Alright, as requested, here is the
ActiveScan log:
Incident Status Location
Adware:Adware/AzeSearch No disinfected C:\Documents and Settings\Brian Martinolich\Desktop\HJT\backups\backup-20050625-161313-345.inf
Adware:Adware/Perfect-Search No disinfected C:\Documents and Settings\Brian Martinolich\Favorites\Adult\Escorts.url
Adware:Adware/Startpage.LH No disinfected C:\Documents and Settings\Brian Martinolich\Favorites\Adult\Single Girls.url
Adware:Adware/KeenValue No disinfected C:\WINDOWS\browserxtras\pn\remove.exe
Adware:Adware/nCase No disinfected C:\WINDOWS\Downloaded Program Files\clientax.inf
Adware:Adware/Gator No disinfected C:\WINDOWS\GatorPatch.log
Adware:Adware/Antivirus-gold No disinfected C:\WINDOWS\screen.html
Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\smdat32m.sys
Adware:Adware/AzeSearch No disinfected C:\WINDOWS\SYSTEM32\azebar.xml
Adware:Adware/SAHAgent No disinfected C:\WINDOWS\SYSTEM32\bln02nqv.exe
Adware:Adware/AzeSearch No disinfected C:\WINDOWS\SYSTEM32\iasada.dll
Adware:Adware/WUpd No disinfected C:\WINDOWS\SYSTEM32\ide21201.vxd
Adware:Adware/TopSpyware No disinfected C:\WINDOWS\SYSTEM32\winnook.exe
Virus:Trj/Downloader.AUP Disinfected C:\WINDOWS\VT17.exe
here is the
HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 5:09:23 AM, on 6/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\Program Files\EarthLink TotalAccess\TaskPanl.exe
C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\Winamp\winamp.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\Documents and Settings\Brian Martinolich\Desktop\HJT\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/mywayR1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://www.dell4me.com/mywayR3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - C:\WINDOWS\nem220.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SABHO - {21B4ACC4-8874-4AEC-AEAC-F567A249B4D4} - c:\program files\180searchassistant\salmhook.dll (file missing)
O2 - BHO: PnIEBrowserHelperObj Class - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: AddressBar Class - {f65b197f-8260-4d52-909a-f70118e646eb} - C:\WINDOWS\system32\iasada.dll
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [MPFExe] C:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -b
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Web Rebates - file://C:\Program Files\Web_Rebates\Sy1150\Tp1150\scri1150a.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Program Files\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\WINDOWS\System32\shdocvw.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM\aim.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Program Files\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111F00-3E00-11D2-8470-0060089874ED} -
http://supportsoft.a...ad/tgctlins.cabO16 - DPF: {99410CDE-6F16-42ce-9D49-3807F78F0287} (ClientInstaller Class) -
http://www.180search...com/180saax.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://www.pandasoft.../as5/asinst.cabO16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
http://us.dl1.yimg.c.../ymmapi_416.dllO16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} -
http://us.dl1.yimg.c...utocomplete.cabO20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - Unknown owner - c:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - Networks Associates Technology, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - C:\PROGRA~1\McAfee.com\PERSON~1\MPFSERVICE.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
and also, here is the
Ewido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 4:07:49 PM, 6/25/2005
+ Report-Checksum: 5C7CEFCD
+ Date of database: 6/25/2005
+ Version of scan engine: v3.0
+ Duration: 59 min
+ Scanned Files: 87792
+ Speed: 24.57 Files/Second
+ Infected files: 138
+ Removed files: 138
+ Files put in quarantine: 138
+ Files that could not be opened: 0
+ Files that could not be cleaned: 0
+ Binder: Yes
+ Crypter: Yes
+ Archives: Yes
+ Scanned items:
C:\
+ Scan result:
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@19495311[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@53312104[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@63676511[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@91380899[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@bannerspace[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@dcsklxjd7oifwzramfu7ehxd9_2j2f[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@dcskqeg2voifwznnd6alhtnei_8f3u[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@gostats[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@myway[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@myway[4].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@specificpop[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian martinolich@tryaolfree[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Application Data\Earthlink\6.0\
[email protected]\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@1069571080[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@35487201[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@41186290[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@889585570[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@889585570[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@889642185[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@889666703[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@889679939[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@adknowledge[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@advertising[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@atdmt[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@bannerspace[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@bluestreak[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@burstnet[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@com[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@dcsgvi06gpljwp8qykja7ku7d_7i3o[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@doubleclick[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@exitexchange[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@fastclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@mediaplex[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@realmedia[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@spylog[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@tradedoubler[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@tribalfusion[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@valueclick[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@xiti[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian
[email protected][1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Cookies\brian martinolich@zedo[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\bmof.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@35487201[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@adknowledge[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@burstnet[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@com[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@dcswkdum9pljwpslkirxaz7o5_7t5n[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@exitexchange[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@geocities[2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian martinolich@sexsearchcom[1].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Cookies\brian
[email protected][2].txt -> Spyware.Tracking-Cookie -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\cpac.exe -> Trojan.Agent.ep -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\cpck.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Del35B.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Del413.tmp -> TrojanDownloader.Small.asf -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\Del4D2.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\dfoj.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\fbcg.exe -> Trojan.Agent.ep -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\fhcm.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\gcaj.exe -> Trojan.Agent.ep -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\hjjm.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\jfak.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\jkill.exe -> Spyware.VX2 -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\ldgh.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\mala.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\res35D.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\Documents and Settings\Brian Martinolich\Local Settings\Temp\res414.tmp -> Spyware.180Solutions -> Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug.a -> Cleaned with backup
C:\Program Files\Internet Optimizer\update\install.exe -> TrojanDownloader.Dyfuca.de -> Cleaned with backup
C:\Program Files\Media Access\MediaAccC.dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\Program Files\Mozilla Firefox\plugins\npzango.dll -> Spyware.WinAD -> Cleaned with backup
C:\Program Files\Spybot - Search & Destroy\wtwebdriver\files\3.3.1.001\wtvh.dll -> Spyware.WildTangent.b -> Cleaned with backup
C:\Program Files\Web_Rebates\disp1150.exe -> Spyware.WebRebates.b -> Cleaned with backup
C:\Program Files\Web_Rebates\Sy1150\Sy1150\1150_1.dat -> Spyware.TopMoxie -> Cleaned with backup
C:\Program Files\Windows Media Player\Slysoft AnyDVD 5.1.0.1 Crack.zip/Slysoft AnyDVD 5.1.0.1 Crack.exe -> Worm.VB.cz -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP312\A0090197.exe -> TrojanDownloader.Agent.jt -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP319\A0092598.exe -> TrojanDownloader.Agent.jt -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP320\A0092642.exe -> TrojanDownloader.Agent.jt -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP347\A0122799.dll -> Spyware.WildTangent.b -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP347\A0122811.dll -> Spyware.WildTangent.b -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP347\A0122821.dll -> Spyware.WildTangent.b -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP348\A0125909.dll -> Spyware.AzSearch -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP353\A0129071.exe -> Dialer.Generic -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP376\A0143314.dll -> Spyware.WinAD -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP376\A0143315.dll -> Spyware.WinAD.ag -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP376\A0143316.exe -> Spyware.WinAD -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP376\A0143317.exe -> Spyware.WinAD -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP377\A0143350.exe -> Spyware.180Solutions -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP377\A0143571.vxd -> Spyware.MediaPass -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP378\A0143611.dll -> Spyware.180Solutions -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143727.exe -> Spyware.WinAD -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143728.exe -> Spyware.Sahat.o -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143732.exe -> Spyware.WinAD -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143733.exe -> Trojan.TopAntiSpyware.l -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143734.dll -> Spyware.Look2Me.ab -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143735.dll -> Spyware.Look2Me.ab -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143736.dll -> Spyware.Look2Me.ab -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143737.dll -> Spyware.Look2Me.ab -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143738.dll -> Spyware.Sahat.l -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143746.exe -> Spyware.180Solutions -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143747.exe -> Spyware.180solutions -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143748.exe -> TrojanDownloader.Dyfuca.ei -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0143761.dll -> Spyware.AzSearch -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0144731.dll -> TrojanDownloader.Dyfuca -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0145731.dll -> Spyware.AzSearch.a -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP380\A0145761.dll -> Spyware.MoneyGainer -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP381\A0145787.dll -> Spyware.180Solutions -> Cleaned with backup
C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30-83E44C588624}\RP384\A0146858.exe -> Spyware.Sahat.o -> Cleaned with backup
C:\WINDOWS\180.exe -> Spyware.WinAD -> Cleaned with backup
C:\WINDOWS\Downloaded Program Files\ClientAX.dll -> Spyware.180Solutions -> Cleaned with backup
::Report End
The computer is running really well, extremely better than it was before, but I still believe that McAfee might be making it run a little slow, plus, it wasn't letting me run a scan on HijackThis until after I ended the process in Task Manager...idk, what are you suggesting? Should I remove it or not?
Again, thanks, you've been wonderful help. Are there any more steps?