I followed the instruction but I am still getting the winfixer popup and others. Here is the new Hijack log followed by the ewido log. Thanks for your help.
Logfile of HijackThis v1.99.1
Scan saved at 11:13:06 PM, on 8/12/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\System32\CTSvcCDA.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\WINNT\System32\inetsrv\inetinfo.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\MotorolaDAP.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\svchost.exe
C:\Program Files\Yahoo!\browser\ybrwicon.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\PROGRA~1\YAHOO!\browser\ycommon.exe
C:\WINNT\SM1BG.EXE
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE
C:\Program Files\2Wire\2PortalMon.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINNT\system32\rundll32.exe
C:\WINNT\system32\devldr32.exe
C:\WINNT\system32\wuauclt.exe
C:\Documents and Settings\Mike Wheeler\Desktop\HijackThis.exe
\?\C:\WINNT\system32\WBEM\WMIADAP.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://yahoo.sbc.com/dslR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Startpagina = file:///C:/Program%20Files/MS-Connect/Portal/portal.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak =
http://yahoo.sbc.com/dslR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\WS_FTP Pro\wsbho2k0.dll (file missing)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\ycomp5_5_7_0.dll
O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [YBrowser] C:\Program Files\Yahoo!\browser\ybrwicon.exe
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SM1BG] C:\WINNT\SM1BG.EXE
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [IPInSightMonitor 01] "C:\Program Files\SBC Yahoo!\Connection Manager\IP InSight\IPMon32.exe"
O4 - HKLM\..\Run: [EPSON Stylus Photo RX500] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_S4I2K1.EXE /P24 "EPSON Stylus Photo RX500" /O6 "USB001" /M "Stylus Photo RX500"
O4 - HKLM\..\Run: [2wSysTray] C:\Program Files\2Wire\2PortalMon.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [FineReader7NewsReaderPro] "C:\Program Files\ABBYY FineReader 7.0 Professional Edition\ABBYYNewsReader.exe"
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINNT\system32\ctfmon.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Memorex Autorun.lnk = E:\autorun.exe
O4 - Global Startup: EPSON CardMonitor.lnk = C:\Program Files\EPSON\EPSON CardMonitor\EPSON CardMonitor1.1.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra 'Tools' menuitem: Yahoo! Login - {2499216C-4BA5-11D5-BD9C-000103C116D5} - C:\Program Files\Yahoo!\Common\ylogin.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0854D220-A90A-466D-BC02-6683183802B7} (PrintPreview Class) -
http://sabor.fnismls...rintControl.cabO16 - DPF: {2B4F4FA8-814A-11D7-B31B-0002A500B281} (FASetupStart Control) -
http://ff.fullaudio.....0.36/setup.cabO16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
http://us.dl1.yimg.c...nst20040510.cabO20 - Winlogon Notify: ThemeManager - C:\WINNT\system32\wverror.dll
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINNT\System32\CTSvcCDA.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: Motorola Digital Audio Player Manager (MotorolaDAP) - Motorola Inc. - C:\WINNT\system32\MotorolaDAP.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINNT\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: YPCService - Yahoo! Inc. - C:\WINNT\system32\YPCSER~1.EXE
---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------
+ Created on: 10:18:28 PM, 8/12/2005
+ Report-Checksum: D8D250AD
+ Scan result:
HKLM\SOFTWARE\CashBack -> Spyware.CashBack : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\AtlBrowser.EXE -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\BookedSpace.DLL -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\AppID\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\AtlBrCon.AtlBrCon\CurVer -> Spyware.eZula : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CLSID -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\BookedSpace.Extension\CurVer -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\CLSID\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\{6EC11407-5B2E-4E25-8BDF-77445B52AB37} -> Spyware.VX2 : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{05080E6B-A88A-4CFD-8C3D-9B2557670B6E} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E1357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{8EEE58D5-130E-4CBD-9C83-35A0564E2468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED11357} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\Interface\{C6906A23-4717-4E1F-B6FD-F06EBED12468} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\NLS.UrlCatcher -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\NLS.UrlCatcher\CLSID -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{0DC5CD7C-F653-4417-AA43-D457BE3A9622} -> Spyware.BookedSpace : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516C2E3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Classes\TypeLib\{4EB7BBE8-2E15-424B-9DDB-2CDB9516E2A3} -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NaviSearch -> Spyware.NaviSearch : Cleaned with backup
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\H323TSP -> Spyware.Look2Me : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\intexp -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\intexp\Config -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\intexp\MyFileSystem2 -> Spyware.IEPlugin : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{0019C3E2-DD48-4A6D-ABCD-8D32436323D9} -> Spyware.BookedSpace : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} -> Spyware.BargainBuddy : Cleaned with backup
HKU\S-1-5-21-1482476501-1563985344-1957994488-1000\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CE188402-6EE7-4022-8868-AB25173A3E14} -> Spyware.BargainBuddy : Cleaned with backup
[260] C:\WINNT\system32\wverror.dll -> Spyware.Look2Me : Error during cleaning
[1496] C:\WINNT\system32\guard.tmp -> Spyware.Look2Me : Error during cleaning
[1764] C:\WINNT\system32\guard.tmp -> Spyware.Look2Me : Error during cleaning
C:\WINNT\system32\lyeps11n.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\cxmuid.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\usiplat.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\dcnput.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\rLschap.dll -> Spyware.Look2Me : Cleaned with backup
C:\WINNT\system32\ezStub.exe -> Adware.eZula : Cleaned with backup
C:\WINNT\Downloaded Program Files\ActiveX.ocx -> Spyware.Look2Me : Cleaned with backup
C:\Program Files\Norton SystemWorks\Norton CleanSweep\Backup\SysP2590.BUD.mwt/WINNT/Downloaded Program Files/ActiveSecurity.ocx -> Not-A-Virus.VirTool.Collector : Error during cleaning
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP565\A0363454.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363491.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363492.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363494.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363495.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363496.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363497.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363579.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363596.exe -> Trojan.Imiserv.c : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363601.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363664.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363665.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363666.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363668.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363669.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363670.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363674.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363675.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363676.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363677.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363679.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363680.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP566\A0363681.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363721.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363722.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363723.DLL -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363724.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363725.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363726.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363727.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363728.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363729.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363730.dll -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363731.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363732.exe -> Spyware.WinAD : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363733.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363734.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363735.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363736.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363737.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363739.exe -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363740.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363741.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363742.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363743.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363744.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363770.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363772.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP567\A0363795.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP561\A0359339.exe -> Spyware.Statblaster : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP563\A0361239.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP563\A0361244.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0361407.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0361408.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362022.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362213.srg -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362241.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362243.exe -> Spyware.VirtualBouncer : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362244.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362245.dll -> Adware.eZula : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362248.exe -> Spyware.ISearch : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362257.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362293.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362300.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362307.dll -> Spyware.SurfSide : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362308.dll -> Spyware.SurfSide : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362309.exe -> Spyware.SurfSide : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362316.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0362327.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363333.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363335.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363336.dll -> Spyware.Look2Me : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363429.exe -> Trojan.Agent.gp : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363430.exe -> Adware.BetterInternet : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363431.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363432.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363433.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363434.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363436.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363437.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363439.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363440.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363441.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363442.exe -> Spyware.CashBack : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363444.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{518D67A7-69B5-4E80-BFB4-CC05B87965FB}\RP564\A0363445.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011942.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00011951.dll -> Spyware.Look2Me : Cleaned with backup
C:\Recycled\NPROTECT\00011998.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00012854.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00013183.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00013186.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Recycled\NPROTECT\00013217.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Recycled\NPROTECT\00013485.dll -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Recycled\NPROTECT\00013486.dat -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Recycled\NPROTECT\00013487.cpl -> TrojanDownloader.Qoologic.p : Cleaned with backup
C:\Recycled\NPROTECT\00013488.dll -> TrojanDownloader.Qoologic.s : Cleaned with backup
C:\Recycled\NPROTECT\00013489.exe -> TrojanDownloader.Qoologic.u : Cleaned with backup
C:\Recycled\NPROTECT\00013490.DLL -> TrojanDownloader.Wintrim.av : Cleaned with backup
C:\Recycled\NPROTECT\00010975.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\Recycled\NPROTECT\00010976.dll -> Spyware.VirtualBouncer : Cleaned with backup
C:\Recycled\NPROTECT\00010977.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\Recycled\NPROTECT\00010978.DLL -> Spyware.VirtualBouncer : Cleaned with backup
C:\Recycled\NPROTECT\00010980.EXE -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00010982.exe -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00010983.exe -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00010989.dll -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00010990.dll -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011049.EXE -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011083.exe -> TrojanDownloader.OneClickSearch.k : Cleaned with backup
C:\Recycled\NPROTECT\00011119.EXE -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011120.dll -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011121.exe -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011123.exe -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011155.exe -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011193.dll -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011195.dll -> Adware.eZula : Cleaned with backup
C:\Recycled\NPROTECT\00011279.cab/clientax.dll -> Spyware.180Solutions : Error during cleaning
C:\Recycled\NPROTECT\00011339.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011340.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011342.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011343.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011345.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011346.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011351.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011352.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011353.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011548.dll -> Spyware.180Solutions : Cleaned with backup
C:\Recycled\NPROTECT\00011551.exe -> Spyware.180Solutions : Cleaned with backup
C:\Recycled\NPROTECT\00011681.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011682.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011683.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011685.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011687.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011688.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011689.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011697.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011700.DLL -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011701.EXE -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011702.EXE -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011704.EXE -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011705.EXE -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011706.DLL -> Spyware.WinAD : Cleaned with backup
C:\Recycled\NPROTECT\00011708.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011709.vxd -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011710.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011711.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011713.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011714.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011715.exe -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00011856.exe -> Trojan.Agent.gp : Cleaned with backup
C:\Recycled\NPROTECT\00011972.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Recycled\NPROTECT\00011975.EXE -> Adware.BetterInternet : Cleaned with backup
C:\Recycled\NPROTECT\00011979.exe -> TrojanDownloader.Intexp.d : Cleaned with backup
C:\Recycled\NPROTECT\00011980.dll -> Spyware.Hijacker.Generic : Cleaned with backup
C:\Recycled\NPROTECT\00012360.dll -> Spyware.Look2Me : Cleaned with backup
C:\Recycled\NPROTECT\00012367.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00013161.exe -> TrojanDownloader.Small.abd : Cleaned with backup
C:\Recycled\NPROTECT\00013170.dll -> Spyware.BookedSpace : Cleaned with backup
C:\Recycled\NPROTECT\00013171.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\Recycled\NPROTECT\00013661.exe -> Spyware.PurityScan : Cleaned with backup
C:\Recycled\NPROTECT\00013673.EXE -> Spyware.Lop : Cleaned with backup
C:\Recycled\NPROTECT\00013675.EXE -> Spyware.Lop : Cleaned with backup
::Report End