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc42.exe -> Downloader.Adload.eo : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc43.exe -> Downloader.Adload.eo : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc44.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc45.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc46.exe -> Downloader.Adload.ep : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc47.exe -> Downloader.Agent.ala : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc48.exe -> Downloader.Small.cyh : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc51.exe -> Downloader.Qoologic.at : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc52.exe -> Downloader.VB.alg : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc55.exe -> Downloader.Adload.cy : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc59.exe -> Dropper.Agent.aie : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc61.exe -> Dropper.Mudrop.bq : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc62.exe -> Downloader.Dyfuca.fb : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc7.exe -> Downloader.Adload.eu : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc8.exe -> Downloader.Adload.eo : Cleaned with backup
C:\RECYCLER\S-1-5-21-629950214-409482784-1995338991-1007\Dc9.exe -> Downloader.Adload.ep : Cleaned with backup
C:\WINDOWS\ac3_0002.exe -> Downloader.Small.cyh : Cleaned with backup
C:\WINDOWS\amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\aobxmcn.exe -> Hijacker.VB.ij : Cleaned with backup
C:\WINDOWS\aobxmcnA.exe -> Downloader.VB.alu : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\APInstall_Tiny.dll -> Adware.AccessMedia : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\amm06.ocx -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\HbInstIE.dll -> Adware.HotBar : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\Kvfto.dll -> Adware.Tbh : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\Luoye.dll -> Adware.Tencent : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\MediaTicketsInstaller.ocx -> Dropper.PurityScan.ae : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\pre.exe -> Hijacker.VB.lb : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\USDR6_0001_D08M0404NetInstaller.exe -> Not-A-Virus.Downloader.Win32.WinFixer.l : Cleaned with backup
C:\WINDOWS\lt.exe -> Downloader.Small.ajc : Cleaned with backup
C:\WINDOWS\MirarSetup_876075.exe -> Adware.SaveNow : Cleaned with backup
C:\WINDOWS\mtuninst.exe -> Adware.MediaTickets : Cleaned with backup
C:\WINDOWS\offun.exe -> Downloader.VB.nw : Cleaned with backup
C:\WINDOWS\ogosgwwsw.dll -> Downloader.Small.ajc : Cleaned with backup
C:\WINDOWS\optimize.exe -> Downloader.Dyfuca.ey : Cleaned with backup
C:\WINDOWS\srvpystwnv.exe -> Downloader.Dyfuca.ey : Cleaned with backup
C:\WINDOWS\sys012219097661.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\sys022190976612.exe -> Downloader.VB.tw : Cleaned with backup
C:\WINDOWS\SYSC00.exe -> Trojan.VB.tg : Cleaned with backup
:mozilla.21:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.22:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Zedo : Cleaned with backup
:mozilla.27:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.28:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Goclick : Cleaned with backup
:mozilla.49:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.50:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.51:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.52:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.58:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tacoda : Cleaned with backup
:mozilla.63:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.64:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.68:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.69:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.70:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Reliablestats : Cleaned with backup
:mozilla.79:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.80:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
:mozilla.81:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Adrevolver : Cleaned with backup
-> : Error during cleaning
:mozilla.87:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Tracking101 : Cleaned with backup
:mozilla.88:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.89:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.90:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
:mozilla.91:C:\WINDOWS\system32\config\systemprofile\Application Data\Mozilla\Firefox\Profiles\1ixafitq.default\cookies.txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Application Data\Τasks\nѕlookup.exe -> Adware.ClickSpring : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@aavalue[2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@admarketplace[2].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@admarketplace[3].txt -> TrackingCookie.Admarketplace : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@adrevolver[1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][3].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][3].txt -> TrackingCookie.Enhance : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][3].txt -> TrackingCookie.Goclick : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@clickbank[1].txt -> TrackingCookie.Clickbank : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[2].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@cpvfeed[3].txt -> TrackingCookie.Cpvfeed : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kmpads[2].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@kmpads[3].txt -> TrackingCookie.Kmpads : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Tracking101 : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Adrevolver : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Top-banners : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Aavalue : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@searchingbooth[1].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@searchingbooth[2].txt -> TrackingCookie.Searchingbooth : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@starware[3].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Reliablestats : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[1].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[2].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@tacoda[3].txt -> TrackingCookie.Tacoda : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][1].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\[email protected][2].txt -> TrackingCookie.Starware : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-stat[1].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@web-stat[2].txt -> TrackingCookie.Web-stat : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Cookies\owner@zedo[1].txt -> TrackingCookie.Zedo : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Desktop\TagASaurus.exe -> Hijacker.Small : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\!update.exe -> Downloader.PurityScan.da : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\ac2_0004.exe -> Downloader.Small.cpu : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\B8EA4.tmp/cvn0.exe -> Adware.SearchAssistant : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\B8EA4.tmp/wfxqhv.exe -> Adware.Suggestor : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\B8EA4.tmp/zqskw.exe -> Adware.Suggestor : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\BundleInstaller.exe -> Trojan.LdPinch.atp : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\da1F8.tmp -> Adware.SurfSide : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\drsmartload180a.exe -> Downloader.Pakes : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\GLB227.tmp/empty_00000001 -> Adware.Ucmore : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\mmxsnet.exe -> Adware.MediaMotor : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file0.dat -> Adware.Tbh : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file11.dat -> Adware.Tencent : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temp\~DF21.exe/file9.dat -> Adware.Tencent : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\UFMWJ5KZ\popup[1].php -> Hijacker.Agent.a : Cleaned with backup
C:\WINDOWS\system32\config\systemprofile\My Documents\sуmbols\tracert.exe -> Downloader.PurityScan.da : Cleaned with backup
C:\WINDOWS\System32bez6n4r21.exe -> Adware.SearchAssistant : Cleaned with backup
C:\WINDOWS\System32fufudc.exe -> Adware.SearchAssistant : Cleaned with backup
C:\WINDOWS\System32ha3f.exe -> Trojan.Runner.j : Cleaned with backup
C:\WINDOWS\System32n9nyb.exe -> Adware.Suggestor : Cleaned with backup
C:\WINDOWS\System32ra8pv.exe -> Adware.SearchAssistant : Cleaned with backup
C:\WINDOWS\TMS002.exe -> Adware.Exfol : Cleaned with backup
C:\WINDOWS\TMS008.exe -> Adware.Exfol : Cleaned with backup
C:\WINDOWS\TMS009.exe -> Adware.Exfol : Cleaned with backup
C:\WINDOWS\unwn.exe -> Trojan.Qoologic : Cleaned with backup


::Report End

i thought i posted the uninst manager but i guess the post was too long again...-.-

Adobe Flash Player 9 ActiveX
Adobe Reader 6.0
ArcSoft ShowBiz 2
ATI Control Panel
ATI Display Driver
Blackhawk Striker from Hewlett-Packard Desktops (remove only)
Blasterball 2 from Hewlett-Packard Desktops (remove only)
Bounce Symphony from Hewlett-Packard Desktops (remove only)
CC_ccStart
ccCommon
Easy Internet Sign-up
Excavation from Hewlett-Packard Desktops (remove only)
Five Card Frenzy from Hewlett-Packard Desktops (remove only)
GameSpy Arcade
Google Desktop
Google Toolbar for Internet Explorer
HijackThis 1.99.1
HP Deskjet Preloaded Printer Drivers
HP Instant Support
HP Organize
HP Photo & Imaging 3.1
HP Photo and Imaging 2.0 - Photosmart Cameras
HP PSC & OfficeJet 3.0
HP Software Update
HPIZ311
Intel® Extreme Graphics Driver
IntelliComplete (remove only)
IntelliMover Data Transfer Demo
Internet Explorer Q828750
Internet Explorer Security Plugin 2006
Internet Security Add-On
InterVideo WinDVD Player
IrfanView (remove only)
iTunes
J2SE Runtime Environment 5.0 Update 8
Java 2 Runtime Environment, SE v1.4.2
JpegSizer 5.3e
KBD
LimeWire 4.12.6
LiveReg (Symantec Corporation)
LiveUpdate 1.90 (Symantec Corporation)
Memories Disc Creator 2.0
Microsoft .NET Framework 1.1
Microsoft Halo
Microsoft Money 2004
Microsoft Money 2004 System Pack
Microsoft Office 2000 Small Business
Microsoft Office Standard Edition 2003
Microsoft Plus! Digital Media Edition
Microsoft Works 7.0
MSRedist
MSXML 4.0 SP2 Parser and SDK
Multimedia Card Reader
MUSICMATCH? Jukebox
My Web Search (Smiley Central)
Norton AntiVirus 2004
Norton AntiVirus 2004 (Symantec Corporation)
Norton AntiVirus Parent MSI
NVIDIA GART Driver
Orbital from Hewlett-Packard Desktops (remove only)
Otto from Hewlett-Packard Desktops (remove only)
Outlook Express Update Q330994
Overball from Hewlett-Packard Desktops (remove only)
PC-Doctor for Windows
Photosmart 140,240,7200,7600,7700,7900 Series
Polar Bowler from Hewlett-Packard Desktops (remove only)
PS2
Public Messenger ver 2.03
Python 2.2 combined Win32 extensions
Python 2.2.1
Quicken 2004
QuickTime
RealOne Player
RecordNow!
Safety Alerter 2006
Screensavers Installer Version 2
Slide
Slyder from Hewlett-Packard Desktops (remove only)
Sonic Update Manager
SpamSubtract
Starware316 4.4.1.0
strCodec 8.0
SymNet
TEC
toolkit
Updates from HP
WildTangent GameChannel (remove only)
WildTangent Updater
WildTangent Web Driver
Windows XP Hotfix - KB821557
Windows XP Hotfix - KB823559
Windows XP Hotfix - KB824146
Windows XP Hotfix - KB828028
Windows XP Hotfix (SP2) [See Q329115 for more information]
Windows XP Hotfix (SP2) [See q329256 for more information]
Windows XP Hotfix (SP2) [See Q329390 for more information]
Windows XP Hotfix (SP2) [See Q329834 for more information]
Windows XP Hotfix (SP2) Q327979
Windows XP Hotfix (SP2) Q328310
Windows XP Hotfix (SP2) Q329112
Windows XP Hotfix (SP2) Q329170
Windows XP Hotfix (SP2) Q329909
Windows XP Hotfix (SP2) Q331953
Windows XP Hotfix (SP2) Q331958
Windows XP Hotfix (SP2) Q810565
Windows XP Hotfix (SP2) Q810577
Windows XP Hotfix (SP2) Q810833
Windows XP Hotfix (SP2) Q811789
Windows XP Hotfix (SP2) Q814033
Windows XP Hotfix (SP2) Q814995
Windows XP Hotfix (SP2) Q815485
Windows XP Hotfix (SP2) Q817287
Windows XP Hotfix (SP2) Q817606
Zone Deluxe Games
  • 0

#14
Noviciate

Noviciate

    Confused Helper

  • Malware Removal
  • 1,567 posts
You will need to make a copy of these instructions because you have to disconnect from the internet to complete the fix. Either print them out or copy and paste them into Notepad.

Preparation

1) Log off from the internet and disconnect your modem cable for the duration of the fix.

Removal

1) Go to Start > Control Panel > Add/Remove Programs and remove the following, and then reboot your PC:

My Web Search (Smiley Central)

2) Run HijackThis as you did to generate a log, but this time click on 'Do a system scan only'.
Place a checkmark in the boxes to the left of the following entries, by clicking on them:

R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: (no name) - - (no file)

O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: (no name) - {45A4902E-4479-4EAE-A186-8D0F7E4C78DE} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)
O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

O3 - Toolbar: Starware316 - {9FB3908C-6565-4CB0-95F8-E9F85258723C} - C:\Program Files\Starware316\bin\Starware316.dll (file missing)

O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
O4 - HKLM\..\Run: [My Web Search Bar] rundll32 C:\PROGRA~1\MYWEBS~1\bar\1.bin\MWSBAR.DLL,S
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe


CLOSE ALL OPEN WINDOWS AND BROWSERS - EXCEPT HJT and click on Fix checked

3) Remove any/all of the following files/folders that you can find:

Folders

C:\Program Files\MyWebSearch
C:\Program Files\Starware316


As an example:
To delete C:\WINDOWS\system32\foldertogo
Double click the My Computer icon on your Desktop.
Double click on Local Disc (C:)
Double click on the Windows folder,
Double click on the System 32 folder,
Right click on foldertogo and from the menu that appears, click on 'Delete'


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

It is unclear from your log whether or not you have a firewall installed - this could leave your PC at increased risk of infection. If you have one running, please ignore this. If it is disabled, please re-enable it.

If you don't have one, there are a couple of free firewalls available.
Zone Alarm: Available here.
Kerio: Available here.

It is important to note that you should only have one firewall installed at a time, but you can download both to your Desktop and install each in turn to see which one you prefer.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Your version of Adobe Reader is out of date which can present a security risk to your PC. You can get the latest versiob from here.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

As long as the above goes OK, I want you to run your PC as normal for a few days. When you are happy that everything is fine, do the following:

Update your anti-virus program,
Disable System Restore,
Boot into Safe Mode,
Scan your computer for viruses.
When you get the all clear, reboot into Normal Mode.
Re-enable System Restore,
Create a Restore Point.
This will give a clean Restore Point should you need it in the future.
A tutorial for System Restore is available here.

The reason for waiting is that if removing the malware has caused a problem, which it occasionally does, you can put your PC back to how it was before the fix. This will re-install the malware, but an infected PC is better than an expensive paperweight!

Some bedtime reading: This is a very good tutorial about keeping your computer safe and secure on the internet.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP