Thanks for the quick response.
I had trouble getting the computer to enter safe mode. Nothing I did worked. Pressing F8 or Tab+F8 during the early start up screens doesn't work. The windows help info didn't help either.
I ran Ewido in normal mode anyway. HJT and ewido logs are below:
Logfile of HijackThis v1.99.1
Scan saved at 2:59:35 PM, on 8/9/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Winamp3\winampa.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\wkcalrem.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\CheckIt\86\CheckIt86.exe
C:\PROGRA~1\Toolbar\TBPS.exe
C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
C:\WINDOWS\System32\wrzycwi.exe
C:\PROGRA~1\COMMON~1\WinTools\WSup.exe
C:\PROGRA~1\Toolbar\PIB.exe
C:\Program Files\Hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ufl.edu/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - SOFTWARE - (no file)
O2 - BHO: Band Class - {00F1D395-4744-40f0-A611-980F61AE2C59} - C:\WINDOWS\dsr.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\PROGRA~1\Toolbar\toolbar.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\PROGRA~1\Toolbar\toolbar.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\2\printray.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [svrmc] C:\WINDOWS\system\CatRoot\svrmc.exe
O4 - HKLM\..\Run: [*svrmc] C:\WINDOWS\system\CatRoot\svrmc.exe
O4 - HKLM\..\Run: [*xmlnet] C:\WINDOWS\inf\xmlnet.exe
O4 - HKLM\..\Run: [*antieula] C:\WINDOWS\java\CLASSES\antieula.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [mqlrxp] c:\windows\system32\njcempn.exe
O4 - HKLM\..\Run: [tztunn] C:\WINDOWS\System32\wrzycwi.exe r
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Event Reminder.lnk = C:\Program Files\Mindscape\PrintMaster\PMREMIND.EXE
O4 - Global Startup: Microsoft Works Calendar Reminders.lnk = ?
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program Files\Cisco Systems\VPN Client\ipsecdialer.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: CheckIt 86.lnk = C:\Program Files\CheckIt\86\CheckIt86.exe
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Add To CheckIt &86 Trust List - C:\PROGRA~1\CHECKIT\86\AddToTrustList.js
O8 - Extra context menu item: Backward &Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: (no name) - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CHECKIT\86\CheckIt86.exe
O9 - Extra 'Tools' menuitem: CheckIt &86 - {2887F316-8C6C-47ae-A462-D2C9739D2C3D} - C:\PROGRA~1\CHECKIT\86\CheckIt86.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .cdx: C:\Program Files\Internet Explorer\plugins\Npcdp32.dll
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnote...ad/mnviewer.cabO16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.syma...bin/AvSniff.cabO16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} -
http://a1540.g.akama...meInstaller.exeO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupd...b?1093356755600O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.syma...n/bin/cabsa.cabO16 - DPF: {9BFC2253-B9D9-477E-9488-CA450232620D} (BinAg1 Class) -
https://fastconnectk...flowActiveX.CABO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://play09.pogo.c...aploader_v5.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcaf...360/mcfscan.cabO18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\PROGRA~1\Toolbar\toolbar.dll
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service (ccPxySvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 2:58:00 PM, 8/9/2005
+ Report-Checksum: FF68FD24
+ Scan result:
HKLM\SOFTWARE\Classes\CLSID\{2C4E6D22-B71F-491F-AAD3-B6972A650D50} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{310CC549-4541-46A9-940F-52B342A6E682} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{3EC8E271-FAB9-418a-8A8E-65AEB4029E64} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{69357D4E-BF4D-4651-91E9-52ECD45A0128} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6E21F428-5617-47F7-AED8-B2E1D8FBA711} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{708BE496-E202-497B-BC31-9CF47E3BF8D6} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{72AC6865-B1D3-4C32-A27B-4B3BF04DE655} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{87067F04-DE4C-4688-BC3C-4FCF39D609E7} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8B0FA130-0C3D-4CB1-AEB7-2C29DA5509A3} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{A8DEB4A5-D9EF-4D21-B4F6-921475004E7D} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{BBF122A7-8A4D-45B5-9E00-0F68BC87C904} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CAE0999F-78C5-49DC-9F30-13142AAAABA4} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{F1616B86-9288-489D-B71A-0CCF2F1A89DA} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{FF76A5DA-6158-4439-99FF-EDC1B3FE100C} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Common.Buttons\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{234F09FB-FE89-4C6D-9203-31832FC051C3} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{365B9A54-E613-46E5-9DB1-4F91A9DE80BD} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{618BE527-B7F5-417C-BC51-98FDC2D6DE61} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{66C22569-F05C-4A70-A142-763B337E1002} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{7B8BD940-B1EF-460C-85A2-9ACAAF7F9303} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{99AA88D1-D9D3-410A-BE9E-044F94C183DA} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C380566D-F343-42AB-987B-6B38A1A35747} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{D1951679-1D52-43FC-9585-0737143585F5} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{F273D4EA-2025-4410-8408-251A0CD46BE7} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\tpro -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res\toolbar.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\PROTOCOLS\Name-Space Handler\res\WToolsB.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginConfig -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginConfig\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDown -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDown\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginDownAdd\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginEvents -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginEvents\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginInst -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginInst\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginServer -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.PluginServer\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TBPS.ToolbarScript\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\toolbar.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\toolbar.ResProtocol\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{37AC49E3-E906-4BD8-AE83-D0F7FB48FD17} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{8992B6CA-B8C9-4AED-BF89-0A17F6296A06} -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{B23B3ADD-84B1-414A-92B9-0CABE5A781F4} -> Spyware.IBIS : Cleaned with backup
HKLM\SOFTWARE\Classes\WToolsB.ResProtocol -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\WToolsB.ResProtocol\Clsid -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3EC8E271-FAB9-418a-8A8E-65AEB4029E64} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72AC6865-B1D3-4C32-A27B-4B3BF04DE655} -> Spyware.VirtuMonde : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87766247-311C-43B4-8499-3D5FEC94A183} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8952A998-1E7E-4716-B23D-3DBE03910972} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8DA5457F-A8AA-4CCF-A842-70E6FD274094} -> Spyware.HuntBar : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\AUI -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\toolbar -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\toolbar\Install -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\WinTools -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\WinTools\kydmzylki -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\WinTools\nlibjhin -> Spyware.WebSearch : Cleaned with backup
HKLM\SOFTWARE\WinTools\nlibx4m -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\ControlSet002\Services\WinToolsSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\ZepMon -> Spyware.BetterInternet : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\TBPSSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Security -> Spyware.WebSearch : Cleaned with backup
HKLM\SYSTEM\CurrentControlSet\Services\WinToolsSvc\Enum -> Spyware.WebSearch : Cleaned with backup
HKU\.DEFAULT\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-823518204-113007714-1060284298-1003\Software\Toolbar -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-823518204-113007714-1060284298-1003\Software\Toolbar\UrlSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-823518204-113007714-1060284298-1003\Software\WinTools -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-21-823518204-113007714-1060284298-1003\Software\WinTools\URLSearchHooks -> Spyware.WebSearch : Cleaned with backup
HKU\S-1-5-18\Software\toolbar -> Spyware.WebSearch : Cleaned with backup
[1172] C:\WINDOWS\system32\DrPMon.dll -> Adware.BetterInternet : Cleaned with backup
[2000] C:\PROGRA~1\Toolbar\TBPSSvc.exe -> Spyware.WebSearch : Cleaned with backup
[228] C:\Program Files\Common Files\WinTools\WToolsS.exe -> Spyware.Wintol : Cleaned with backup
[380] C:\WINDOWS\TEMP\hrfflNh2.exe -> Spyware.WebSearch : Cleaned with backup
[756] VM_011A0000 -> Adware.BetterInternet : Error during cleaning
[1140] C:\WINDOWS\System32\ricxid.exe -> Trojan.Agent.cp : Cleaned with backup
[456] C:\PROGRA~1\Toolbar\TBPS.exe -> Spyware.WebSearch : Cleaned with backup
[740] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe -> Spyware.Wintol : Cleaned with backup
[1992] C:\PROGRA~1\Toolbar\PIB.exe -> Spyware.WebSearch : Cleaned with backup
[1568] C:\PROGRA~1\COMMON~1\WinTools\WSup.exe -> Spyware.Wintol : Cleaned with backup
C:\WINDOWS\SYSTEM32\in10b6.dll -> Adware.eZula : Cleaned with backup
C:\WINDOWS\SYSTEM32\ricxid.exe -> Trojan.Agent.cp : Cleaned with backup
C:\WINDOWS\SYSTEM32\DrPMon.dll -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\SYSTEM32\DrPMon.dll_tobedeleted -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\SYSTEM32\msbb321.dll.tcf -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\SYSTEM32\siae3123.exe.tcf -> Spyware.F1Organizer : Cleaned with backup
C:\WINDOWS\SYSTEM32\BO2801040128.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\WINDOWS\TEMP\hrfflNh2.exe -> Spyware.WebSearch : Cleaned with backup
C:\WINDOWS\dinst.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\WINDOWS\Downloaded Program Files\popcaploader.dll -> Not-A-Virus.RiskWare.Downloader.PopCap.a : Cleaned with backup
C:\WINDOWS\Nail.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\dsr.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\WINDOWS\dsr.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\WINDOWS\cluiqt.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\tqcrehkdg.exe -> Adware.BetterInternet : Cleaned with backup
C:\WINDOWS\Nail.exe -> Adware.BetterInternet : Cleaned with backup
C:\Program Files\Common Files\WinTools\WSup.exe -> Spyware.Wintol : Cleaned with backup
C:\Program Files\Common Files\WinTools\WToolsS.exe -> Spyware.Wintol : Cleaned with backup
C:\Program Files\Common Files\WinTools\WToolsA.exe -> Spyware.Wintol : Cleaned with backup
C:\Program Files\Toolbar\gykhxlmu.rmr -> Spyware.IBIS : Cleaned with backup
C:\Program Files\Toolbar\xlmurin.wzg -> Spyware.IBIS : Cleaned with backup
C:\Program Files\Toolbar\PIB.exe -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Toolbar\TBPS.exe -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Toolbar\nzqlihv.wzg -> Spyware.WebSearch : Cleaned with backup
C:\Program Files\Toolbar\TBPSSvc.exe -> Spyware.WebSearch : Cleaned with backup
C:\Documents and Settings\Krista Renner Wilson\Local Settings\Temp\alueitna.dat -> Spyware.VirtuMonde : Cleaned with backup
C:\Documents and Settings\Krista Renner Wilson\Local Settings\Temporary Internet Files\Content.IE5\01234567\WinTS[1].cab/WToolsS.exe -> Spyware.Wintol : Error during cleaning
C:\Documents and Settings\Krista Renner Wilson\Local Settings\Temporary Internet Files\Content.IE5\W5AVK5YB\TBPSSvc[1].cab/TBPSSvc.exe -> Spyware.WebSearch : Error during cleaning
C:\Documents and Settings\Krista Renner Wilson\Cookies\krista renner wilson@abetterinternet[2].txt -> Spyware.Cookie.Abetterinternet : Cleaned with backup
:mozilla.21:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.2o7 : Cleaned with backup
:mozilla.31:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.38:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.39:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.40:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.41:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.44:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
:mozilla.45:C:\Documents and Settings\Krista Renner Wilson\Application Data\Mozilla\Firefox\Profiles\default.87e\cookies.txt -> Spyware.Cookie.Tribalfusion : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP24\A0003411.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP24\A0003412.exe.tcf -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP24\A0003422.exe.tcf -> Spyware.Wintools : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP26\A0003508.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP26\A0003515.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP26\A0003516.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP26\A0003523.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP27\A0003530.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP28\A0003537.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP30\A0003548.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP31\snapshot\MFEX-2.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP31\snapshot\MFEX-3.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP31\A0003555.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP31\A0003554.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP32\snapshot\MFEX-2.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP32\snapshot\MFEX-3.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP32\snapshot\MFEX-7.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP32\A0003564.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP33\snapshot\MFEX-2.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP33\snapshot\MFEX-3.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP33\snapshot\MFEX-7.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP33\snapshot\MFEX-8.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP33\A0003573.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\snapshot\MFEX-2.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\snapshot\MFEX-3.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\snapshot\MFEX-7.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\snapshot\MFEX-8.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\snapshot\MFEX-9.DAT -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0004508.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0004509.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0004510.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0004516.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0004517.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP34\A0003580.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP35\A0004527.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP36\A0004544.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP38\A0004555.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP40\A0004568.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP41\A0004576.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP42\A0005508.dll -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP42\A0005514.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP42\A0005515.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP42\A0004583.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP43\A0005532.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP44\A0005541.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP45\A0005546.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP46\A0005552.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP46\A0005563.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP46\A0005564.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP46\A0005578.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP47\A0005586.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP47\A0005595.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP47\A0005596.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP47\A0005603.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP53\A0006595.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP53\A0006596.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP53\A0007595.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP53\A0007596.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008595.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008596.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008825.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008827.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008839.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008841.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008951.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008952.DLL -> Spyware.ClearSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008963.exe.tcf -> TrojanDownloader.Virtumonde.a : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008964.exe.tcf -> TrojanDownloader.Virtumonde.a : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008962.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008970.exe -> Spyware.BiSpy : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008975.exe -> TrojanDownloader.Keenval : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008982.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008987.exe -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008994.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008995.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009003.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009009.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009010.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009014.DLL -> Spyware.MyWebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009024.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009025.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009028.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009032.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009038.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009039.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008955.exe.tcf -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008956.dll.tcf -> TrojanDownloader.QDown.H : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008957.exe.tcf -> TrojanDownloader.Virtumonde.a : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008958.exe.tcf -> TrojanDownloader.Alchemic : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008959.exe.tcf -> Trojan.KillFiles.fz : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008960.dll.tcf -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008965.exe.tcf -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008966.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008967.exe.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008968.exe.tcf -> TrojanDownloader.Agent.ae : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008971.exe.tcf -> TrojanDownloader.Agent.ae : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008972.exe.tcf -> TrojanDownloader.Agent.ae : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008974.dll.tcf -> Spyware.ImiBar : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008976.exe.tcf -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0008998.exe.tcf -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009000.dll.tcf -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009027.exe.tcf -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009044.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009045.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009046.exe -> Spyware.F1Organizer : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009055.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009057.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009058.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009059.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009068.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009069.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009071.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009078.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009079.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009081.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009088.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009089.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009091.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009098.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009099.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009101.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009108.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009109.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009111.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009118.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009119.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009121.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009128.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009129.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009131.exe -> Spyware.Wintol : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009138.exe -> Trojan.Agent.cp : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009139.EXE -> Spyware.WebSearch : Cleaned with backup
C:\System Volume Information\_restore{7E6B4A93-AFB8-4498-8A28-794A17B443F6}\RP59\A0009141.exe -> Spyware.Wintol : Cleaned with backup
::Report End