Thank you tons for re-opening the post. HEre's all of the logs you requested, I am even including the latest hijackthis log as well (...in case it changed at all). I noticed that the system32 folder still pops up at windows startup. I hope we can get this all resolved! Thanks
SPSeHjFix Log:
(7/9/05 1:26:53 AM) SPSeHjFix started v1.1.2
(7/9/05 1:26:53 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/9/05 1:26:53 AM) Language: english
(7/9/05 1:26:53 AM) Win-Path: C:\WINDOWS
(7/9/05 1:26:53 AM) System-Path: C:\WINDOWS\system32
(7/9/05 1:26:53 AM) Temp-Path: C:\DOCUME~1\Whitney\LOCALS~1\Temp\
(7/9/05 4:09:21 AM) SPSeHjFix started v1.1.2
(7/9/05 4:09:21 AM) OS: WinXP Service Pack 2 (5.1.2600)
(7/9/05 4:09:21 AM) Language: english
(7/9/05 4:09:21 AM) Win-Path: C:\WINDOWS
(7/9/05 4:09:21 AM) System-Path: C:\WINDOWS\system32
(7/9/05 4:09:21 AM) Temp-Path: C:\DOCUME~1\Whitney\LOCALS~1\Temp\
(7/9/05 4:09:31 AM) Disinfection started
(7/9/05 4:09:31 AM) Bad-Dll(IEP): (not found)
(7/9/05 4:09:31 AM) Bad-Dll(IEP) in BHO: (not found)
(7/9/05 4:09:31 AM) UBF: 8 - UBB: 3 - UBR: 92
(7/9/05 4:09:31 AM) UBF: 8 - UBB: 3 - UBR: 92
(7/9/05 4:09:31 AM) Bad IE-pages: (none)
(7/9/05 4:09:31 AM) Stealth-String not found
(7/9/05 4:09:31 AM) Not infected->END
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:07:13 AM, 7/9/2005
+ Report-Checksum: 9706AF94
+ Scan result:
HKLM\SOFTWARE\Classes\AdultBar.AdultBar -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar\CLSID -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultBar.AdultBar\CurVer -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch\CLSID -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\AdultSearch.AdultSearch\CurVer -> Spyware.AdultLinks : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3646C2BD-3554-49CA-8125-44DEEFB881DE} -> Spyware.Altnet : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{16097036-894C-4C00-A61F-93CA0D49A70E} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{1740E1C8-2504-4472-A458-4B6C31A26F5E} -> Spyware.EzSearchBar : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{20F36AF3-3486-4BB6-8BCB-F1F8ABE74D07} -> Spyware.NavExcel : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{2ED5AF98-9258-45BA-B79B-06625C92F662} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{700DC0DD-F409-42E0-9DE5-21EE1A2BA9FD} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C91E8926-D4BE-4685-99F4-0D996B96BAC0} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D273D427-57C6-4B12-860F-BBB8195F6E2A} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{FD42F6D3-7AB1-470C-979B-7996EDC99099} -> Spyware.TOPicks : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{F720B40F-3A38-4B22-B30D-DCF095D42498} -> Spyware.P2PNetworking : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{FA4DE133-D3C3-4ED4-92D1-CD4DDE839AB3} -> Spyware.NavExcel : Cleaned with backup
HKU\S-1-5-21-2284095636-2942888322-2251389636-1007\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{C1E58A84-95B3-4630-B8C2-D06B77B7A0FC} -> Spyware.NavExcel : Cleaned with backup
:mozilla.6:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Spylog : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.27:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.28:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.35:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.36:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.37:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.42:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.43:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.46:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.47:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.48:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.50:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.51:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.52:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.53:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.68:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.73:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.79:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.83:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.84:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.88:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.89:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.91:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.108:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.109:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.111:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.116:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.120:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.121:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.122:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.133:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.134:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Qksrv : Cleaned with backup
:mozilla.154:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.155:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.156:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.157:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.158:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.203:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Coremetrics : Cleaned with backup
:mozilla.204:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.214:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.215:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.216:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.217:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.218:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.219:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.220:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.221:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.222:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.223:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.224:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.225:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.227:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.231:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.232:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.233:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.234:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.235:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.236:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.237:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.238:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.239:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.240:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.241:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.242:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.243:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.244:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.245:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.246:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.247:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.248:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.249:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.250:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.251:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.252:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.279:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.280:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.281:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.287:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.289:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.290:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Linksynergy : Cleaned with backup
:mozilla.291:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.295:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Realtracker : Cleaned with backup
:mozilla.341:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.342:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.343:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.344:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.345:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.346:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.414:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.247realmedia : Cleaned with backup
:mozilla.446:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.464:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.465:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.466:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.467:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitslink : Cleaned with backup
:mozilla.518:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.519:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.552:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.568:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.569:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.591:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.592:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.626:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.627:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.628:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.629:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Adorigin : Cleaned with backup
:mozilla.630:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.658:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.661:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.684:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.693:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.694:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.695:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.696:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.697:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.725:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.742:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.774:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.775:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.776:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.777:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.786:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.805:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Ad-logics : Cleaned with backup
:mozilla.818:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.831:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Dbbsrv : Cleaned with backup
:mozilla.868:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.869:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.870:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.872:C:\Documents and Settings\Whitney\Application Data\Mozilla\Firefox\Profiles\au474r7g.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\whitney@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\whitney@advertising[1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\whitney@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\whitney@doubleclick[2].txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\whitney@mediaplex[1].txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
C:\Documents and Settings\Whitney\Cookies\
[email protected][2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\asmfiles.cab/asm.exe -> Spyware.Altnet : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\DrTemp\thin-140-1-x-x.exe -> Adware.BetterInternet : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\msg5.tmp10691932235808.exe -> Heuristic.Win32.Hijacker1 : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\msgB.tmp10693657463153.exe -> TrojanDownloader.IstBar.co : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\msgC.tmp10693657461909.exe -> TrojanDownloader.IstBar.co : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\msgD.tmp10693657475749.exe -> TrojanDownloader.IstBar.co : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\navapp.exe -> Spyware.NavExcel : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\NHelper.dll -> Spyware.NavExcel : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\NHUninstaller.exe -> Spyware.NavExcel : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\v2.0.4d.cab/NHelper.dll -> Spyware.NavExcel : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\v2.0.4d.cab/NHUninstaller.exe -> Spyware.NavExcel : Cleaned with backup
C:\Documents and Settings\Whitney\Local Settings\Temp\temp.fr5A16\NavHelper\v2.0.4d\v2.0.4d.cab/navapp.exe -> Spyware.NavExcel : Cleaned with backup
C:\Program Files\LimeShop\LimeShop.exe -> Spyware.TopMoxie : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\1A546AF5-E082-4BEE-B821-F8CB65\4353A7D8-AB1F-44D5-8E2D-C66A93 -> Spyware.NavExcel : Cleaned with backup
C:\Program Files\Microsoft AntiSpyware\Quarantine\1A546AF5-E082-4BEE-B821-F8CB65\F570100E-E3A5-4B50-A987-BDD89D/NHUpdater.exe -> Spyware.NavExcel : Cleaned with backup
C:\WINDOWS\ccc.exe -> TrojanDownloader.MlFree : Cleaned with backup
C:\WINDOWS\SYSTEM32\ltiwxqso.dll -> Trojan.Golid.b : Cleaned with backup
C:\WINDOWS\SYSTEM32\test3a.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\ttil_sbc.exe -> Adware.eZula : Cleaned with backup
::Report End
********************************************************************
PANDA SCAN LOG
Incident Status Location
Spyware:Spyware/AdClicker No disinfected Windows Registry
Adware:Adware/TalkStocks No disinfected C:\WINDOWS\system32\mstbl.ocx
Adware:Adware/PowerScan No disinfected Windows Registry
Adware:Adware/CWS No disinfected c:\documents and settings\whitney\favorites\Health
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\a.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\LimeShop\System\Code\bf.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\bq.class
Adware:Adware/MoeMoney No disinfected C:\Program Files\LimeShop\System\Code\bs.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dc.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dm.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\du.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\dx.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\i.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\j.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\p.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\q.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\s.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\t.class
Adware:Adware/TopMoxie No disinfected C:\Program Files\LimeShop\System\Code\u.class
Adware:Adware/NavHelper No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1A546AF5-E082-4BEE-B821-F8CB65\3B30285C-D298-4548-9E45-42A49F
Adware:Adware/NavHelper No disinfected C:\Program Files\Microsoft AntiSpyware\Quarantine\1A546AF5-E082-4BEE-B821-F8CB65\6E10E78E-0684-4611-AE42-15F185
Adware:Adware/TalkStocks No disinfected C:\WINDOWS\SYSTEM32\mstbl.ocx
Adware:Adware/P2PNetworking No disinfected C:\WINDOWS\SYSTEM32\P2P Networking v124.cpl
Adware:Adware/Iagold No disinfected C:\WINDOWS\SYSTEM32\rgwhwxfv.dll
Virus:Trj/Downloader.CYQ Disinfected C:\WINDOWS\SYSTEM32\rsd.exe
Adware:Adware/Iagold No disinfected C:\WINDOWS\SYSTEM32\usvzuaus.dll
**********************************************************************
And last but not least Hijackthis:
Logfile of HijackThis v1.99.1
Scan saved at 1:48:35 AM, on 7/11/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Symantec AntiVirus\Rtvscan.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
C:\WINDOWS\System32\DSentry.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Dell\AccessDirect\dadapp.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Linksys\Wireless-B Notebook Adapter\WPC11Cfg.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\WINDOWS\system32\cidaemon.exe
C:\Program Files\HiJackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dellnet.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.byu.eduR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.byu.eduR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
http://localhostO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {A70F8123-9E66-AA0C-ACEC-CD69B6D68D4F} - C:\WINDOWS\system32\buvyzaod.dll (file missing)
O2 - BHO: (no name) - {DACCA194-E9FE-B59B-EB96-A96CC5761937} - C:\WINDOWS\system32\ltiwxqso.dll (file missing)
O2 - BHO: cnt Class - {E10959A2-8862-4582-973A-05BDAF4E0FE9} - C:\WINDOWS\System32\ctcnt1.dll (file missing)
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [iehelper] C:\Program Files\syslaunch.exe
O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [] c:\WINDOWS\System32\
O4 - HKLM\..\Run: [<meta http-equiv="Content-Type" content="text/html; charset=iso-8859] c:\WINDOWS\System32\<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
O4 - HKLM\..\Run: [<title>Off Campus Telecommunications Internet Signup</ti] c:\WINDOWS\System32\<title>Off Campus Telecommunications Internet Signup</title>
O4 - HKLM\..\Run: [<style type="text/c] c:\WINDOWS\System32\<style type="text/css">
O4 - HKLM\..\Run: [ ] c:\WINDOWS\System32\ <!--
O4 - HKLM\..\Run: [ <center><font face='Verdana, Arial, Helvetica, sans-serif' size='2'><br><B>Search of the Day</B></font>] c:\WINDOWS\System32\ <center><font face='Verdana, Arial, Helvetica, sans-serif' size='2'><br><B>Search of the Day</B></font><br>
O4 - HKLM\..\Run: [ <font face='Verdana, Arial, Helvetica, sans-serif' size='2'><A href="direc.asp?keywords=hobbies home recording dvds&chnl=1&t=r&pb=1207">hobbies home recording dvds</a></font></cen] c:\WINDOWS\System32\ <font face='Verdana, Arial, Helvetica, sans-serif' size='2'><A href="direc.asp?keywords=hobbies home recording dvds&chnl=1&t=r&pb=1207">hobbies home recording dvds</a></font></center>
O4 - HKLM\..\Run: [ <script id="kmpScript" src="
http://ads.kmpads.co...at=1207"></scr] c:\WINDOWS\System32\ <script id="kmpScript" src="
http://ads.kmpads.co...1207"></script>O4 - HKLM\..\Run: [var strT] c:\WINDOWS\System32\var strTemp;
O4 - HKLM\..\Run: [top.location.replace(strTe] c:\WINDOWS\System32\top.location.replace(strTemp);
O4 - HKLM\..\Run: [ <font face='Verdana, Arial, Helvetica, sans-serif' size='2'><A href="direc.asp?keywords=hobbies jewelry making&chnl=1&t=r&pb=1208">hobbies jewelry making</a></font></cen] c:\WINDOWS\System32\ <font face='Verdana, Arial, Helvetica, sans-serif' size='2'><A href="direc.asp?keywords=hobbies jewelry making&chnl=1&t=r&pb=1208">hobbies jewelry making</a></font></center>
O4 - HKLM\..\Run: [ <script id="kmpScript" src="
http://ads.kmpads.co...at=1208"></scr] c:\WINDOWS\System32\ <script id="kmpScript" src="
http://ads.kmpads.co...1208"></script>O4 - HKLM\..\Run: [ TOOL4AME] c:\WINDOWS\System32\ TOOL4AME.COM
O4 - HKLM\..\Run: [<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Frameset//] c:\WINDOWS\System32\<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Frameset//EN">
O4 - HKLM\..\Run: [ <title>tool4ame.com</ti] c:\WINDOWS\System32\ <title>tool4ame.com</title>
O4 - HKLM\..\Run: [ <meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7] c:\WINDOWS\System32\ <meta name="GENERATOR" Content="Microsoft Visual Studio .NET 7.1">
O4 - HKLM\..\Run: [ <meta name="CODE_LANGUAGE" Content="] c:\WINDOWS\System32\ <meta name="CODE_LANGUAGE" Content="C#">
O4 - HKLM\..\Run: [ <meta name="vs_defaultClientScript" content="JavaScri] c:\WINDOWS\System32\ <meta name="vs_defaultClientScript" content="JavaScript">
O4 - HKLM\..\Run: [ <meta name="vs_targetSchema" content="
http://schemas.micro...intellisense/i] c:\WINDOWS\System32\ <meta name="vs_targetSchema" content="
http://schemas.micro...ellisense/ie5">O4 - HKLM\..\Run: [ <nofra] c:\WINDOWS\System32\ <noframes>
O4 - HKLM\..\Run: [ <b] c:\WINDOWS\System32\ <body>
O4 - HKLM\..\Run: [ <a href='www1.eta.us/default.aspx?a=tool4ame.c] c:\WINDOWS\System32\ <a href='www1.eta.us/default.aspx?a=tool4ame.com'>
O4 - HKLM\..\Run: [ </b] c:\WINDOWS\System32\ </body>
O4 - HKLM\..\Run: [ </nofra] c:\WINDOWS\System32\ </noframes>
O4 - HKLM\..\Run: [ <frameset rows=] c:\WINDOWS\System32\ <frameset rows="*">
O4 - HKLM\..\Run: [ <frame src='http://www1.eta.us/default.aspx?a=tool4ame.com&ref=*&rs=&doc=p] c:\WINDOWS\System32\ <frame src='http://www1.eta.us/default.aspx?a=tool4ame.com&ref=*&rs=&doc=php'>
O4 - HKLM\..\Run: [ </frame] c:\WINDOWS\System32\ </frameset>
O4 - HKLM\..\Run: [ <!-- #15] c:\WINDOWS\System32\ <!-- #15 -->
O4 - HKLM\..\Run: [<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="Search the web at beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859] c:\WINDOWS\System32\<title>beneditutti.com</title><meta name="keywords" content="beneditutti.com"><meta name="description" content="Search the web at beneditutti.com"><meta name="robots" content="INDEX, FOLLOW"><meta name="revisit-after" content="10"><meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
O4 - HKLM\..\Run: [<frame src="
http://landing.domai...&adultfilter=o] c:\WINDOWS\System32\<frame s