Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

2005/06/11 Neznarf Hijack Log [RESOLVED]


  • This topic is locked This topic is locked

#1
neznarf

neznarf

    Member

  • Member
  • PipPip
  • 26 posts
:tazz: I am also joining the Geek university today so I can help others in the future. Thank you in advance for helping me. I have ran ad aware, spybot, win registry repair pro, cws shredder, and a file clean up program. I believe I have successfully removed cws because shredder came up with nothing. I am still running my infected computer in safe mode, I am afraid if I start in regular mode the files will duplicate themselves again. When I did start in reg mode, exe programs would just keep starting up and running until my computer would shut down do to over exertion. Here is my file. Direct question can be asked at REMOVED EMAIL. Thank you, Jim Franzen Houston Texas.

Logfile of HijackThis v1.99.1
Scan saved at 7:52:16 AM, on 6/11/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\mmvzlb.exe
C:\Program Files\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://red.clientapp...://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [mrmxgoho] C:\WINDOWS\System32\laijdifa\mrmxgoho.exe
O4 - HKLM\..\Run: [xvrsqp] C:\WINDOWS\System32\xkogka\xvrsqp.exe
O4 - HKLM\..\Run: [mfasfola] C:\WINDOWS\System32\ggaeo\mfasfola.exe
O4 - HKLM\..\Run: [kshntklm] C:\WINDOWS\System32\ahibvp\kshntklm.exe
O4 - HKLM\..\Run: [chyr] C:\WINDOWS\System32\lujxuw\chyr.exe
O4 - HKLM\..\Run: [eetsprtc] C:\WINDOWS\System32\jxfcplpv\eetsprtc.exe
O4 - HKLM\..\Run: [hcaqypn] C:\WINDOWS\System32\xeokkmsu\hcaqypn.exe
O4 - HKLM\..\Run: [roce] C:\WINDOWS\System32\ojfrhdhh\roce.exe
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\System32\sdsyi\ftexc.exe
O4 - HKLM\..\Run: [dqqcit] C:\WINDOWS\System32\cljyy\dqqcit.exe
O4 - HKLM\..\Run: [aurvwfi] C:\WINDOWS\System32\dalnx\aurvwfi.exe
O4 - HKLM\..\Run: [rcrtd] C:\WINDOWS\System32\ciyr\rcrtd.exe
O4 - HKLM\..\Run: [ucbkmji] C:\WINDOWS\System32\uuhi\ucbkmji.exe
O4 - HKLM\..\Run: [gsynpsb] C:\WINDOWS\System32\yqiodvfk\gsynpsb.exe
O4 - HKLM\..\Run: [gaekqd] C:\WINDOWS\System32\mnwx\gaekqd.exe
O4 - HKLM\..\Run: [dksph] C:\WINDOWS\System32\btvgi\dksph.exe
O4 - HKLM\..\Run: [jmgfw] C:\WINDOWS\System32\byaikev\jmgfw.exe
O4 - HKLM\..\Run: [ujwli] C:\WINDOWS\System32\akcxd\ujwli.exe
O4 - HKLM\..\Run: [jrxmjpfg] C:\WINDOWS\System32\surf\jrxmjpfg.exe
O4 - HKLM\..\Run: [armtfk] C:\WINDOWS\System32\kxqbop\armtfk.exe
O4 - HKLM\..\Run: [tmgcsetg] C:\WINDOWS\System32\xjjuoiur\tmgcsetg.exe
O4 - HKLM\..\Run: [pfsx] C:\WINDOWS\System32\croambir\pfsx.exe
O4 - HKLM\..\Run: [fpgfl] C:\WINDOWS\System32\vledwh\fpgfl.exe
O4 - HKLM\..\Run: [lcqlhun] C:\WINDOWS\System32\qiyqwj\lcqlhun.exe
O4 - HKLM\..\Run: [svuqvuff] C:\WINDOWS\System32\fbygvr\svuqvuff.exe
O4 - HKLM\..\Run: [dgfqnj] C:\WINDOWS\System32\snmcvst\dgfqnj.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitemld32.exe
O4 - HKLM\..\Run: [EUIIDLL] C:\WINDOWS\EUIIDLL.EXE
O4 - HKLM\..\Run: [RCBLENC] C:\WINDOWS\RCBLENC.EXE
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [itkidi] c:\windows\system32\mmvzlb.exe
O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe" /autocheck
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O23 - Service: ackbdjpykc - Unknown owner - C:\WINDOWS\System32\jpykc\ackbd.exe
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: cembsjuuqktt - Unknown owner - C:\WINDOWS\System32\juuqktt\cembs.exe
O23 - Service: csjfivvoeirigmsn - Unknown owner - C:\WINDOWS\System32\eirigmsn\csjfivvo.exe
O23 - Service: dslqtxvjifvl - Unknown owner - C:\WINDOWS\System32\txvjifvl\dslq.exe
O23 - Service: fwfikoqetgeq - Unknown owner - C:\WINDOWS\System32\tgeq\fwfikoqe.exe
O23 - Service: greenstdSystem32 - Unknown owner - C:\WINDOWS\System32\greenstd.exe (file missing)
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: ivjfqkglekirn - Unknown owner - C:\WINDOWS\System32\kglekirn\ivjfq.exe
O23 - Service: kshntklmahibvp - Unknown owner - C:\WINDOWS\System32\ahibvp\kshntklm.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: pfsxcroambir - Unknown owner - C:\WINDOWS\System32\croambir\pfsx.exe
O23 - Service: rnjsmgpvaanib - Unknown owner - C:\WINDOWS\System32\pvaanib\rnjsmg.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe (file missing)
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
O23 - Service: xhllhtqxhy - Unknown owner - C:\WINDOWS\System32\tqxhy\xhllh.exe

Edited by Excal, 20 July 2005 - 09:32 PM.

  • 0

Advertisements


#2
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Hi Jim and welcome to GeeksToGo! My name is Excal and I will be helping you.

I can see that you have some malware issues. This maybe a few step process in removing it. I encourage you to stick with it and follow my directions as closely as possible so as to avoid complicating the problem further.

You have quite the little collection of assorted malware :tazz:

Hopefully you can download some programs with out having to come out of safemode, or do you have another computer where you can put the file on a disc/CD?

Please download and install these programs - don't run them yet!!

Please download and unzip
About:Buster to a folder. Inside the folder is a readme file that has instructions on the use of the program.
AboutBuster MUST be updated before you use it.
Start AboutBuster, click the update button, check for updates. Please don't run it yet.

Please download and install AD-Aware.
Check Here on how setup and use it - please make sure you update it first.

Download and unzip cwsserviceremove to your desktop. use either link below:
Site 1
Site 2
Site 3

Download and install CleanUp! Here*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.

Download CWShredder here to its own folder.

Update CWShredder
  • Open CWShredder and click I AGREE
  • Click Check For Update
  • Close CWShredder
We will be using this program later.

Download the Host Here
Please do not use program yet

Download LQfix Here
save it to your desktop, please do not use yet

Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

1. Click this link to be sure you can view hidden files.

2. Ensure you are NOT connected to the internet.

3. Open up the Host program.
  • Make sure that the "make hosts writable?" button in the upper right corner is enabled.
  • Click back up Host files
  • then click Restore orginal host files
  • close program
4. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

5. Go to Start->Run and type in services.msc and hit OK. Then look for ackbdjpykc - Unknown owner and double click on it. Click on the Stop button and under Startup type, choose Disabled.

Do the same with the following services:

cembsjuuqktt - Unknown owner
csjfivvoeirigmsn - Unknown owner
dslqtxvjifvl - Unknown owner
fwfikoqetgeq - Unknown owner
greenstdSystem32 - Unknown owner
ivjfqkglekirn - Unknown owner
kshntklmahibvp - Unknown owner
pfsxcroambir - Unknown owner
rnjsmgpvaanib - Unknown owner
System Startup Service (SvcProc)
WebSeach Toolbar support NT service
WinTools for IE service (WinToolsSvc)
xhllhtqxhy - Unknown owner


6. Close all browsers, windows and unneeded programs.

7. Open HiJack and do a scan.

8. Put a Check next to the following items:

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://red.clientapp...://my.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [mrmxgoho] C:\WINDOWS\System32\laijdifa\mrmxgoho.exe
O4 - HKLM\..\Run: [xvrsqp] C:\WINDOWS\System32\xkogka\xvrsqp.exe
O4 - HKLM\..\Run: [mfasfola] C:\WINDOWS\System32\ggaeo\mfasfola.exe
O4 - HKLM\..\Run: [kshntklm] C:\WINDOWS\System32\ahibvp\kshntklm.exe
O4 - HKLM\..\Run: [chyr] C:\WINDOWS\System32\lujxuw\chyr.exe
O4 - HKLM\..\Run: [eetsprtc] C:\WINDOWS\System32\jxfcplpv\eetsprtc.exe
O4 - HKLM\..\Run: [hcaqypn] C:\WINDOWS\System32\xeokkmsu\hcaqypn.exe
O4 - HKLM\..\Run: [roce] C:\WINDOWS\System32\ojfrhdhh\roce.exe
O4 - HKLM\..\Run: [ftexc] C:\WINDOWS\System32\sdsyi\ftexc.exe
O4 - HKLM\..\Run: [dqqcit] C:\WINDOWS\System32\cljyy\dqqcit.exe
O4 - HKLM\..\Run: [aurvwfi] C:\WINDOWS\System32\dalnx\aurvwfi.exe
O4 - HKLM\..\Run: [rcrtd] C:\WINDOWS\System32\ciyr\rcrtd.exe
O4 - HKLM\..\Run: [ucbkmji] C:\WINDOWS\System32\uuhi\ucbkmji.exe
O4 - HKLM\..\Run: [gsynpsb] C:\WINDOWS\System32\yqiodvfk\gsynpsb.exe
O4 - HKLM\..\Run: [gaekqd] C:\WINDOWS\System32\mnwx\gaekqd.exe
O4 - HKLM\..\Run: [dksph] C:\WINDOWS\System32\btvgi\dksph.exe
O4 - HKLM\..\Run: [jmgfw] C:\WINDOWS\System32\byaikev\jmgfw.exe
O4 - HKLM\..\Run: [ujwli] C:\WINDOWS\System32\akcxd\ujwli.exe
O4 - HKLM\..\Run: [jrxmjpfg] C:\WINDOWS\System32\surf\jrxmjpfg.exe
O4 - HKLM\..\Run: [armtfk] C:\WINDOWS\System32\kxqbop\armtfk.exe
O4 - HKLM\..\Run: [tmgcsetg] C:\WINDOWS\System32\xjjuoiur\tmgcsetg.exe
O4 - HKLM\..\Run: [pfsx] C:\WINDOWS\System32\croambir\pfsx.exe
O4 - HKLM\..\Run: [fpgfl] C:\WINDOWS\System32\vledwh\fpgfl.exe
O4 - HKLM\..\Run: [lcqlhun] C:\WINDOWS\System32\qiyqwj\lcqlhun.exe
O4 - HKLM\..\Run: [svuqvuff] C:\WINDOWS\System32\fbygvr\svuqvuff.exe
O4 - HKLM\..\Run: [dgfqnj] C:\WINDOWS\System32\snmcvst\dgfqnj.exe
O4 - HKLM\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - HKLM\..\Run: [etbrun] C:\windows\system32\elitemld32.exe
O4 - HKLM\..\Run: [EUIIDLL] C:\WINDOWS\EUIIDLL.EXE
O4 - HKLM\..\Run: [RCBLENC] C:\WINDOWS\RCBLENC.EXE
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [itkidi] c:\windows\system32\mmvzlb.exe
O23 - Service: ackbdjpykc - Unknown owner - C:\WINDOWS\System32\jpykc\ackbd.exe
O23 - Service: cembsjuuqktt - Unknown owner - C:\WINDOWS\System32\juuqktt\cembs.exe
O23 - Service: csjfivvoeirigmsn - Unknown owner - C:\WINDOWS\System32\eirigmsn\csjfivvo.exe
O23 - Service: dslqtxvjifvl - Unknown owner - C:\WINDOWS\System32\txvjifvl\dslq.exe
O23 - Service: fwfikoqetgeq - Unknown owner - C:\WINDOWS\System32\tgeq\fwfikoqe.exe
O23 - Service: greenstdSystem32 - Unknown owner - C:\WINDOWS\System32\greenstd.exe (file missing)
O23 - Service: ivjfqkglekirn - Unknown owner - C:\WINDOWS\System32\kglekirn\ivjfq.exe
O23 - Service: kshntklmahibvp - Unknown owner - C:\WINDOWS\System32\ahibvp\kshntklm.exe
O23 - Service: pfsxcroambir - Unknown owner - C:\WINDOWS\System32\croambir\pfsx.exe
O23 - Service: rnjsmgpvaanib - Unknown owner - C:\WINDOWS\System32\pvaanib\rnjsmg.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: WebSeach Toolbar support NT service (TBPSSvc) - Unknown owner - C:\PROGRA~1\Toolbar\TBPSSvc.exe (file missing)
O23 - Service: WinTools for IE service (WinToolsSvc) - Unknown owner - C:\Program Files\Common Files\WinTools\WToolsS.exe (file missing)
O23 - Service: xhllhtqxhy - Unknown owner - C:\WINDOWS\System32\tqxhy\xhllh.exe


9. click the Fix Checked box

10. Please remove these entries from Add/Remove Programs in the Control Panel(if present):

WinTools
TBPSSvc or Huntbar
SurfSidekick
Media Access


11. Please remove the following folders using Windows Explorer (if present):

C:\WINDOWS\System32\laijdifa
C:\WINDOWS\System32\xkogka
C:\WINDOWS\System32\ggaeo
C:\WINDOWS\System32\ahibvp
C:\WINDOWS\System32\lujxuw
C:\WINDOWS\System32\jxfcplpv
C:\WINDOWS\System32\xeokkmsu
C:\WINDOWS\System32\ojfrhdhh
C:\WINDOWS\System32\sdsyi
C:\WINDOWS\System32\cljyy
C:\WINDOWS\System32\dalnx
C:\WINDOWS\System32\ciyr
C:\WINDOWS\System32\uuhi
C:\WINDOWS\System32\yqiodvfk
C:\WINDOWS\System32\mnwx
C:\WINDOWS\System32\btvgi
C:\WINDOWS\System32\byaikev
C:\WINDOWS\System32\akcxd
C:\WINDOWS\System32\surf
C:\WINDOWS\System32\kxqbop
C:\WINDOWS\System32\xjjuoiur
C:\WINDOWS\System32\croambir
C:\WINDOWS\System32\vledwh
C:\WINDOWS\System32\qiyqwj
C:\WINDOWS\System32\fbygvr
C:\WINDOWS\System32\snmcvst
C:\Program Files\SurfSideKick 3
C:\Program Files\Media Access
C:\WINDOWS\System32\jpykc
C:\WINDOWS\System32\juuqktt
C:\WINDOWS\System32\eirigmsn
C:\WINDOWS\System32\txvjifvl
C:\WINDOWS\System32\tgeq
C:\WINDOWS\System32\kglekirn
C:\WINDOWS\System32\ahibvp
C:\WINDOWS\System32\croambir
C:\WINDOWS\System32\pvaanib
C:\PROGRA~1\Toolbar
C:\Program Files\Common Files\WinTools
C:\WINDOWS\System32\tqxhy


12. Please remove just the files from the following paths using Windows Explorer (if present):

C:\WINDOWS\EUIIDLL.EXE
C:\WINDOWS\RCBLENC.EXE
c:\windows\system32\mmvzlb.exe
C:\WINDOWS\System32\greenstd.exe
C:\WINDOWS\svcproc.exe


13. Please run about:buster by RubbeRDuckY:
  • Click Begin Removal.
  • It will begin to check your computer for malicious files.
  • AboutBuster will finish and open a new page. Follow the instructions for protection on that page.
  • Shut down AboutBuster. A log should have been created.Please Save this log and copy it in your next post.
14. Double click on LQFix program u downloaded.
A doswindow will open and close again, this is normal.

15. Scan with AdAware and let it remove any bad files found.

16. Run the program CleanUp! (do not reboot yet)

17. Double click on the cwsserviceremove and when asked to merge say yes.

18. Now run CWShredder. Click I Agree, then Fix and then Next, let it fix everything it asks about. Reboot your computer into normal windows.

19. Reboot into normal mode and please run this online virus scan: ActiveScan - Save the results from the scan!

20. Please post an Active scan log and a fresh HiJackThis log. Let me know how your computer is running.
  • 0

#3
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
K, did all that. When I fired the system back up I had some Aurora windows pop up. :tazz: I tried to run the on line virus scan but the system froze. ;) So I don't have that log. I re booted into safe mode and did a new hijack log. ;)

Logfile of HijackThis v1.99.1
Scan saved at 10:58:36 AM, on 6/24/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.exe
c:\windows\system32\nxacair.exe
C:\Program Files\hijackthis\HijackThis.exe

O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [cembs] C:\WINDOWS\System32\juuqktt\cembs.exe
O4 - HKLM\..\Run: [dslq] C:\WINDOWS\System32\txvjifvl\dslq.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\enjdci.exe
O4 - HKLM\..\Run: [odmelib] C:\WINDOWS\System32\dpdswray\odmelib.exe
O4 - HKLM\..\Run: [mitnoge] c:\windows\system32\nxacair.exe
O4 - HKCU\..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Program Files\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe

Thank you.
  • 0

#4
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Can you please give me a HJT from normal mode.


Thanks,

:tazz:

Excal
  • 0

#5
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :tazz:

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

#6
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Here is my normal mode HJT log

Logfile of HijackThis v1.99.1
Scan saved at 10:05:00 PM, on 7/20/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\qttask.exe
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\enjdci.exe
c:\windows\system32\duralpn.exe
C:\WINDOWS\System32\caseview.EXE
C:\Program Files\Palm\HOTSYNC.EXE
C:\WINDOWS\System32\lawfld32.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [cembs] C:\WINDOWS\System32\juuqktt\cembs.exe
O4 - HKLM\..\Run: [dslq] C:\WINDOWS\System32\txvjifvl\dslq.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\enjdci.exe
O4 - HKLM\..\Run: [odmelib] C:\WINDOWS\System32\dpdswray\odmelib.exe
O4 - HKLM\..\Run: [jjfgmjti] C:\WINDOWS\System32\mwhyyhxp\jjfgmjti.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [riikgbk] c:\windows\system32\duralpn.exe
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [caseview] C:\WINDOWS\System32\caseview.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
  • 0

#7
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
hi neznarf,

Make sure you stick with this through the whole fix until we are assured that you are all cleaned up. Thanks :tazz:


DOWNLOAD PROGRAMS


Please download ewido security suite it is a trial version of the program.
  • Install ewido security suite
  • When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu".
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update ewido.
ewido manual updates Do NOT run a scan yet. (if you already have, please just update)

Download and unzip HSfix to your desktop :
HSRegFix

Please download Nailfix from Here
click nailfix.exe and choose install, a new folder will be created on your desktop named nailfix
please do NOT run it yet.

Download and install CleanUp! Here*NOTE* Cleanup deletes EVERYTHING out of temp/temporary folders and does not make backups.
We will use this program later.


THE FIX


Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

1. Click this link to be sure you can view hidden files.

2. Ensure you are NOT connected to the internet.

3. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

4. Go to Start->Run and type in services.msc and hit OK. Then look for System Startup Service (SvcProc) and double click on it. Click on the Stop button and under Startup type, choose Disabled. (if present)

5. Go into Hijack This->Config->Misc. Tools->Open process manager. Select the following and click “Kill process” for each one (If they still exist)

C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\enjdci.exe
c:\windows\system32\duralpn.exe
C:\WINDOWS\System32\caseview.EXE
C:\WINDOWS\System32\lawfld32.EXE


6. Once in Safe Mode, please double-click on
Nailfix.cmd Your desktop and icons will disappear and reappear, and a window should open and close very quickly --- this is normal.

7. Now open and run Ewido:
  • Click on scanner
  • Click Complete System Scan and the scan will begin.
  • During the scan when it ask if you want to clean the first file, put a check in the lower left corner of the box that says "Perform action on all infections" then choose clean and click OK
  • When the scan is finished, look at the bottom of the screen and click the Save report button.
  • Save the report to your desktop
Close Ewido

8. Close all browsers, windows and unneeded programs.

9. Open HiJack and do a scan.

10. Put a Check next to the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://websearch.drs...esearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
O2 - BHO: Band Class - {01F44A8A-8C97-4325-A378-76E68DC4AB2E} - C:\WINDOWS\systb.dll
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O4 - HKLM\..\Run: [cembs] C:\WINDOWS\System32\juuqktt\cembs.exe
O4 - HKLM\..\Run: [dslq] C:\WINDOWS\System32\txvjifvl\dslq.exe
O4 - HKLM\..\Run: [version] C:\WINDOWS\System32\enjdci.exe
O4 - HKLM\..\Run: [odmelib] C:\WINDOWS\System32\dpdswray\odmelib.exe
O4 - HKLM\..\Run: [jjfgmjti] C:\WINDOWS\System32\mwhyyhxp\jjfgmjti.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [riikgbk] c:\windows\system32\duralpn.exe
O4 - HKCU\..\Run: [caseview] C:\WINDOWS\System32\caseview.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - c:\windows\SvcProc.exe


11. click the Fix Checked box

12. Please remove these entries from Add/Remove Programs in the Control Panel(if present):

SurfSideKick 3
caseview


13. Please remove the following folders using Windows Explorer (if present):

C:\Program Files\SurfSideKick 3
C:\WINDOWS\System32\juuqktt
C:\WINDOWS\System32\txvjifvl
C:\WINDOWS\System32\dpdswray
C:\WINDOWS\System32\mwhyyhxp


14. Please remove just the files from the following paths using Windows Explorer (if present):

C:\WINDOWS\systb.dll
C:\WINDOWS\System32\wintask.exe
C:\WINDOWS\System32\enjdci.exe
c:\windows\system32\duralpn.exe
C:\WINDOWS\System32\caseview.EXE
C:\WINDOWS\System32\lawfld32.EXE
C:\WINDOWS\wupdt.exe
c:\windows\SvcProc.exe


15. Double click on the HSFix and when asked to merge say yes.

16. Run the program CleanUp!

17. Reboot into normal mode and please run this online virus scan: ActiveScan - Save the results from the scan!

18. Please post an Active scan log , Ewido Scan log and a fresh HiJackThis log. Let me know how your computer is running.

Edited by Excal, 20 July 2005 - 09:34 PM.

  • 0

#8
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
When computer starts up the icon take a long time to appear. I tried to run the panda software online scan numerous times and my computer keeps freezing. here are new HTJT log and the Ewido scan log. Aurora did not apear this time, I am able to go to web sites without pop ups.

Logfile of HijackThis v1.99.1
Scan saved at 11:05:38 PM, on 7/31/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\cidaemon.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drs...esearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Program Files\SurfSideKick 3\SskBho.dll (file missing)
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [Dinst] C:\WINDOWS\dinst.exe
O4 - HKLM\..\Run: [xnxqhto] c:\windows\system32\lvknee.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [caseview] C:\WINDOWS\System32\caseview.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe


EWIDO

---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 7:33:53 PM, 7/31/2005
+ Report-Checksum: 2C452C43

+ Scan result:

HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{0818D423-6247-11D1-ABEE-00D049C10000} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{016235BE-59D4-4CEB-ADD5-E2378282A1D9} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0A1D22C3-37BE-470C-9C29-E3074EE0574B} -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{2C4E6D22-B71F-491F-AAD3-B6972A650D50} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{825CF5BD-8862-4430-B771-0C15C5CA8DEF} -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A166C1B0-5CDB-447A-894A-4B9FD7149D51} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{B5AB638F-D76C-415B-A8F2-F3CEAC502212} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BE8D0059-D24D-4919-B76F-99F4A2203647} -> Spyware.EliteBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FB45C451-B0E9-4407-BB6A-9361013F3E9A} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.BottomFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.LeftFrame\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupBrowser\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\IMIToolbar.PopupWindow\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{370F6327-41C4-4FA6-A2DF-1BA57EE0FBB9} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{94984402-B480-45C7-AD2D-84E5EB52CFCD} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B548B7D8-3D03-4AED-A6A1-4251FAD00C10} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{B99A727F-0782-4A71-BCC2-6E1E66414904} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{BC333116-6EA1-40A1-9D07-ECB192DB8CEA} -> Spyware.AproposMedia : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C08175C6-B2B2-47FC-AF1A-32F77A6CB673} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C380566D-F343-42AB-987B-6B38A1A35747} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{EFA52460-8822-4191-BA38-FACDD2007910} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\Radio.RadioPlayer -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Radio.RadioPlayer\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{09049E4F-8D9E-4C8A-A952-5BAF1A115C59} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{230C3786-1C2C-45BD-9D2D-9D277FCE6289} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{D8BD4DED-5BB2-4D4E-9A6A-F10244FED7D6} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CLSID -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\Classes\Wbho.Band\CurVer -> Spyware.IEPlugin : Cleaned with backup
HKLM\SOFTWARE\dealhelper -> Spyware.DealHelper : Cleaned with backup
HKLM\SOFTWARE\dealhelper\KeyWord -> Spyware.DealHelper : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{50B4D2B3-723F-41B3-AEC4-0BD66F0F45FF} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{A166C1B0-5CDB-447A-894A-4B9FD7149D51} -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\70tovmto -> Spyware.SAHA : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\InternetOffers -> Spyware.LZIO : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinDH -> Spyware.DealHelper : Cleaned with backup
HKLM\SOFTWARE\picsvr -> Spyware.Delfin : Cleaned with backup
HKLM\SOFTWARE\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\APP -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\BBDE -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\BBDHE -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\BBDI -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\COMMON -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\MAJORSE -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\RADIO -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\SVC -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Files\TBR -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Install -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\PlugIns\RADIO -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Apropos -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client\Cookies -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\contextplus -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Spyware.AproposMedia : Cleaned with backup
HKU\.DEFAULT\Software\Bolger -> Spyware.VX2 : Cleaned with backup
HKU\.DEFAULT\Software\DLMax -> Spyware.BetterInternet : Cleaned with backup
HKU\.DEFAULT\Software\drelkge789AEF5 -> Spyware.DesktopTraffic : Cleaned with backup
HKU\.DEFAULT\Software\drelkge789AEF5\ppops -> Spyware.DesktopTraffic : Cleaned with backup
HKU\.DEFAULT\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\PlugIns\RADIO -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\Toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX\HXClient -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX\HXDL -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX\HXIUL -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX\HXIUL\Current -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Alset\HX\HXIUL\Manifest -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client\Cookies -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client\Cookies\Data -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client\Cookies\Data\net -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client\Cookies\Data\net\contextplus -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Avenue Media -> Spyware.InternetOptimizer : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Bundles -> Spyware.SecondThought : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\DLMax -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\LQ -> Dialer.Generic : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Microsoft\Windows\CurrentVersion\Uninstall\HelpExpress -> Spyware.HelpExpress : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\salm -> Spyware.180Solutions : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar\PlugIns\RADIO -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\Toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\WinTools -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-1060284298-1957994488-336697219-1005\Software\WinTools\URLSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Apropos -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client\Cookies -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\contextplus -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Apropos\Client\Cookies\Data\net\contextplus\adchannel.contextplus.net/services/AdChannelServer -> Spyware.AproposMedia : Cleaned with backup
HKU\S-1-5-18\Software\Bolger -> Spyware.VX2 : Cleaned with backup
HKU\S-1-5-18\Software\DLMax -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-18\Software\drelkge789AEF5 -> Spyware.DesktopTraffic : Cleaned with backup
HKU\S-1-5-18\Software\drelkge789AEF5\ppops -> Spyware.DesktopTraffic : Cleaned with backup
HKU\S-1-5-18\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\PlugIns -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\PlugIns\COMMON -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\PlugIns\RADIO -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\Server -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\Toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][2].txt -> Spyware.Cookie.Falkag : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][2].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@serving-sys[2].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@tradedoubler[1].txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\chris@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][1].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Chris\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@247realmedia[1].txt -> Spyware.Cookie.247realmedia : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Pointroll : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@burstnet[2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@hitbox[2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@revenue[2].txt -> Spyware.Cookie.Revenue : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\claudine@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Burstnet : Cleaned with backup
C:\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\Documents and Settings\Claudine\Local Settings\Temp\XOJ\aurareco.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][1].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][2].txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][1].txt -> Spyware.Cookie.Addynamix : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@adtrak[1].txt -> Spyware.Cookie.Adtrak : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@casalemedia[1].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@qksrv[2].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\jim@tribalfusion[2].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\Documents and Settings\Jim\Cookies\[email protected][2].txt -> Spyware.Cookie.Adserver : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@2o7[3].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@admonitor[2].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@adorigin[2].txt -> Spyware.Cookie.Adorigin : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@advertising[3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Counted : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@bluemountain[1].txt -> Spyware.Cookie.Bluemountain : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@bluestreak[2].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@fastclick[4].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@fastclick[5].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@gator[1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@hitbox[1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@hitbox[3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@linksynergy[2].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@mediaplex[2].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@questionmarket[3].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@ru4[1].txt -> Spyware.Cookie.Ru4 : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@spinbox[1].txt -> Spyware.Cookie.Spinbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Realtracker : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@track-star[1].txt -> Spyware.Cookie.Track-star : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@trafficmp[1].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@valueclick[1].txt -> Spyware.Cookie.Valueclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Gator : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][3].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][2].txt -> Spyware.Cookie.Myaffiliateprogram : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][1].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\[email protected][3].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\oldhdd\Documents and Settings\Claudine\Cookies\claudine@x10[2].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@admonitor[2].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@advertising[3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@flycast[1].txt -> Spyware.Cookie.Flycast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@focalink[1].txt -> Spyware.Cookie.Focalink : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@linksynergy[1].txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@overture[1].txt -> Spyware.Cookie.Overture : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@preferences[2].txt -> Spyware.Cookie.Preferences : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@questionmarket[2].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@targetnet[1].txt -> Spyware.Cookie.Targetnet : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@tribalfusion[1].txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Commission-junction : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Qksrv : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\anyuser@x10[1].txt -> Spyware.Cookie.X10 : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@2o7[3].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@ad-flow[2].txt -> Spyware.Cookie.Ad-flow : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@admonitor[1].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@admonitor[2].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@admonitor[3].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Ad-flow : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Admonitor : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Enliven : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][3].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][4].txt -> Spyware.Cookie.Link4ads : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Internetfuel : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@advertising[3].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@advertising[5].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@adviva[1].txt -> Spyware.Cookie.Adviva : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@atdmt[3].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@bfast[1].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@bfast[2].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@bfast[3].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@bfast[4].txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@bluestreak[1].txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@centrport[2].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@centrport[3].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@click2net[1].txt -> Spyware.Cookie.Click2net : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@click2net[2].txt -> Spyware.Cookie.Click2net : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@clickagents[1].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@clickagents[3].txt -> Spyware.Cookie.Clickagents : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitslink : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Sextracker : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@doubleclick[1].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@doubleclick[3].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@doubleclick[4].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][2].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][1].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\[email protected][3].txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@engage[1].txt -> Spyware.Cookie.Engage : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@engage[2].txt -> Spyware.Cookie.Engage : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@epilot[1].txt -> Spyware.Cookie.Epilot : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@euniverseads[2].txt -> Spyware.Cookie.Euniverseads : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@excite[2].txt -> Spyware.Cookie.Excite : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[1].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[4].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[5].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[6].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@fastclick[7].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@flycast[1].txt -> Spyware.Cookie.Flycast : Cleaned with backup
C:\oldhdd\Documents and Settings\Default\Cookies\default@flycast[2].txt -> Spyware.Cookie.Flycast : Cleaned with backup
C:\ol
  • 0

#9
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I have tried to run the panda software scan on my documents only and that went through. I am currently running on hard drives and I will post the results when it completes. I was originally trying to run the scans on My Computer, and the scans didn't start and computer would eventually freeze.
  • 0

#10
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
DSRFix by Atribune et al for all OS.

Please print out or copy this page to Notepad . Make sure to work through the steps in the exact order in which they are mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fix.
  • Download DSRFIX from HERE onto your Desktop.
    • Unzip and EXTRACT the files to your Desktop.
    • The program creates and names the new folder to house the files.
    • DO NOT RUN IT YET
  • Download Cleanup from Here (Alternate site if the above is not working Go Here)
    • A window will open and choose SAVE, then DESKTOP as the destination.
    • On your Desktop, click on Cleanup40.exe icon.
    • Then, click RUN and place a checkmark beside "I Agree"
    • Then click NEXT followed by START and OK.
    • A window will appear with many choices, keep all the defaults as set when the Slide Bar to the left is set to Standard Quality.
    • Click OK
    • DO NOT RUN IT YET
  • CLOSE INTERNET EXPLORER, if it is open


  • Open the folder dsrfix
    • Double click on the dsrfix batch file( the one with the little gear in it )
    • Once dsrfix has completed it will close on its own
  • Run Cleanup
    • Click on the "Cleanup" button and let it run.
    • Once its done, close the program.
  • REBOOT your system.


  • Please restart HJT and post back a fresh HJT log for review.

  • 0

Advertisements


#11
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
Did That here is new HJT log

Logfile of HijackThis v1.99.1
Scan saved at 12:53:14 AM, on 8/1/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton Personal Firewall\NISUM.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Norton Personal Firewall\NISSERV.EXE
C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
C:\WINDOWS\System32\cidaemon.exe
C:\WINDOWS\Explorer.exe
C:\Program Files\Adaptec\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\WINDOWS\System32\qttask.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = www.google.com
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [xnxqhto] c:\windows\system32\lvknee.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\ypager.exe" -quiet
O4 - HKCU\..\Run: [caseview] C:\WINDOWS\System32\caseview.EXE
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoft.../as5/asinst.cab
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXE
O23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exe
  • 0

#12
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I forgot to mention that computer froze up again on the hard drive search at the Panda Software site. Also when I log onto the computer the computer tells me the the c:/windows/nail.exe file is missing.
  • 0

#13
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Wow, much better.

Are you familiar with, or did you install this program on your computer?:[caseview] C:\WINDOWS\System32\caseview.EXE


THE FIX


Please read this post completely, it may make it easier for you if you copy and paste this post to a new text document or print it for reference later.

1. Click this link to be sure you can view hidden files.

2. Ensure you are NOT connected to the internet.

3. Reboot into safe mode.

Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.

4. Close all browsers, windows and unneeded programs.

5. Open HiJack and do a scan.

6. Put a Check next to the following items:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://searchmiracle.com/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {00F1D395-4744-40f0-A611-980F61AE2C59} - (no file)
O4 - HKLM\..\Run: [xnxqhto] c:\windows\system32\lvknee.exe
O4 - HKCU\..\Run: [SurfSideKick 3] C:\Program Files\SurfSideKick 3\Ssk.exe


7. click the Fix Checked box

8. Please remove these entries from Add/Remove Programs in the Control Panel(if present):

SurfSideKick 3

9. Please remove the following folders using Windows Explorer (if present):

C:\Program Files\SurfSideKick 3

10. Please remove just the files from the following paths using Windows Explorer (if present):

c:\windows\system32\lvknee.exe

11. Reboot into normal mode and please run this online virus scan: ActiveScan - Save the results from the scan!

12. Download and Run Silentrunners
  • Please click this link to download Silent Runners.
  • Save it to the desktop.
  • Run Silent Runner's by doubleclicking the "Silent Runners" icon on your desktop.
  • You will see a text file appear on the desktop - it's not done yet, just let it run (it won't appear to be doing anything!)
  • Once you receive the prompt "All Done!", double-click on the new text file on the desktop and copy that entire log and paste it here.

  • NOTE* If you receive any warning message about scripts, please choose to allow the script to run.
    For some time it will look like nothing is happening. Just keep waiting.
  • Once it's done it will create a log. A window will come up telling you when it's saved. Please post that log here
13. Please post the Active scan log, Silentrunners log and a fresh HiJackThis log. Let me know how your computer is running.
  • 0

#14
neznarf

neznarf

    Member

  • Topic Starter
  • Member
  • PipPip
  • 26 posts
I have no idea what caseview.exe is. I am doing the Panda Software scan now. If I freeze again during the scan should I proceed with Silent Runners?
  • 0

#15
Excal

Excal

    Malware Slayer Extraordinaire!

  • Retired Staff
  • 12,739 posts
Yes please.


Thanks,

:tazz:

Excal
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP