Hi Sam,
I followed the steps per your instruction. I'm still getting infection alerts from my antivirus of an infection called Win32.Bettlnet.AW (I realize we might not be done, I'm just letting you know).
While running hijackthis in safe mode, I did not delete:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
because they were represented as:
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drs...esearch.cgi?id=These items were not present so I obviously did not delete them:
O2 - BHO: SST - {FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} - C:\Program Files\Lycos\sst.dll (file missing)
O4 - HKLM\..\Run: [oaqgdq] c:\windows\system32\kluhjl.exe r
If I didn't do something right, let me know and I'll fix it.
Here is my hijackthis log:
Logfile of HijackThis v1.99.1
Scan saved at 10:46:58 AM, on 7/26/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\LTSMMSG.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\System32\qttask.exe
C:\WINDOWS\System32\WScript.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Microsoft AntiSpyware\gcasServ.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\Messenger\msmsgs.exe
c:\windows\system32\gnzdnb.exe
C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\Sony\VAIO Action Setup\VAServ.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\iPod\bin\iPodService.exe
c:\progra~1\Support.com\client\bin\tgcmd.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://websearch.drs...esearch.cgi?id=R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
http://websearch.drs...esearch.cgi?id=R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://websearch.drs...esearch.cgi?id=O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\adobe\acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\System32\qttask.exe
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
O4 - HKLM\..\Run: [QuickFinder Scheduler] "C:\Program Files\Corel\WordPerfect Office 2002\Programs\QFSCHD100.EXE"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\Run: [CaAvTray] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVTray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [evbppp] c:\windows\system32\gnzdnb.exe r
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exe
O4 - Global Startup: VAIO Action Setup (Server).lnk = ?
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....204&clcid=0x409O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\PROGRA~1\COMMON~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: VET Message Service (VETMSGNT) - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
Here is my Ewido log:
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:29:19 AM, 7/26/2005
+ Report-Checksum: 4CDFEC19
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\IEagent\387 -> Spyware.ClearSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\ins -> Spyware.WebRebates : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKU\.DEFAULT\Software\BTGrab -> Spyware.BetterInternet : Cleaned with backup
HKU\.DEFAULT\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-000000002230} -> Spyware.ClearSearch : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E65A557-173C-4DE9-860B-28FC5CACA542} -> Spyware.FastFind : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA5A82FB-D6BE-44F9-9363-B1ABABC153C1} -> Spyware.BetterInternet : Cleaned with backup
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKU\S-1-5-21-3403473811-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-000000002230} -> Spyware.ClearSearch : Cleaned with backup
HKU\S-1-5-21-3403473811-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-21-3403473811-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-3403473811-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E65A557-173C-4DE9-860B-28FC5CACA542} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-21-3403473811-1907411925-173008773-1006\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
HKU\S-1-5-18\Software\BTGrab -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-18\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-0000-0000-0000-000000002230} -> Spyware.ClearSearch : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{00000000-F09C-02B4-6EC2-AD0300000000} -> Spyware.Transponder : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{01F44A8A-8C97-4325-A378-76E68DC4AB2E} -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2E65A557-173C-4DE9-860B-28FC5CACA542} -> Spyware.FastFind : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EA5A82FB-D6BE-44F9-9363-B1ABABC153C1} -> Spyware.BetterInternet : Cleaned with backup
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FFFFDA2C-A0D5-4D60-8EE1-1B7F8929E24D} -> Spyware.SideSearch : Cleaned with backup
:mozilla.8:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.22:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.23:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.24:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.25:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.26:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.29:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Friend\Application Data\Mozilla\Firefox\Profiles\tpw96rby.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Friend\Cookies\friend@abetterinternet[1].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Friend\Cookies\friend@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Friend\Cookies\
[email protected][2].txt -> Spyware.Cookie.Webtrendslive : Cleaned with backup
:mozilla.9:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.10:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.11:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.12:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Liveperson : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.17:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.18:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.19:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.30:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.32:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.33:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Overture : Cleaned with backup
:mozilla.34:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.49:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.54:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.55:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.56:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.57:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.58:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.59:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.60:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.61:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.62:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.63:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.64:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.65:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.66:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.67:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.71:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.74:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.75:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.77:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.78:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
:mozilla.87:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Bluestreak : Cleaned with backup
:mozilla.96:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
:mozilla.103:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.117:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.118:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.119:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Ru4 : Cleaned with backup
:mozilla.141:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.142:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Addynamix : Cleaned with backup
:mozilla.143:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.144:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.145:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.146:C:\Documents and Settings\Kara Hueni\Application Data\Mozilla\Firefox\Profiles\3gmh7oq8.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara hueni@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara hueni@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara
[email protected][2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara hueni@advertising[2].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara hueni@atdmt[1].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara
[email protected][1].txt -> Spyware.Cookie.Advertising : Cleaned with backup
C:\Documents and Settings\Kara Hueni\Cookies\kara hueni@trafficmp[2].txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.13:C:\Documents and Settings\Marilynn\Application Data\Mozilla\Firefox\Profiles\gq64o8xu.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.14:C:\Documents and Settings\Marilynn\Application Data\Mozilla\Firefox\Profiles\gq64o8xu.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.15:C:\Documents and Settings\Marilynn\Application Data\Mozilla\Firefox\Profiles\gq64o8xu.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.16:C:\Documents and Settings\Marilynn\Application Data\Mozilla\Firefox\Profiles\gq64o8xu.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.20:C:\Documents and Settings\Marilynn\Application Data\Mozilla\Firefox\Profiles\gq64o8xu.default\cookies.txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Documents and Settings\Marilynn\Cookies\marilynn@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\Marilynn\Cookies\marilynn@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
C:\Documents and Settings\Marilynn\Cookies\marilynn@atdmt[2].txt -> Spyware.Cookie.Atdmt : Cleaned with backup
C:\Documents and Settings\Marilynn\Cookies\marilynn@centrport[1].txt -> Spyware.Cookie.Centrport : Cleaned with backup
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll -> Spyware.Wheaterbug : Cleaned with backup
C:\WINDOWS\cnlqqj.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\jxgagoaxk.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\systb.dll -> Spyware.ImiBar : Cleaned with backup
C:\WINDOWS\system32\btaskx.exe -> Adware.BetterInternet : Cleaned with backup
::Report End